Skip to content

[FEATURE] Support OAuth User Attribute Mapping #1025

Description

@lightlike

Is your feature request related to a problem? Please describe.

I want to connect tinyauth to nextcloud but it seems that the user endpoint does not return all the data (email in this case) in the expected structure.

Describe the solution you'd like.

It would be nice to have some simple json mapping where one can just remap the location of the provided userinfo.

Example:

TINYAUTH_OAUTH_PROVIDERS_[NAME]_USERINFOPATH_EMAIL=ocs.data.email

Additional context

There already is a similar Issue with Grafana: https://help.nextcloud.com/t/oauth2-userinfo-api/70556/12

An example structure for nextcloud user can be found here: https://docs.nextcloud.com/server/latest/developer_manual/client_apis/OCS/ocs-api-overview.html#user-metadata

The docs show xml but it can be formatted as json using format=json

Human Written Confirmation

  • I confirm this request was written by me and not generated by an LLM or AI assistant.

Activity

  1. steveiliop56 commented on Aug 23, 2026

    @steveiliop56
    Member

    Added with #1087.

    You will be able to use the following mappings:

    # Username claim.
    TINYAUTH_OAUTH_PROVIDERS_name_CLAIMS_USERNAME=
    # Email claim.
    TINYAUTH_OAUTH_PROVIDERS_name_CLAIMS_EMAIL=
    # Name claim.
    TINYAUTH_OAUTH_PROVIDERS_name_CLAIMS_NAME=
    # Groups claim.
    TINYAUTH_OAUTH_PROVIDERS_name_CLAIMS_GROUPS=

    However, I am not sure if I should allow sub as well because it's technically a requirement and an OpenID Connect server MUST include it in the response.

  2. lightlike commented on Aug 23, 2026

    @lightlike
    Author

    I do not think the sub claim should be a problem.
    Nextclouds ocs.data.id is static and cannot be changed without recreating the entire user.
    So I would just set username and sub to the same value.
    I cannot say anything for other applications.

    Whatever is easiest for you. I am happy as long as I no longer get errors.
    I know that this is not an officially supported OIDC Endpoint. This uses OAuth2. I do not know much of the official standard.
    But I also set up Pocket ID so that is my alternative if something does not work.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions