Sites that delegate all sign-in to an OIDC provider had no way to skip
the password form. New sso_auto_redirect setting (admin > Settings >
User session) makes /session forward straight to /session/sso via
location.replace so the back button cannot trap users in a redirect
loop. ?nosso=1 and an existing sso_error keep the password form
reachable for admin recovery; OAuth app-consent flows are unaffected.
Generated with [Devin](https://devin.ai)
Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
"ssoIssuerDes":"Base URL of the OIDC issuer, e.g. <0>https://keycloak.example.com/realms/master</0>. The provider metadata is fetched from <1>.well-known/openid-configuration</1> under this URL.",
"ssoIssuerDes":"Base URL of the OIDC issuer, e.g. <0>https://keycloak.example.com/realms/master</0>. The provider metadata is fetched from <1>.well-known/openid-configuration</1> under this URL.",
"ssoRegisterEnabledDes":"Automatically create a local account when a user signs in via SSO for the first time. The sign-up email filter below also applies.",
"ssoRegisterEnabledDes":"Automatically create a local account when a user signs in via SSO for the first time. The sign-up email filter below also applies.",
"ssoAutoRedirect":"Auto redirect to SSO",
"ssoAutoRedirectDes":"Skip the login form and send visitors straight to the identity provider. Append <0>?nosso=1</0> to the login URL to reach the password form (e.g. for admin recovery).",
"ssoCallbackUrl":"Callback URL",
"ssoCallbackUrl":"Callback URL",
"ssoCallbackUrlDes":"Register this URL as the redirect/callback URL in your identity provider: <0>{{url}}</0>",
"ssoCallbackUrlDes":"Register this URL as the redirect/callback URL in your identity provider: <0>{{url}}</0>",