Skip to main content

E-infra authentication and authorization module for InvenioRDM

This remote backend adds support for Czech e-infra AAI solution - login.e-infra.cz allowing all members of czech academic community can use their home institution credentials to log in.

Installation

Add the module to your repository's pyproject.toml:

dependencies = [
    "oarepo-oidc-einfra>=4.0.0",
    # ...
]

Configuration

  1. Register a new application with e-infra OIDC Provider at https://spadmin.e-infra.cz/. When registering the application ensure that the Redirect URI points to https://<my_invenio_site>:5000/oauth/authorized/e-infra/

General parameters

OIDC parameters

In OIDC parameters, you need to set at least the following scopes:

  • openid
  • profile
  • email
  • eduperson_entitlement
  • isCesnetEligibleLastSeen
  • organization

Perun-specific parameters

  1. Grab the Client ID and Client Secret after registering the application and add them to your ENVIRONMENT variables:
INVENIO_EINFRA_CONSUMER_KEY=*Client ID*
INVENIO_EINFRA_CONSUMER_SECRET=*Client Secret*
  1. Add the remote application to the site's invenio.cfg:
from oarepo_oidc_einfra import EINFRA_LOGIN_APP

OAUTHCLIENT_REMOTE_APPS = {"e-infra": EINFRA_LOGIN_APP}
  1. Add the e-infra public key to your invenio.cfg or environment variables:
EINFRA_RSA_KEY = b"-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAmho5h/lz6USUUazQaVT3\nPHloIk/Ljs2vZl/RAaitkXDx6aqpl1kGpS44eYJOaer4oWc6/QNaMtynvlSlnkuW\nrG765adNKT9sgAWSrPb81xkojsQabrSNv4nIOWUQi0Tjh0WxXQmbV+bMxkVaElhd\nHNFzUfHv+XqI8Hkc82mIGtyeMQn+VAuZbYkVXnjyCwwa9RmPOSH+O4N4epDXKk1V\nK9dUxf/rEYbjMNZGDva30do0mrBkU8W3O1mDVJSSgHn4ejKdGNYMm0JKPAgCWyPW\nJDoL092ctPCFlUMBBZ/OP3omvgnw0GaWZXxqSqaSvxFJkqCHqLMwpxmWTTAgEvAb\nnwIDAQAB\n-----END PUBLIC KEY-----\n"
  1. Add the VO, communities group, api url and others to your invenio.cfg or environment variables:
EINFRA_SERVICE_USERNAME = "username"
"""Username of the service in the E-INFRA Perun."""

EINFRA_SERVICE_PASSWORD = "password"
"""Password of the service in the E-INFRA Perun."""

EINFRA_SERVICE_ID = 0
"""Internal ID of the service (whose username and password are above) in the E-INFRA Perun."""

EINFRA_REPOSITORY_VO_ID = 0
"""Internal ID of the VO in the E-INFRA Perun that represents the repository."""

EINFRA_COMMUNITIES_GROUP_ID = 0
"""Internal ID of the group in the E-INFRA Perun that represents the communities."""

EINFRA_REPOSITORY_FACILITY_ID = 0
"""Internal ID of the facility in the E-INFRA Perun that represents the repository."""

EINFRA_CAPABILITIES_ATTRIBUTE_ID = 0
"""Internal ID of the attribute in the E-INFRA Perun that represents the capabilities."""

EINFRA_SYNC_SERVICE_ID = 0
"""Internal ID of the service in the E-INFRA Perun that is responsible for synchronization
(creating and pushing dumps with resources and users)."""
  1. Start the server and go to the login page https://127.0.0.1:5000/login/

Mapping global invenio roles

To map perun group to a global invenio role:

  1. Assign the facility to the group via a resource
  2. On resource, add the following capability: res:roles:<role_name>

Users that will be members of the group will be automatically given the role (and if they are removed from the group the role will be removed).

Metadata

Release files for oarepo-oidc-einfra 8.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for oarepo-oidc-einfra 8.0.0
File Size Uploaded
oarepo_oidc_einfra-8.0.0.tar.gz 25.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for oarepo-oidc-einfra 8.0.0
File Interpreter ABI Platform
oarepo_oidc_einfra-8.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 58.7 kB

Release files / oarepo_oidc_einfra-8.0.0.tar.gz

Download URL oarepo_oidc_einfra-8.0.0.tar.gz
Size 25.0 kB
Tags Source
SHA-256 checksum
How to use checksums
a86ecd64abc1f2c033ff66e03a8bf3747a82151115afdcdad721a183e3cbed75
BLAKE2b-256 checksum
How to use checksums
1774004af61b6ec76b5b3061e5642837bbd7b24140bb244bb570f4763485a288
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release files / oarepo_oidc_einfra-8.0.0-py3-none-any.whl

Download URL oarepo_oidc_einfra-8.0.0-py3-none-any.whl
Size 33.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8ce2caca89762e2ff974b222bb2bf3cad65fb4d9fbbec73e529f5c8fb80b36e4
BLAKE2b-256 checksum
How to use checksums
7d3399b08d1de0878d54c8bfeb6696aaef5fa4954fc4d00a9d4b06e18473c0a6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.14

Release history Release notifications | RSS feed

8.0.1

2 release files

This release

8.0.0 This release

2 release files

7.2.1

2 release files

7.2.0

2 release files

7.1.1

2 release files

7.1.0

2 release files

7.0.3

2 release files

7.0.2

2 release files

7.0.1

2 release files

7.0.0

2 release files

6.0.0

2 release files

5.0.0

2 release files

4.2.0

2 release files

4.1.0

2 release files

4.0.0

2 release files

3.0.1

2 release files

3.0.0

2 release files

1.3.6

2 release files

1.3.4

2 release files

1.3.3

2 release files

1.3.2

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.9

2 release files

1.1.8

2 release files

1.1.7

2 release files

1.1.6

2 release files

1.1.5

2 release files

1.1.4

2 release files

1.1.2

2 release files

1.1.1

2 release files

1.1.0

2 release files

1.0.9

2 release files

1.0.8

2 release files

1.0.7

2 release files

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page