Repository navigation
Customised federated cloud id to prevent something like [email protected]@nextcloud.mydomain.ltd #782
Description
Activity
@schiessle wasn't there some discussion ongoing already?
Yes, we discussed this already and it sounds link a interesting idea. The difficult part is that someone would need to maintain the mapping and make sure that it is always up-to-date.
I think @icewind1991 had some similiar ideas...
The difficult part is that someone would need to maintain the mapping and make sure that it is always up-to-date.
True but this is already the case in some way for uid mapping in the LDAP configuration.
I think the resolving can be done using well-known URIs
For example if original federated cloud id is :
[email protected]@nextcloud.example.comand we want to use : [email protected]We should : add a .well-known redirection like this : https://example.com/.well-known/federated-cloud -> https://nextcloud.example.com
So when we try to share to [email protected], nextcloud behave like this :
- Try to connect to a federated cloud instance at example.com with user
user - If not found try to find a .well-known redirection
- If redirection found, try to connect with user
user - If user
usernot found, try with user[email protected]
This way no user mapping is needed, only some basic redirection that already works with DAV.
What do you think ?
Reacted by Antoine Vacher and Simó Albert i Beltran- Try to connect to a federated cloud instance at example.com with user
It looks quite simple and efficient indeed.
This all sounds good and like a really interesting approach. But there is one open question for me:
- How should we decide which federated cloud ID we show in the users personal settings? Right now we always construct it with
<user>@<nextcloud>. If we enable this well-known redirecty it could be onlyuseror even something completely different. For example I would like to use my email address and put the well known re-direct to my personal domain.
Any idea to solve this problem? Should we just allow people to set their own federated cloud id in the personal settings?
- How should we decide which federated cloud ID we show in the users personal settings? Right now we always construct it with
If we solve the remaining questions I would love to add it to the road map for Nextcloud 12. Of course I would also be happy if some of you would like to work on it 😃
I think this should be decided by the Nextcloud administrator.
The choices can be:
- Full id (
[email protected]@nextcloud.example.com) - Full username, custom domain (
[email protected]@example.com) - Short username, full domain (
[email protected]) - Short username, custom domain (
[email protected])
Short username can be determined like this:
- If there is an @ inside the username
- Split the username on the first @ and the short username is the first split result
- Else
- The short username is the full username
The domain should be customizable by the administrator. Because he can setup the
.well-knowredirection with any domain he owns.Perhaps a check should be added in the administration panels to alert the administrator when the customized domain doesn't redirect to the nextcloud instance.
I would like to work on that, but my last year of engineering school is taking too much time !
Reacted by Antoine Vacher, Gaspard d'Hautefeuille, DJCrashdummy, Simó Albert i Beltran, Tommy Sparber and Daniel Scharon- Full id (
Another possibility is to use a DNS record (SRV) like this :
_nextcloud._tcp.example.org. 3600 IN SRV 0 10 443 nextcloud.exemple.org.Reacted by Baudouin Feildel, kulga, Mirsal, Simó Albert i Beltran, Daniel Scharon, Tommy Sparber, Joel Lopes Da Silva and Gyula Szabó@icewind1991 I think this goes in the same direction we just discussed
- addedstaleTicket or PR with no recent activityTicket or PR with no recent activity
on Jun 20, 2018 Are there any ongoing design discussion on this topic?
Reacted by Daniel Scharon- removedstaleTicket or PR with no recent activityTicket or PR with no recent activity
on Jul 24, 2018 is there any progress regarding this concept?
Reacted by Joel Lopes Da Silva and Alexey Abel- added0. Needs triagePending check for reproducibility or if it fits our roadmapPending check for reproducibility or if it fits our roadmap1. to developAccepted and waiting to be taken care ofAccepted and waiting to be taken care ofand removed0. Needs triagePending check for reproducibility or if it fits our roadmapPending check for reproducibility or if it fits our roadmap
on Aug 20, 2020 I would really love to see this feature request get some traction. I think it would be great if Nextcloud users were really able to use their email address as their federated cloud ID (at least for users who have control over the domain name used in their email address). This would allow such users to have a stable federated cloud ID, regardless of the Nextcloud server they're currently using to store their data.
Reacted by Daniel Scharon, Paul van Tilburg and Gyula SzabóRelated #365
- addedhotspot: account name handlingUser / Group names - invalid, consistency, enforcement, etc.User / Group names - invalid, consistency, enforcement, etc.
on Jul 16, 2025
This is a repost of an issue that I originaly opened on owncloud/core#23412 but that did not get a definitive answer. Maybe with nextcloud it would be different :)
This is a thought about the federated cloud Id.
I have a LDAP for all my users and in every hosted service, the user name is mapped to the email. Let's say [email protected]
I configured a nextcloud instance on nextcloud.mydomain.ltd with LDAP and the users can successfully use it using their user name [email protected]
So far so good.
However, when they want to share their federated cloud id, they have to share john.doe@[email protected] which is quite non-intuitive as:
I completely understand why the federated cloud id is currently defined as it is. However there may be additional options that could be added. For instance, why not having something like this:
About
<right-part>:-If false: john.doe would be the username from [email protected].
-If true; username would be [email protected].
3. When a foreign owncloud user would try to share something, it would try to see if there is a http://mydomain.ltd/nextcloud-federated-sharing.xml.
-If one is found then it would try sharing using the real federated id reconstructed from the xml: john.doe@[email protected]
-If none is found then use the regular federated sharing
This is a just a first thought that is quite similar to the autoconfig of email account configuration. Maybe it would also be possible to use DNS SRV records to do this.
Let me know what you think :)