Sso Saml Oidc
Skill Profile
(Select at least one profile to enable specific modules)
Overview
Single Sign-On (SSO) enables users to authenticate once and access multiple applications. This skill covers implementing SSO with SAML 2.0 (enterprise standard) and OpenID Connect (OIDC, modern OAuth 2.0-based) for enterprise authentication, including JIT provisioning, group/role mapping, and multi-tenancy support.
Why This Matters
- Enterprise Requirement: SSO is mandatory for most enterprise deals
- Security: Centralized authentication with MFA enforcement
- User Experience: No password fatigue, seamless access to all apps
- Operational Efficiency: Automated onboarding/offboarding through IdP
Core Concepts & Rules
1. Core Principles
- Follow established patterns and conventions
- Maintain consistency across codebase
- Document decisions and trade-offs
2. Implementation Guidelines
- Start with the simplest viable solution
- Iterate based on feedback and requirements
- Test thoroughly before deployment
Inputs / Outputs / Contracts
- Inputs:
- SAML assertion (signed XML)
- OIDC ID token (JWT)
- IdP metadata (SAML) or discovery endpoint (OIDC)
- Client credentials (client_id, client_secret)
- Entry Conditions:
- Database initialized with users table
- SSO/OIDC library installed
- IdP configuration available
- Outputs:
- Authenticated user session
- User attributes (email, name, groups)
- User roles mapped from groups
- JWT session token (optional)
- Artifacts Required (Deliverables):
- SAML/OIDC authentication endpoints
- Metadata exchange implementation
- JIT provisioning logic
- Group/role mapping configuration
- Session management (secure cookies)
- Acceptance Evidence:
- Successful SSO login with test accounts
- User attributes correctly mapped
- Group/role mapping working
- Session properly secured (httpOnly, secure)
- Success Criteria:
- SSO login works with at least 3 IdPs (Okta, Azure AD, Google)
- OIDC login works with Google, Auth0
- JIT provisioning creates/updates users
- Group/role mapping assigns correct roles
- Session is secure (httpOnly, SameSite)
Skill Composition
- Depends on: Database Design, Session Management
- Compatible with: SCIM Provisioning, Enterprise RBAC Models, Security Questionnaires
- Conflicts with: None
- Related Skills: SCIM Provisioning, Enterprise RBAC Models
Quick Start / Implementation Example
- Review requirements and constraints
- Set up development environment
- Implement core functionality following patterns
- Write tests for critical paths
- Run tests and fix issues
- Document any deviations or decisions
# Example implementation following best practices
def example_function():
# Your implementation here
pass
Assumptions / Constraints / Non-goals
- Assumptions:
- Development environment is properly configured
- Required dependencies are available
- Team has basic understanding of domain
- Constraints:
- Must follow existing codebase conventions
- Time and resource limitations
- Compatibility requirements
- Non-goals:
- This skill does not cover edge cases outside scope
- Not a replacement for formal training
Compatibility & Prerequisites
- Supported Versions:
- Python 3.8+
- Node.js 16+
- Modern browsers (Chrome, Firefox, Safari, Edge)
- Required AI Tools:
- Code editor (VS Code recommended)
- Testing framework appropriate for language
- Version control (Git)
- Dependencies:
- Language-specific package manager
- Build tools
- Testing libraries
- Environment Setup:
.env.example keys: API_KEY, DATABASE_URL (no values)
Test Scenario Matrix (QA Strategy)
| Type |
Focus Area |
Required Scenarios / Mocks |
| Unit |
Core Logic |
Must cover primary logic and at least 3 edge/error cases. Target minimum 80% coverage |
| Integration |
DB / API |
All external API calls or database connections must be mocked during unit tests |
| E2E |
User Journey |
Critical user flows to test |
| Performance |
Latency / Load |
Benchmark requirements |
| Security |
Vuln / Auth |
SAST/DAST or dependency audit |
| Frontend |
UX / A11y |
Accessibility checklist (WCAG), Performance Budget (Lighthouse score) |
Technical Guardrails & Security Threat Model
1. Security & Privacy (Threat Model)
- Top Threats: Injection attacks, authentication bypass, data exposure
2. Performance & Resources
3. Architecture & Scalability
4. Observability & Reliability
Agent Directives & Error Recovery
(ข้อกำหนดสำหรับ AI Agent ในการคิดและแก้ปัญหาเมื่อเกิดข้อผิดพลาด)
- Thinking Process: Analyze root cause before fixing. Do not brute-force.
- Fallback Strategy: Stop after 3 failed test attempts. Output root cause and ask for human intervention/clarification.
- Self-Review: Check against Guardrails & Anti-patterns before finalizing.
- Output Constraints: Output ONLY the modified code block. Do not explain unless asked.
Definition of Done (DoD) Checklist
Anti-patterns / Pitfalls
- ⛔ Don't: Log PII, catch-all exception, N+1 queries
- ⚠️ Watch out for: Common symptoms and quick fixes
- 💡 Instead: Use proper error handling, pagination, and logging
Reference Links & Examples
- Internal documentation and examples
- Official documentation and best practices
- Community resources and discussions
Versioning & Changelog
- Version: 1.0.0
- Changelog:
- 2026-02-22: Initial version with complete template structure
Converted and distributed by TomeVault — claim your Tome and manage your conversions.
1---2name: sso-saml-oidc3description: Single Sign-On (SSO) enables users to authenticate once and access multiple Use when this capability is needed.4---56# Sso Saml Oidc78## Skill Profile9*(Select at least one profile to enable specific modules)*10- [ ] **DevOps**11- [x] **Backend**12- [ ] **Frontend**13- [ ] **AI-RAG**14- [ ] **Security Critical**1516## Overview17Single Sign-On (SSO) enables users to authenticate once and access multiple applications. This skill covers implementing SSO with SAML 2.0 (enterprise standard) and OpenID Connect (OIDC, modern OAuth 2.0-based) for enterprise authentication, including JIT provisioning, group/role mapping, and multi-tenancy support.1819## Why This Matters20- **Enterprise Requirement**: SSO is mandatory for most enterprise deals21- **Security**: Centralized authentication with MFA enforcement22- **User Experience**: No password fatigue, seamless access to all apps23- **Operational Efficiency**: Automated onboarding/offboarding through IdP2425---2627## Core Concepts & Rules2829### 1. Core Principles30- Follow established patterns and conventions31- Maintain consistency across codebase32- Document decisions and trade-offs3334### 2. Implementation Guidelines35- Start with the simplest viable solution36- Iterate based on feedback and requirements37- Test thoroughly before deployment383940## Inputs / Outputs / Contracts41* **Inputs**:42 - SAML assertion (signed XML)43 - OIDC ID token (JWT)44 - IdP metadata (SAML) or discovery endpoint (OIDC)45 - Client credentials (client_id, client_secret)46* **Entry Conditions**:47 - Database initialized with users table48 - SSO/OIDC library installed49 - IdP configuration available50* **Outputs**:51 - Authenticated user session52 - User attributes (email, name, groups)53 - User roles mapped from groups54 - JWT session token (optional)55* **Artifacts Required (Deliverables)**:56 - SAML/OIDC authentication endpoints57 - Metadata exchange implementation58 - JIT provisioning logic59 - Group/role mapping configuration60 - Session management (secure cookies)61* **Acceptance Evidence**:62 - Successful SSO login with test accounts63 - User attributes correctly mapped64 - Group/role mapping working65 - Session properly secured (httpOnly, secure)66* **Success Criteria**:67 - SSO login works with at least 3 IdPs (Okta, Azure AD, Google)68 - OIDC login works with Google, Auth069 - JIT provisioning creates/updates users70 - Group/role mapping assigns correct roles71 - Session is secure (httpOnly, SameSite)7273## Skill Composition74* **Depends on**: Database Design, Session Management75* **Compatible with**: SCIM Provisioning, Enterprise RBAC Models, Security Questionnaires76* **Conflicts with**: None77* **Related Skills**: [SCIM Provisioning](file://50-enterprise-integrations/scim-provisioning/SKILL.md), [Enterprise RBAC Models](file://50-enterprise-integrations/enterprise-rbac-models/SKILL.md)7879---8081## Quick Start / Implementation Example82831. Review requirements and constraints842. Set up development environment853. Implement core functionality following patterns864. Write tests for critical paths875. Run tests and fix issues886. Document any deviations or decisions8990```python91# Example implementation following best practices92def example_function():93 # Your implementation here94 pass95```969798## Assumptions / Constraints / Non-goals99100* **Assumptions**:101 - Development environment is properly configured102 - Required dependencies are available103 - Team has basic understanding of domain104* **Constraints**:105 - Must follow existing codebase conventions106 - Time and resource limitations107 - Compatibility requirements108* **Non-goals**:109 - This skill does not cover edge cases outside scope110 - Not a replacement for formal training111112113## Compatibility & Prerequisites114115* **Supported Versions**:116 - Python 3.8+117 - Node.js 16+118 - Modern browsers (Chrome, Firefox, Safari, Edge)119* **Required AI Tools**:120 - Code editor (VS Code recommended)121 - Testing framework appropriate for language122 - Version control (Git)123* **Dependencies**:124 - Language-specific package manager125 - Build tools126 - Testing libraries127* **Environment Setup**:128 - `.env.example` keys: `API_KEY`, `DATABASE_URL` (no values)129130131## Test Scenario Matrix (QA Strategy)132133| Type | Focus Area | Required Scenarios / Mocks |134| :--- | :--- | :--- |135| **Unit** | Core Logic | Must cover primary logic and at least 3 edge/error cases. Target minimum 80% coverage |136| **Integration** | DB / API | All external API calls or database connections must be mocked during unit tests |137| **E2E** | User Journey | Critical user flows to test |138| **Performance** | Latency / Load | Benchmark requirements |139| **Security** | Vuln / Auth | SAST/DAST or dependency audit |140| **Frontend** | UX / A11y | Accessibility checklist (WCAG), Performance Budget (Lighthouse score) |141142143## Technical Guardrails & Security Threat Model144145### 1. Security & Privacy (Threat Model)146* **Top Threats**: Injection attacks, authentication bypass, data exposure147- [ ] **Data Handling**: Sanitize all user inputs to prevent Injection attacks. Never log raw PII148- [ ] **Secrets Management**: No hardcoded API keys. Use Env Vars/Secrets Manager149- [ ] **Authorization**: Validate user permissions before state changes150151### 2. Performance & Resources152- [ ] **Execution Efficiency**: Consider time complexity for algorithms153- [ ] **Memory Management**: Use streams/pagination for large data154- [ ] **Resource Cleanup**: Close DB connections/file handlers in finally blocks155156### 3. Architecture & Scalability157- [ ] **Design Pattern**: Follow SOLID principles, use Dependency Injection158- [ ] **Modularity**: Decouple logic from UI/Frameworks159160### 4. Observability & Reliability161- [ ] **Logging Standards**: Structured JSON, include trace IDs `request_id`162- [ ] **Metrics**: Track `error_rate`, `latency`, `queue_depth`163- [ ] **Error Handling**: Standardized error codes, no bare except164- [ ] **Observability Artifacts**:165 - **Log Fields**: timestamp, level, message, request_id166 - **Metrics**: request_count, error_count, response_time167 - **Dashboards/Alerts**: High Error Rate > 5%168169170## Agent Directives & Error Recovery171*(ข้อกำหนดสำหรับ AI Agent ในการคิดและแก้ปัญหาเมื่อเกิดข้อผิดพลาด)*172173- **Thinking Process**: Analyze root cause before fixing. Do not brute-force.174- **Fallback Strategy**: Stop after 3 failed test attempts. Output root cause and ask for human intervention/clarification.175- **Self-Review**: Check against Guardrails & Anti-patterns before finalizing.176- **Output Constraints**: Output ONLY the modified code block. Do not explain unless asked.177178179## Definition of Done (DoD) Checklist180181- [ ] Tests passed + coverage met182- [ ] Lint/Typecheck passed183- [ ] Logging/Metrics/Trace implemented184- [ ] Security checks passed185- [ ] Documentation/Changelog updated186- [ ] Accessibility/Performance requirements met (if frontend)187188189## Anti-patterns / Pitfalls190191* ⛔ **Don't**: Log PII, catch-all exception, N+1 queries192* ⚠️ **Watch out for**: Common symptoms and quick fixes193* 💡 **Instead**: Use proper error handling, pagination, and logging194195196## Reference Links & Examples197198* Internal documentation and examples199* Official documentation and best practices200* Community resources and discussions201202203## Versioning & Changelog204205* **Version**: 1.0.0206* **Changelog**:207 - 2026-02-22: Initial version with complete template structure208209---210> Converted and distributed by [TomeVault](https://tomevault.io/claim/amnadtaowsoam) — claim your Tome and manage your conversions.211<!-- tomevault:4.0:skill_md:2026-04-13 -->