Skip to content

feat: Amend OAUTH framework to support per-service scopes and tokens. - #164

Open
ralflang wants to merge 1 commit into
FRAMEWORK_6_0from
feat/oauth_service_tokens
Open

ralflang wants to merge 1 commit into
FRAMEWORK_6_0from
feat/oauth_service_tokens

Conversation

@ralflang

Copy link
Copy Markdown
Member

Related to #110
Related to horde/Core#234

Implement storage for per-service Oauth scopes and tokens.

@jcdelepine

The philosophy is like this:

Besides the already existing purpose "login", an OIDC provider may offer separate scopes to access services or resources, i.e. IMAP, SMTP, Caldav...

These purposes are centrally managed by an administrator along with the OIDC/OAuth setup.

I.e. the site administrator controls which OpenID providers/services can be used for "login with..." and also controls which email providers, addressbook providers etc this site's apps may access (provided the user has access)

Beyond the technical layer for OAuth, Horde doesn't care about each provider's scope names. We translate them to ServicePurposes fulfilled by ServiceAuthorizations. So each provider may have totally different scope names without affecting the applications.

Unfortunately neither with Microsoft nor Google the access to their OIDC backed APIs works out of the box. The site administrator needs to create IDs in Entra or Google Cloud Console for this integration to work. With your own Keycloak or other IdP this is not an issue but for smalltime users this might be a bummer.

Integration with IMP as a pilot will follow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant