Claude be2b1a1127
docs: port Wave 1 OIDC provider guides (all 5)
All five OIDC provider walkthroughs now live under administration/oidc/,
consistent in structure: prereqs → provider-side config → RomM env vars →
email matching → test → optional role mapping.

- administration/oidc/authelia.md: claims policy + client config
- administration/oidc/authentik.md: 2025.10 email_verified property
  mapping, provider + application setup
- administration/oidc/keycloak.md: previously orphaned; now linked from
  Navigation.md and the OIDC hub. Uses DISABLE_USERPASS_LOGIN (replacing
  the old doc's PASSWORD_AUTH_ENABLED which doesn't exist in the env
  template)
- administration/oidc/pocketid.md: passkey-only flow
- administration/oidc/zitadel.md: project/app setup, "User Info inside
  ID Token" fix for the "Email is missing from token" error

All cross-link to the hub's role-mapping section and to
troubleshooting/authentication.md.

Builds clean with --strict.
2026-04-18 16:46:45 +00:00
..
2026-04-15 20:13:19 -04:00
2026-02-13 09:20:48 -05:00
2026-04-15 20:13:19 -04:00
2026-02-28 14:19:25 -05:00
2025-10-27 17:32:41 -04:00
2025-11-11 17:56:03 -05:00