Our team is building authentication/authorization capabilities for our app. The app is intended for the enterprise audience. The app is going to use OIDC/OAuth2 for authentication and authorization. We need to support a couple of things:
- Being able to support SAML2.0
- Being able to use the enterprise IdP to get user scopes.
From research, it seems we need to employ some kind of an authentication broker but I'm trying to understand a few things on how the flow works.
How will the customer IdP know how to provide our application scope? What is the broker responsible for? (Just be a pipeline between customer IdP and our app) How do the SAML assertion being translated to the Oauth2.0 scopes?