Authentication

This chapter describes various ways to authenticate to Continuwuity.

Authentication flows

Continuwuity implements the following authentication flows:

  • OAuth login (also known as next-gen auth): clients redirect the user to Continuwuity's own login and registration page to complete the authentication process.
  • Legacy login (also known as the User Interactive Authentication framework): clients provide their own UI to log in to or register with the server directly.

Different sets of clients support different flows, but most clients are moving towards next-gen auth. One can set which login modes are allowed via the compatibility_mode variable of the [global.oauth] config file section.

Configure your client well-known for OAuth logins

To ensure OAuth logins work, Continuwuity must know the base URL its Client-Server API is being served on:

[global.well_known]
client = "https://matrix.example.com"

Refer to the delegation documentation for more details.

Authentication sources

Continuwuity can read user authentication data from the following sources:

  • Internal authentication - this is the default setup, where Continuwuity reads user authentication data from its local database. It allows for registration, email, and password reset self-service. See the internal authentication documentation.

  • Delegated authentication - in this mode, the server connects to an OpenID Connect identity provider for user authentication. This method allows for integrating with single sign-on services, but enabling it will disable legacy logins. See the delegated authentication documentation.

Only one authentication source can be used at a time.