徕卡三维激光扫描产品中文培训与文档中心

如何配置你的 OIDC SSO | Hexagon GeoCloud

How to configure your OIDC SSO

中文 原文更新:— 查看英文原文 ↗

开始之前

选择公司 <alias>:

  1. 必须全部为小写字母;
  2. 不含特殊字符;
  3. 最多 23 个字符。

前提条件:

字段 值
Redirect URI https://hxauth.com/auth/realms/nsi-ext-<alias>/broker/oidc/endpoint(将 <alias> 替换为你的公司别名)
Application type Web(非单页应用 Single-Page Application)

配置 OIDC SSO

请遵循微软指南:Configure OIDC SSO for gallery and custom applications - Microsoft Entra ID | Microsoft Learn

  1. 遵循上方配置前提条件中的第 1–3 步。
  2. 第 4 步 —— 跳过 —— 无需特殊权限。
  3. 第 5 步 —— 跳过 —— 仅需默认声明(claims)。
  4. 第 6 步 —— 按指南所述执行。将 OIDC 元数据文档复制到 SSO 注册表。注意:OIDC 元数据文档不包含任何敏感信息(如 Client Secret),它包含的是 OIDC 流程所需的各类 URI 等元数据。
  5. 第 7 步 —— 使用指南中提到的典型作用域(scopes),即 openid profile email。记下 Client ID 与 Client Secret —— 你需要在 SSO 注册表中提供这些值。