Skip to main content

E-infra authentication and authorization module for InvenioRDM

This remote backend adds support for Czech e-infra AAI solution - login.e-infra.cz allowing all members of czech academic community can use their home institution credentials to log in.

Installation

Add the module to your repository's pyproject.toml:

dependencies = [
    "oarepo-oidc-einfra>=4.0.0",
    # ...
]

Configuration

  1. Register a new application with e-infra OIDC Provider at https://spadmin.e-infra.cz/. When registering the application ensure that the Redirect URI points to https://<my_invenio_site>:5000/oauth/authorized/e-infra/

General parameters

OIDC parameters

In OIDC parameters, you need to set at least the following scopes:

  • openid
  • profile
  • email
  • eduperson_entitlement
  • isCesnetEligibleLastSeen
  • organization

Perun-specific parameters

  1. Grab the Client ID and Client Secret after registering the application and add them to your ENVIRONMENT variables:
INVENIO_EINFRA_CONSUMER_KEY=*Client ID*
INVENIO_EINFRA_CONSUMER_SECRET=*Client Secret*
  1. Add the remote application to the site's invenio.cfg:
from oarepo_oidc_einfra import EINFRA_LOGIN_APP

OAUTHCLIENT_REMOTE_APPS = {"e-infra": EINFRA_LOGIN_APP}
  1. Add the e-infra public key to your invenio.cfg or environment variables:
EINFRA_RSA_KEY = b"-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmho5h/lz6USUUazQaVT3\nPHloIk/Ljs2vZl/RAaitkXDx6aqpl1kGpS44eYJOaer4oWc6/QNaMtynvlSlnkuW\nrG765adNKT9sgAWSrPb81xkojsQabrSNv4nIOWUQi0Tjh0WxXQmbV+bMxkVaElhd\nHNFzUfHv+XqI8Hkc82mIGtyeMQn+VAuZbYkVXnjyCwwa9RmPOSH+O4N4epDXKk1V\nK9dUxf/rEYbjMNZGDva30do0mrBkU8W3O1mDVJSSgHn4ejKdGNYMm0JKPAgCWyPW\nJDoL092ctPCFlUMBBZ/OP3omvgnw0GaWZXxqSqaSvxFJkqCHqLMwpxmWTTAgEvAb\nnwIDAQAB\n-----END PUBLIC KEY-----\n"
  1. Add the VO, communities group, api url and others to your invenio.cfg or environment variables:
EINFRA_SERVICE_USERNAME = "username"
"""Username of the service in the E-INFRA Perun."""

EINFRA_SERVICE_PASSWORD = "password"
"""Password of the service in the E-INFRA Perun."""

EINFRA_SERVICE_ID = 0
"""Internal ID of the service (whose username and password are above) in the E-INFRA Perun."""

EINFRA_REPOSITORY_VO_ID = 0
"""Internal ID of the VO in the E-INFRA Perun that represents the repository."""

EINFRA_COMMUNITIES_GROUP_ID = 0
"""Internal ID of the group in the E-INFRA Perun that represents the communities."""

EINFRA_REPOSITORY_FACILITY_ID = 0
"""Internal ID of the facility in the E-INFRA Perun that represents the repository."""

EINFRA_CAPABILITIES_ATTRIBUTE_ID = 0
"""Internal ID of the attribute in the E-INFRA Perun that represents the capabilities."""

EINFRA_SYNC_SERVICE_ID = 0
"""Internal ID of the service in the E-INFRA Perun that is responsible for synchronization
(creating and pushing dumps with resources and users)."""
  1. Start the server and go to the login page https://127.0.0.1:5000/login/

Mapping global invenio roles

To map perun group to a global invenio role:

  1. Assign the facility to the group via a resource
  2. On resource, add the following capability: res:roles:<role_name>

Users that will be members of the group will be automatically given the role (and if they are removed from the group the role will be removed).

Metadata

Release files for oarepo-oidc-einfra 8.0.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for oarepo-oidc-einfra 8.0.1
File Size Uploaded
oarepo_oidc_einfra-8.0.1.tar.gz 25.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for oarepo-oidc-einfra 8.0.1
File Interpreter ABI Platform
oarepo_oidc_einfra-8.0.1-py3-none-any.whl Python 3 none any Details

Total release size: 60.6 kB

Release files / oarepo_oidc_einfra-8.0.1.tar.gz

Download URL oarepo_oidc_einfra-8.0.1.tar.gz
Size 25.7 kB
Tags Source
SHA-256 checksum
How to use checksums
1bd79fc6e9075be0bf32cf0aa30ec00ed471447e60a78f1ea21910a69bb3dbe7
BLAKE2b-256 checksum
How to use checksums
fe387a2a8f933eb7ff24f4466793149edf5fb37ad0957d1de336ca414d696217
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / oarepo_oidc_einfra-8.0.1-py3-none-any.whl

Download URL oarepo_oidc_einfra-8.0.1-py3-none-any.whl
Size 34.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8d8cafd0c1c52ef6098fac06408616127a54febbe35c246ffd2e28eb37f3f493
BLAKE2b-256 checksum
How to use checksums
3505c0577ddeb17f8e9c088c5b74de2d8ef796cd56e9b829bceae81f9de23141
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

This release

8.0.1 This release

2 release files

8.0.0

2 release files

7.2.1

2 release files

7.2.0

2 release files

7.1.1

2 release files

7.1.0

2 release files

7.0.3

2 release files

7.0.2

2 release files

7.0.1

2 release files

7.0.0

2 release files

6.0.0

2 release files

5.0.0

2 release files

4.2.0

2 release files

4.1.0

2 release files

4.0.0

2 release files

3.0.1

2 release files

3.0.0

2 release files

1.3.6

2 release files

1.3.4

2 release files

1.3.3

2 release files

1.3.2

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.9

2 release files

1.1.8

2 release files

1.1.7

2 release files

1.1.6

2 release files

1.1.5

2 release files

1.1.4

2 release files

1.1.2

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.9

2 release files

1.0.8

2 release files

1.0.7

2 release files

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page