Improve user-facing OIDC errors when no role is matched #7436
Labels
c-gj
Internal Customer Reference
c-ju
Internal Customer Reference
error-msg
Improving customer facing error messages.
feature-request
Used for new features in Teleport, improvements to current should be #enhancements
support-load
This issue generates support load
What
What would you like Teleport to do differently? Improve the user-facing OIDC errors if/when an SSO user doesn't match any roles. At present, the displayed error is "Login Unsuccessful" and "unable to process callback".
How
How would you implement this? Display a friendly user-error "Unable to match your account to any roles, contact your Teleport administrator" or even better a configurable error message for this condition. I can see organizations enriching this type of failure with domain-specific details (support e-mail, links to create tickets, etc...)
Why
Why do you need this? It provides some context for the user and the initial support contact.
Workaround
N/A
The text was updated successfully, but these errors were encountered: