| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Name | Name | Last commit date | ||
|---|---|---|---|---|
This is a Plone authentication plugin for OpenID Connect. OAuth 2.0 should work as well because OpenID Connect is built on top of this protocol.
If you need to support group enumeration from a Keycloak server, we recommend installing the package pas.plugins.keycloakgroups.
This package supports Plone sites using Volto and Classic UI.
For proper Volto support, the requirements are:
Add pas.plugins.oidc to the Plone installation using pip:
bash pip install pas.plugins.oidc
As of version 2.* of this package the minimum requirements are Plone 6.0 and python 3.8.
Pay attention to the customization of User info property used as userid field, with the wrong configuration it's easy to impersonate another user.
When using this plugin with a Volto frontend, please install @plone-collective/volto-authomatic add-on on your frontend project.
Also, on the OpenID provider, configure the Redirect URL as <Path to your Plone site>/login-oidc/oidc.
When using this plugin with Plone 6 Classic UI the standard URLs used for login (http://localhost:8080/Plone/login) and logout (http://localhost:8080/Plone/logout) will not trigger the usage of the plugin.
To login into a site using the OIDC provider, you will need to change those login URLs to the following:
Where:
Plone Site Id: is the id you gave to the Plone site when you created it. It is usually Plone but may vary. It is the last part of the URL when you browse Plone directly without using any proxy server, ex. http://localhost:8080/Plone+ -> Plone.
oidc pas plugin id: is the id you gave to the OIDC plugin when you created it inside the Plone PAS administration panel. If you just used the default configuration and installed this plugin using Plone's Add-on Control Panel, this id will be oidc.
The pas.plugins.oidc repository has a working setup for a Keycloak development server using Docker and Docker Compose. To use it, in a terminal, run the command:
make keycloak-startThis does not give you a production setup, but it is fine for local development.
This command will use the docker-compose.yml file available in the tests directory.
After start up, Keycloak will be accessible on http://127.0.0.1:8180, and you can manage it with the following credentials:
There are two realms configured plone and plone-test. The later is used in automated tests, while the former should be used for your development environment.
The plone realm ships with an user that has the following credentials:
And, to configure the oidc plugins, please use:
To stop a running Keycloak (needed when running tests), use:
make keycloak-stopAttention, before Keycloak 18, the parameter for logout was redirect_uri and it has been deprecated since version 18. But the Keycloak server can run with the redirect_uri if needed, it is possible to use the plugin with the legacy redirect_uri parameter enabled also. The problem is that if the deprecated parameter is enabled in the plugin but not in the server, the plugin will not work.
So, this is the way it works:
So, for Keycloak, it does not matter if we use the default or legacy mode if the Keycloak runs in legacy mode.
Notes:
Please refer to the Keycloak documentation for up to date instructions. Specifically, here we will use a Docker image, so follow the instructions on how to get started with Keycloak on Docker.
Plone is ready done configured!
See this screenshot:
Go to the other browser, or logout as admin from Keycloak Admin Console. Currently, the Plone login form is unchanged.
Instead, for testing go to the login page of the plugin: http://localhost:8080/Plone/acl_users/oidc/login, this will take you to Keycloak to login, and then return. You should now be logged in to Plone, and see the full name and email, if you have set this in Keycloak.
If the login did work as expected you can try to Plone logout. Currently, the Plone logout form is unchanged.
Instead, for testing go to the logout page of the plugin: http://localhost:8080/Plone/acl_users/oidc/logout, this will take you to Keycloak to logout, and then return to the post-logout redirect URL.
OIDC Backchannel Logout is a server-to-server mechanism where the IdP notifies RPs via an HTTP POST request to terminate user sessions upon logout, ensuring secure and seamless Single Logout (SLO) without relying on the user's browser. See the specification OpenID Connect Back-Channel Logout 1.0.
Current backchannel logout implementation, in this product, utilizes functionality introduced in plone.session >= 4.0.0 (Plone 6 and later) for server-side session invalidation (see plone.session PR plone.session#26), and, at the moment, applies only to Plone Classic UI.
To enable this functionality:
Navigate to .../acl_users/session/manage_secret and enable the Enable per-user keyring option.
Configure the OpenID Provider (e.g., Keycloak) to use the backchannel logout endpoint with the url: .../acl_users/oidc/backchannel-logout
If you need to restrict access to a specific group, you can use the Allowed groups field in the plugin configuration. If the user is not in any of the groups listed, the login will be denied.
To use this feature, you need to create a new scope in the OIDC Provider (e.g., Keycloak) and add the groups to the user's token.
In Keycloak, go to the Client Scopes section and create a new scope named groups. Then, go to the Mappers tab and create a new mapper with the name groups and type Group Membership (Uncheck the Full groups path option). You can find this configuration in the plone realm in the tests directory. The plone client is also configured to use the groups scope.
After that, go to the Client Scopes section and add the new scope to the client you are using with the plugin (for instance, plone).
Finally, in the plugin configuration, add groups to the scopes field.
In the Allowed groups field, you can add the groups that are allowed to log in. For example, in this repository, you could set Foundation Members. Users who are not in this group will not be able to log in.
This plugin uses sessions during the login process to identify the user while he goes to the OIDC provider and comes back from there.
The plugin has 2 ways of working with sessions:
Use the Zope Session Management: if the Use Zope session data manager option in the plugin configuration is enabled, the plugin will use the session configuration configured in Zope. To do so we advise using Products.mcdutils to save the session data in a memcached based storage. Otherwise, Zope will try to use a ZODB-based session which has shown several problems in the past.
Use the cookie-based session management: if the Use Zope session data manager option in the plugin configuration is disabled, the plugin will use a Cookie to save that information in the client's browser.
Optionally, instead of editing your OIDC provider settings through the ZMI, you can use collective.regenv and provide a YAML file with your settings. This is very useful if you have different settings in different environments and you do not want to edit the settings each time you move the contents.
Optionally, if you are using the Varnish caching server in front of Plone, you may see this plugin only partially working. Especially the came_from parameter may be ignored. This is because the buildout standard configuration from plone.recipe.varnish removes most cookies to improve anonymous caching.
The solution is to make sure the __ac_session cookie is added to the cookie-pass option. Check what the current default is in the buildout recipe, and update it:
You need a working python environment (system, virtualenv, pyenv, etc) version 3.8 or superior.
Then install the dependencies and a development instance using:
make installStart Plone, on port 8080, with the command:
make startThe pas.plugins.oidc repository has a working setup for a Keycloak development server using Docker and Docker Compose. To use it, in a terminal, run the command:
make keycloak-startThere are two realms configured plone and plone-test. The later is used in automated tests, while the former should be used for your development environment.
The plone realm ships with an user that has the following credentials:
To stop a running Keycloak (needed when running tests), use:
make keycloak-stopmake i18nmake formatTesting of this package is done with pytest.
Run all tests with:
make testRun all tests but stop on the first error and open a pdb session:
uv run pytest -x --pdbRun tests named TestServiceOIDCPost:
uv run pytest -k TestServiceOIDCPostThe project is licensed under the GPLv2.
| Back | FazBrowse Home | New Git URL |