-
-
Notifications
You must be signed in to change notification settings - Fork 81
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
add new @login endpoint to return available external login options (#…
…1757) * add new @login endpoint to return available external login options * changelog * lint * lint * lint * lint * lint * Update news/1757.feature Co-authored-by: Steve Piercy <web@stevepiercy.com> * Update news/1757.feature Co-authored-by: Steve Piercy <web@stevepiercy.com> * Update news/1757.feature Co-authored-by: Steve Piercy <web@stevepiercy.com> * add docs * yaml * yaml * docs * docs * Review of docs * Revert `'` to `"` * properly implement the adapter in tests * add docs rsults * black * fix response * rename the interface to ILoginProviders * Apply suggestions from code review --------- Co-authored-by: Steve Piercy <web@stevepiercy.com> Co-authored-by: David Glick <david@glicksoftware.com>
- Loading branch information
1 parent
7af9649
commit 74f3d72
Showing
10 changed files
with
226 additions
and
4 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,71 @@ | ||
--- | ||
myst: | ||
html_meta: | ||
"description": "The @login endpoint exposes the list of external authentication services that may be used in the Plone site." | ||
"property=og:description": "The @login endpoint exposes the list of external authentication services that may be used in the Plone site." | ||
"property=og:title": "@login for external authentication links" | ||
"keywords": "Plone, plone.restapi, REST, API, login, authentication, external services" | ||
--- | ||
|
||
# Login for external authentication links | ||
|
||
It is common to use add-ons that allow logging in to your site using third party services. | ||
Such add-ons include using authentication services provided by KeyCloak, GitHub, or other OAuth2 or OpenID Connect enabled services. | ||
|
||
When you install one of these add-ons, it modifies the login process, directing the user to third party services. | ||
|
||
To expose the links provided by these add-ons, `plone.restapi` provides an adapter based service registration. | ||
It lets those add-ons know that the REST API can use those services to authenticate users. | ||
This will mostly be used by frontends that need to show the end user the links to those services. | ||
|
||
To achieve that, third party products need to register one or more adapters for the Plone site root object, providing the `plone.restapi.interfaces.IExternalLoginProviders` interface. | ||
|
||
In the adapter, the add-on needs to return the list of external links and some metadata, including the `id`, `title`, and name of the `plugin`. | ||
|
||
An example adapter would be the following, in a file named {file}`adapter.py`: | ||
|
||
```python | ||
from zope.component import adapter | ||
from zope.interface import implementer | ||
|
||
@adapter(IPloneSiteRoot) | ||
@implementer(IExternalLoginProviders) | ||
class MyExternalLinks: | ||
def __init__(self, context): | ||
self.context = context | ||
|
||
def get_providers(self): | ||
return [ | ||
{ | ||
"id": "myprovider", | ||
"title": "Provider", | ||
"plugin": "pas.plugins.authomatic", | ||
"url": "https://some.example.com/login-url", | ||
}, | ||
{ | ||
"id": "github", | ||
"title": "GitHub", | ||
"plugin": "pas.plugins.authomatic", | ||
"url": "https://some.example.com/login-authomatic/github", | ||
}, | ||
] | ||
``` | ||
|
||
With the corresponding ZCML stanza, in the corresponding {file}`configure.zcml` file: | ||
|
||
```xml | ||
<adapter factory=".adapter.MyExternalLinks" name="my-external-links"/> | ||
``` | ||
|
||
The API request would be as follows: | ||
|
||
```{eval-rst} | ||
.. http:example:: curl httpie python-requests | ||
:request: ../../../src/plone/restapi/tests/http-examples/external_authentication_links.req | ||
``` | ||
|
||
The server will respond with a `Status 200` and the list of external providers: | ||
|
||
```{literalinclude} ../../../src/plone/restapi/tests/http-examples/external_authentication_links.resp | ||
:language: http | ||
``` |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1 @@ | ||
Add a `@login` endpoint to get external login services' links. @erral |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,14 @@ | ||
# -*- coding: utf-8 -*- | ||
from plone.restapi.interfaces import ILoginProviders | ||
from plone.restapi.services import Service | ||
from zope.component import getAdapters | ||
|
||
|
||
class Login(Service): | ||
def reply(self): | ||
adapters = getAdapters((self.context,), ILoginProviders) | ||
external_providers = [] | ||
for name, adapter in adapters: | ||
external_providers.extend(adapter.get_providers()) | ||
|
||
return {"options": external_providers} |
3 changes: 3 additions & 0 deletions
3
src/plone/restapi/tests/http-examples/external_authentication_links.req
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,3 @@ | ||
GET /plone/@login HTTP/1.1 | ||
Accept: application/json | ||
Authorization: Basic YWRtaW46c2VjcmV0 |
19 changes: 19 additions & 0 deletions
19
src/plone/restapi/tests/http-examples/external_authentication_links.resp
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,19 @@ | ||
HTTP/1.1 200 OK | ||
Content-Type: application/json | ||
|
||
{ | ||
"options": [ | ||
{ | ||
"id": "myprovider", | ||
"plugin": "myprovider", | ||
"title": "Provider", | ||
"url": "https://some.example.com/login-url" | ||
}, | ||
{ | ||
"id": "github", | ||
"plugin": "github", | ||
"title": "GitHub", | ||
"url": "https://some.example.com/login-authomatic/github" | ||
} | ||
] | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters