OIDC History Tracking

0
When using the OIDC module, what did you add to be able to track authentication history? There doesn't appear to be anything built into the module, like the saml module delivered. Did you just create you own tracking entities, or is there a more efficient way? Are we missing something as to why that's not delivered with the module?
asked
2 answers
0

Hi Jack,


As far as the OIDC SSO module is concerned, there isn't a built-in authentication history/audit trail that you can use directly for tracking every login attempt.


The OIDC module is primarily responsible for the OIDC authentication flow, user provisioning, token handling, and communication with the Identity Provider. The module does not provide an application-level login history entity similar to a dedicated audit log.



If you need to keep an application-specific history, I would normally implement a small custom entity, for example:

OIDCLoginHistory
----------------
User
LoginDateTime
IdentityProvider
Success
FailureReason

and populate it from the appropriate authentication/provisioning flow.


However, I would first decide what exactly you need to audit. If you only need successful logins, application-level tracking is relatively straightforward. If you also need failed authentication attempts, MFA information, IP address, or the actual authentication method used, I would recommend getting that information from the Identity Provider's audit/sign-in logs instead. The OIDC module does not see the user's password/MFA interaction at the IdP.


This is also why I wouldn't try to modify the OIDC module itself to create a complete authentication audit trail. Keep the OIDC module responsible for authentication and keep your application-specific history in your own module/entity.


For example:

User
  ↓
OIDC login
  ↓
Identity Provider
  ↓
Authentication succeeds
  ↓
Mendix OIDC flow / user provisioning
  ↓
Create OIDCLoginHistory record

For failed logins:

User
  ↓
Identity Provider
  ↓
Authentication failure
  ↓
IdP audit/sign-in logs

The second flow is important because a failed login at the IdP may happen before the request successfully reaches the Mendix application, so there isn't necessarily a Mendix user/session from which your microflow could create a history record.


If the requirement is primarily security/compliance auditing, I would therefore use the IdP's sign-in/audit logs as the authoritative source and only maintain a Mendix-side history if the application needs that information for reporting or business logic.


Hope this helps.

answered
0

Hey Jack Foster,

We also noticed that the OIDC module does not have anything built in for tracking authentication history like the SAML module.

For our implementation, we created our own tracking entity and stored the authentication details whenever the user logs in. This works fine for us and also gives us the flexibility to store whatever details we need.

As far as I know, there is no additional configuration or feature that we were missing in the OIDC module. The authentication history functionality is simply not provided out of the box like it is in the SAML module.

So currently, creating a custom tracking entity seems to be the most straightforward approach if you need authentication history/auditing.

Regards
Reemali

answered