Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Auth for epicsweb.jlab.org should use Keycloak #23

Open
slominskir opened this issue Apr 12, 2023 · 1 comment
Open

Auth for epicsweb.jlab.org should use Keycloak #23

slominskir opened this issue Apr 12, 2023 · 1 comment

Comments

@slominskir
Copy link
Member

slominskir commented Apr 12, 2023

This applies to all apps on epicsweb, but creating issue in wave just to put issue somewhere.

Ideally the httpd forms and sessions modules are abandoned in favor of Keycloak auth at ace.jlab.org/auth

Switch httpd mod_auth_forms to mod_auth_oidc and connect to Keycloak notes:

@slominskir
Copy link
Member Author

Note: It's also worth considering if instead of mod_auth_openidc we allow Tomcat (or otherwise app code) to handle OIDC. This is what we do on ace.jlab.org with Wildfly. App specific requires a good adapter/library though, which can be tricky to sort through:

See:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant