GLAM

Externals

External organizations (customers and partners) under openxchange/external: their accounts and the projects shared with them.

How external access works
  1. Create the group here. GLAM creates openxchange/external/<slug> with a SAML group link external-<slug> at the role you choose - the maximum permission everyone entering through the LDAP group gets. The slug is the group URL and the LDAP contract; the display name is free-form and can differ.
  2. File the IT ticket. Ask internal IT at oox.io/help to create the LDAP group external-<slug> and add the external's accounts to it. The LDAP group name always follows the URL slug, never the display name.
  3. Accounts appear on first sign-in. The SAML link maps the LDAP group into GitLab membership when each person first logs in; until then the group looks empty here. Send the external's users the sign-in instructions below so they know how.
  4. Share projects or groups from the external's page. GLAM handles the share_with_group_lock unlock on locked ancestors and records every unlock in the audit log. Unshare from the same place to offboard.
Sign-in instructions for external users

Send this to the external's users once their LDAP group exists. Their accounts are created on first sign-in through the group SSO link:

https://gitlab.com/groups/openxchange/-/saml/sso?token=P1nBqh-3

  1. Open the link and click the sign-in button; you'll land on the Open-Xchange login page.
  2. Sign in with the Open-Xchange SSO credentials provided by your Open-Xchange contact.
  3. GitLab creates a GitLab.com account linked to your SSO identity - follow the prompts (confirm your email, accept a username).
  4. You now see the projects shared with your organization. Bookmark the link: it also refreshes an expired SSO session.

Users who already have a GitLab.com account with the same email should sign in to it first, then open the link to connect it to the SSO instead of creating a new account.