This directory contains Keycloak-specific configuration files. Keycloak is optional - the SSO implementation works with any OIDC/SAML provider.
If you want to use Keycloak as your SSO provider, this directory contains:
import/crossview-realm.json- Realm configuration for Keycloak- Docker Compose configuration to auto-import the realm
-
Start Keycloak:
docker-compose up -d keycloak
-
Wait for Keycloak to start (about 30 seconds), then configure:
For OIDC:
node scripts/get-keycloak-secret.js
For SAML:
node scripts/get-keycloak-saml-cert.js
Or both:
node scripts/get-keycloak-secret.js node scripts/get-keycloak-saml-cert.js
-
Restart your server to load the configuration.
The realm is configured with both:
- OIDC Client:
crossview-client - SAML Client:
crossview-saml
Both use the same realm and users. You can enable both in config/config.yaml to see both login options.
A test user is included:
- Username:
testuser - Password:
test123
The SSO implementation is provider-agnostic and works with any OIDC or SAML provider. Simply configure your provider's details in config/config.yaml:
sso:
enabled: true
oidc:
enabled: true
issuer: https://your-provider.com/realms/your-realm
clientId: your-client-id
clientSecret: your-client-secret
callbackURL: http://localhost:3001/api/auth/oidc/callback
scope: openid profile emailsso:
enabled: true
saml:
enabled: true
entryPoint: https://your-provider.com/saml/sso
issuer: your-issuer-name
callbackURL: http://localhost:3001/api/auth/saml/callback
cert: |-
-----BEGIN CERTIFICATE-----
Your SAML certificate here
-----END CERTIFICATE-----The implementation works with:
- OIDC: Any OpenID Connect provider (Auth0, Okta, Azure AD, Google, Keycloak, etc.)
- SAML: Any SAML 2.0 provider (Okta, Azure AD, OneLogin, ADFS, etc.)
Just configure the appropriate endpoints and credentials for your provider.