mammoth-country-5949
07/14/2022, 11:28 PMproud-plumber-24205
07/15/2022, 9:08 AMmammoth-country-5949
07/15/2022, 4:20 PMmammoth-country-5949
07/15/2022, 4:21 PMproud-plumber-24205
07/18/2022, 7:17 AMmammoth-country-5949
07/18/2022, 4:22 PMmammoth-country-5949
07/18/2022, 4:24 PMproud-plumber-24205
07/18/2022, 5:06 PMmammoth-country-5949
07/18/2022, 5:35 PMable-glass-7253
07/18/2022, 7:49 PMmicrosoft_tenant
value to "organizations", and AD would then do the realm detection for you.
Regarding your second question, the answer depends on the specific scenario. Sessions are immutable and there is no way to attach metadata to them per se. But you may use a reverse proxy (such as Oathkeeper using it's mutators/hydrators) to attach data to each request with a session. Or if, perchance, the data is included in the user's ID token the first time the user signed up, you can a) define a jsonnet mapper to map it to the user's identity traits[2], or b) retrieve the token itself[3].
[1]: https://www.ory.sh/docs/guides/social-signin/microsoft
[2]: https://www.ory.sh/docs/guides/social-signin/microsoft#data-mapping
[3]: https://www.ory.sh/docs/guides/social-signin/get-tokensmammoth-country-5949
07/18/2022, 8:12 PMproud-plumber-24205
07/19/2022, 7:28 AMI assumed OIDC is only provided through Hydra..To put it simply Kratos is an OIDC client while Hydra is an OAuth2/OpenID server.
able-glass-7253
07/19/2022, 12:15 PMmammoth-country-5949
07/19/2022, 3:31 PM