Single sign-on improvements
SSO setup is now a three-step flow: connect, test, enable. It also supports identity providers that don't send an email address.
Setup
- Three steps: connect a provider, run a test sign-in, then enable it
- Advanced options folded away until needed
- Editable scopes, checked against what the provider says it supports
- Choice of the sign-in prompt the provider shows
- Table of the claims the provider returned during the test
- Claim mapping to roles and to person attributes that can drive segments
- Custom provider icons, and the provider's profile picture as the avatar
Provider compatibility
- Providers that don't share an email address, with people asked for a contact address instead
- Providers that keep identity details in the access token
- Existing providers keep working without a change to their redirect address
Fixes
- Sign-in alert emails only go out for genuinely new devices
- Signing out of Quackback no longer signs you out of your identity provider
- Providers that leave out a standard security value in their sign-in response are now detected
Availability: Settings > Access & Security > SSO.
