Skip to content

Single Sign On

PhotoDock edited this page Jun 6, 2026 · 1 revision

Single sign‑on (SSO)

Users can sign in to PhotoDock with Microsoft or Google instead of a password. The login page shows a "Sign in with Microsoft" and/or "Sign in with Google" button — each appears only when that provider is configured.

Requirements

SSO reuses the same apps as cloud import:

  • Microsoft — the global app in Settings → Cloud photo sources → OneDrive import (Client ID; PKCE).
  • Google — the global app in Settings → Cloud photo sources → Google Drive import (Client ID + secret).

So if you've already set up import, SSO is available with no extra setup. See Cloud photo sources for the app registration steps.

How it works

  1. A user connects their Microsoft/Google account once on their Account page (this links the account).
  2. After that, Sign in with Microsoft/Google logs them straight in.
  3. Matching is by the provider's stable account id, then by email, then by the user's PhotoDock email — so no auto‑provisioning: only users who have linked an account can use SSO. Blocked accounts are denied.

Notes

  • The session cookie is SameSite=Lax so the OAuth redirect actually signs you in. If a first attempt seems stuck, fully log out once (clear the auth_token cookie) and retry.
  • Personal Microsoft accounts: ensure the app's Supported account types includes personal accounts.
  • Personal Google accounts: add them as Test users on the OAuth consent screen until the app is verified.
  • Microsoft SSO always uses the global app (the login page has no logged‑in user yet), so per‑user "bring your own app" enables import but not the Sign in with Microsoft button.

Username/password login (and 2FA, password reset, invites) keep working alongside SSO — see Users, roles & security.

Clone this wiki locally