Z
ZITADEL
Z
ZITADEL
Portainer & Proxmox OIDC - 'Unauthorised'
Original message was deleted
ZITADEL
Join
ZITADEL - Identity infrastructure, simplified for you.
4,316
Members
View on Discord
F
FFO
•
10/29/23, 10:09 AM
Can you share where you see unauthorised
?
F
FFO
•
10/29/23, 10:17 AM
Hm that looks like a problem getting the token
F
FFO
•
10/29/23, 10:18 AM
Do you see the http request on zitadel to
/oauth
/v2
/token
?
F
FFO
•
10/29/23, 10:18 AM
Is there something the logs on both tools
?
F
FFO
•
10/29/23, 10:25 AM
Hm
, not sure how portainer works
.
But I would guess webapp
/authorization code flow should work
F
FFO
•
10/29/23, 10:25 AM
Check the stdout logs for each container
F
FFO
•
10/29/23, 10:32 AM
Hm can you share the config you used in portainer
?
F
FFO
•
10/29/23, 10:32 AM
Maybe a path is wrong or so
F
FFO
•
10/29/23, 11:11 AM
Can it be that the identifier should be sub
?
F
FFO
•
10/29/23, 11:13 AM
Hm ok
, can you check the portainer logs
?
F
FFO
•
10/29/23, 11:13 AM
I think it is a problem getting the token
F
FFO
•
10/29/23, 11:18 AM
Oh wow
F
FFO
•
10/29/23, 11:19 AM
Do you have a proxy in front of zitadel
?
F
FFO
•
10/29/23, 11:19 AM
You can check there for the http call
F
FFO
•
10/29/23, 11:19 AM
Or enable http logs in zitadel
F
FFO
•
10/29/23, 11:20 AM
In zitadel you can also check the events viewer and see if an access token was issued
F
FFO
•
10/29/23, 11:21 AM
If KC works we should as well
. So I think it could be network related
F
FFO
•
10/29/23, 11:24 AM
Ok in that case you could check the access log of traefik for OAuth
/v2
/token calls
F
FFO
•
10/29/23, 11:24 AM
Maybe you spot an error a non 200 http error code there
F
FFO
•
10/29/23, 11:30 AM
Yes now you can filter for your user
F
FFO
•
10/29/23, 11:30 AM
Access token created events are interesting
F
FFO
•
10/29/23, 11:30 AM
Then you can look for one with the client id you use
F
FFO
•
10/30/23, 7:35 AM
You created a new project for portainer
, right
?
F
FFO
•
10/30/23, 7:36 AM
What could be is that portainer excpects the access
_token as JWT instead of opaque
, you could try change that on the application settings in zitadel
F
FFO
•
10/30/23, 8:54 AM
It is just a guess
But at least KC uses JWT all the time
F
FFO
•
10/30/23, 12:24 PM
yeah you can try that
Next page