E-infra authentication and authorization module for InvenioRDM
This remote backend adds support for Czech e-infra AAI solution - login.e-infra.cz allowing all members of czech academic community can use their home institution credentials to log in.
Installation
Add the module to your repository's pyproject.toml:
dependencies = [
"oarepo-oidc-einfra>=4.0.0",
# ...
]
Configuration
- Register a new application with e-infra OIDC Provider at
https://spadmin.e-infra.cz/. When registering the application
ensure that the Redirect URI points to
https://<my_invenio_site>:5000/oauth/authorized/e-infra/
In OIDC parameters, you need to set at least the following scopes:
- openid
- profile
- eduperson_entitlement
- isCesnetEligibleLastSeen
- organization
- Grab the Client ID and Client Secret after registering the application and add them to your ENVIRONMENT variables:
INVENIO_EINFRA_CONSUMER_KEY=*Client ID*
INVENIO_EINFRA_CONSUMER_SECRET=*Client Secret*
- Add the remote application to the site's
invenio.cfg:
from oarepo_oidc_einfra import EINFRA_LOGIN_APP
OAUTHCLIENT_REMOTE_APPS = {"e-infra": EINFRA_LOGIN_APP}
- Add the e-infra public key to your invenio.cfg or environment variables:
EINFRA_RSA_KEY = b"-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmho5h/lz6USUUazQaVT3\nPHloIk/Ljs2vZl/RAaitkXDx6aqpl1kGpS44eYJOaer4oWc6/QNaMtynvlSlnkuW\nrG765adNKT9sgAWSrPb81xkojsQabrSNv4nIOWUQi0Tjh0WxXQmbV+bMxkVaElhd\nHNFzUfHv+XqI8Hkc82mIGtyeMQn+VAuZbYkVXnjyCwwa9RmPOSH+O4N4epDXKk1V\nK9dUxf/rEYbjMNZGDva30do0mrBkU8W3O1mDVJSSgHn4ejKdGNYMm0JKPAgCWyPW\nJDoL092ctPCFlUMBBZ/OP3omvgnw0GaWZXxqSqaSvxFJkqCHqLMwpxmWTTAgEvAb\nnwIDAQAB\n-----END PUBLIC KEY-----\n"
- Add the VO, communities group, api url and others to your invenio.cfg or environment variables:
EINFRA_SERVICE_USERNAME = "username"
"""Username of the service in the E-INFRA Perun."""
EINFRA_SERVICE_PASSWORD = "password"
"""Password of the service in the E-INFRA Perun."""
EINFRA_SERVICE_ID = 0
"""Internal ID of the service (whose username and password are above) in the E-INFRA Perun."""
EINFRA_REPOSITORY_VO_ID = 0
"""Internal ID of the VO in the E-INFRA Perun that represents the repository."""
EINFRA_COMMUNITIES_GROUP_ID = 0
"""Internal ID of the group in the E-INFRA Perun that represents the communities."""
EINFRA_REPOSITORY_FACILITY_ID = 0
"""Internal ID of the facility in the E-INFRA Perun that represents the repository."""
EINFRA_CAPABILITIES_ATTRIBUTE_ID = 0
"""Internal ID of the attribute in the E-INFRA Perun that represents the capabilities."""
EINFRA_SYNC_SERVICE_ID = 0
"""Internal ID of the service in the E-INFRA Perun that is responsible for synchronization
(creating and pushing dumps with resources and users)."""
- Start the server and go to the login page https://127.0.0.1:5000/login/
Mapping global invenio roles
To map perun group to a global invenio role:
- Assign the facility to the group via a resource
- On resource, add the following capability:
res:roles:<role_name>
Users that will be members of the group will be automatically given the role (and if they are removed from the group the role will be removed).
Metadata
Release files for oarepo-oidc-einfra 8.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| oarepo_oidc_einfra-8.0.1.tar.gz | 25.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| oarepo_oidc_einfra-8.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 60.6 kB
Release files / oarepo_oidc_einfra-8.0.1.tar.gz
| Download URL | oarepo_oidc_einfra-8.0.1.tar.gz |
|---|---|
| Size | 25.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1bd79fc6e9075be0bf32cf0aa30ec00ed471447e60a78f1ea21910a69bb3dbe7
|
|
BLAKE2b-256 checksum How to use checksums |
fe387a2a8f933eb7ff24f4466793149edf5fb37ad0957d1de336ca414d696217
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Release files / oarepo_oidc_einfra-8.0.1-py3-none-any.whl
| Download URL | oarepo_oidc_einfra-8.0.1-py3-none-any.whl |
|---|---|
| Size | 34.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8d8cafd0c1c52ef6098fac06408616127a54febbe35c246ffd2e28eb37f3f493
|
|
BLAKE2b-256 checksum How to use checksums |
3505c0577ddeb17f8e9c088c5b74de2d8ef796cd56e9b829bceae81f9de23141
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|