Overview
The UI can be configured to allow users to authenticate using their corporate Google credentials. This page will walk you through the configuration process.
Create an Authorization Source
Obtain a Client ID and Client Secret from the Google system. These values should be generated based on the public URL of your UI.
Client ID and Client Secret can typically be generated at https://console.developers.google.com.
See Google documentation for further instructions.
Configure UI
- From the Top Menu, click System -> Auth Sources
- From the left menu, click New
- Enter a Name for the source (e.g. Google). This name will appear on the sign-in button on the login page
- In the Driver field, select Google
- The Redirect URI should be the URL of your management UI (e.g. https://contoso.west1.korgrid.com)
- Enter the Client ID and Client Secret values obtained from Google in the previous section
- Remote User Fields is the list of fields used to initially find the Google user. This field is auto populated with sub,preferred_username,email,nickname. This default list is typically sufficient for most implementations.
Options (recommended):
- Update Remote User - once user is located in the Google system, update the user's Remote Username field to the corresponding Google unique ID (sub string).
- Update User Email Address - update local user's email address to match email address in Google.
- Update User Display Name - update local user's display name to match display name in Google.
Enabling the Update Remote User option will allow the system to store the user's unique Google ID in the UI's user record so the unique identifier can subsequently be used for finding the Google user; this is typically recommended since fields such as email address can sometimes change.
Additional Fields (optional):
See OIDCOIDC for information regarding additional optional fields.
- After completing the configuration, click Submit to save the new authorization source.
Manually Add Users from Google
After the authorization source is created, users can be created manually to utilize Google as their source for login.
- From the Top Menu, click System -> Users
- From the left menu, click New
- Authorization Source - Select Google as the source from the dropdown list.
- Username - unique name; typically recommended to use the same login as Google.
- Remote Username - recommended to use the user's Google ID.
- Display Name - (optional) If Update User Display Name is enabled on the Google auth source, the display name will automatically synchronize from the Google user.
- Email Address - (optional) If Update User Email Address is enabled on the Google auth source, the email address will automatically synchronize from the Google user.
- Click Submit