Uploaded image for project: 'Single Sign On'
  1. Single Sign On
  2. MGNLSSO-84

Ability to use default Magnolia login as well as SSO login

XMLWordPrintable

    • Yes
    • Yes
    • AdminX 37, AdminX 47

      Goal & problem statement

      Plenty of customers report a problem that once they enable the SSO module on their Magnolia installations, they cannot login to their instance if the IdP provider used by SSO becomes temporarily unavailable. All users get completely locked out of the instance, so if there's an urgent need to access the AdminCentral for whatever reason, this is not possible until the IdP is available again.

      Let's solve this problem.

      Original request from luke.trueman:

      Customers want to have a backup way to get access into the instance with jcr auth, they don't want to rely 100% on external identity provider. They also want to use SSO but not every user is in their SSO, e.g. an SEO agency may need access etc so having the Magnolia users available would be beneficial.

      I know we offer a workaround using a mock docker server/node server, but this doesn't always cover the use case. 

      Potential approach

      lfischer suggests to solve this using multiple login handlers, which allow to use custom IdP provider AND local users at the same time, where local users are configured on the Magnolia instance and serve as a backup login possibility for situations when the IdP used for SSO is not available. 

      He already prepared a repo containing support for multiple login handlers: https://git.magnolia-cms.com/users/lfischer/repos/magnolia-sso-extended/browse 

      Documentation: https://git.magnolia-cms.com/users/lfischer/repos/magnolia-sso-extended/browse/_extended_docs 

      The suggested approach would be to enable support of multiple login handlers (i.e. a custom IdP AND local users) if the customer decides to enable this for emergency situations. This feature could be made part of the core MGNLSSO module.

      Discovery

      We can follow the approach above to enable the default login and SSO login at the same time for SSO v2. In addition, we can introduce a configurable way to enable or disable the default login. 

      For SSO v3, it might need to verify with the SaaS, but the same approach still can be applied.

      UPDATE 23.11.2022: Additional idea by lfischer on how to solve this is available in the sso-extended docs: https://git.magnolia-cms.com/users/lfischer/repos/magnolia-sso-extended/browse/_extended_docs

        Acceptance criteria

              nguyen.phung Nguyen Phung Chi
              luke.trueman Luke Trueman
              Hong Li
              AdminX
              Votes:
              11 Vote for this issue
              Watchers:
              16 Start watching this issue

                Created:
                Updated:
                Resolved:
                Work Started:

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - Not Specified
                  Not Specified
                  Logged:
                  Time Spent - 0.5d
                  0.5d