There are several problems to tackle at the moment:
- Setup issues:
- The OC10's openidconnect app doesn't seems to work without HTTPS (PKCE issue even after removing the cookie setting as documented).
- SSL certificate check can't be disabled for the openidconnect app. I had to touch the code to disable the check (not sure if it's worthy to allow this from the configuration because admins should use valid certificates anyway)
- Migration issues:
- Users to be migrated MUST have logged in at least once in BOTH systems. This will cause problems.
- The user must have logged in OC10 to it's known to the migration tool.
- If the user hasn't logged in oCIS, the migration tool won't find the user when it needs to assign roles, transfer files, etc.
- The migration tool uses the OC10 username to find users in oCIS. If OC10's Keycloak isn't properly configured the migration tool won't find the users in oCIS, which will cause problems.
- I think the default configuration for the openidconnect will use the email as OC10 username. This conflicts with the default Keycloak setup we have for oCIS.
- For these cases, we could setup the OC10 username of each user either manually or via script. However, we don't have an easy way to do it at the moment, and we'll need some time to implement a proper solution.
- Since we should consider the OC10's Keycloak client as base, the oCIS' one might need to be compatible with the OC10 one. This means that, if OC10 is using the email as username, the oCIS client will need to also use the email as username.
There are several problems to tackle at the moment: