Extension:OAuth/id
Status keluaran: stabil |
|
|---|---|
| Penerapan | Identitas pengguna, Hak pengguna, API |
| Deskripsi | Allow users to safely authorize another application ("consumer") to use the MediaWiki API on their behalf. |
| Perancang | Aaron Schulz, Chris Steipp, Brad Jorsch, Robert Vogel, Dejan Savuljesku |
| Versi terbaru | 1.1.0 (continuous updates) |
| Kebijakan kompatibilitas | Cuplikan dikeluarkan bersamaan dengan MediaWiki. Induk tidak kompatibel dengan versi sebelumnya. |
| Perubahan pangkalan data | Ya |
| Domain maya | virtual-oauth |
|
|
|
|
|
|
|
| Licence | Lisensi Publik Umum GNU 2.0 atau lebih baru |
| Unduh | |
| Bantuan | Bantuan:OAuth |
| Terjemahkan pengaya OAuth jika tersedia di translatewiki.net | |
| Peran vagrant | oauth |
| Masalah | Tugas terbuka · Laporkan kekutu |
The OAuth extension implements an OAuth server in MediaWiki that supports both the OAuth 1.0a and OAuth 2.0 protocol versions. It allows third party developers to securely develop applications ("consumers"), to which users can give a limited set of permissions ("grants"), so that the application can use the MediaWiki API on the user's behalf.
| Area | RFC |
|---|---|
| OAuth 1.0a | RFC 5849 |
| OAuth 2.0 framework | RFC 6749 |
| OAuth 2.0 Authorization Code grant | RFC 6749 section 4.1 |
| OAuth 2.0 Refresh Token grant | RFC 6749 section 6 |
| OAuth 2.0 Client Credentials grant | RFC 6749 section 4.4 |
| PKCE for auth-code flow | RFC 7636 |
Keperluan
- OAuth relies on the object cache for temporary tokens and sessions. This should work as long as cache configuration settings are sane. (Older versions required Memcached explicitly.)
- Currently, only MySQL and SQLite database backends are supported
- If the MediaWiki installation is private (i.e. users need to log in to have read access), Special:OAuth will need to be added to the white list.
Pemasangan
- Unduh dan pindahkan folder
OAuthyang diekstrak ke direktoriextensions/Anda.
Pengembang dan penyumbangsih kode sebaiknya memasang pengaya dari Git sebagai gantinya, menggunakan:cd extensions/ git clone https://gerrit.wikimedia.org/r/mediawiki/extensions/OAuth
- Hanya ketika memasang dari Git, jalankan Composer untuk memasang ketergantungan PHP, dengan mengeluarkan perintah
composer install --no-devdi direktori pengaya. (Lihat T173141 untuk komplikasi yang mungkin terjadi.) - Tambahkan kode berikut di bawah berkas LocalSettings.php Anda:
wfLoadExtension( 'OAuth' );
- Jalankan skrip pembaruan yang akan membuat tabel pangkalan data yang diperlukan pengaya ini secara otomatis.
- Configure the general parameters as required.
- OAuth2 will not be enabled if you leave all settings at their defaults.
- Configure the user rights by putting them into the relevant groups in
$wgGroupPermissions.
Selesai – Telusuri ke Special:Versiondi wiki Anda untuk memastikan pengayanya berhasil dipasang.
Pemasangan Vagrant:
- Jika menggunakan Vagrant, pasanglah dengan
vagrant roles enable oauth --provision
To assign a permission to some group, for example to sysops, you add following line to LocalSettings.php:
$wgGroupPermissions['sysop']['mwoauthproposeconsumer'] = true;
Database virtual domains mapping
Since MediaWiki 1.45, it's recommended to configure database virtual domains mapping for OAuth, see this patch.
$wgMWOAuthCentralWiki and virtual domains are separate settings.
To set up virtual domains mapping with OAuth, use:
$wgMWOAuthCentralWiki = '<central-wiki>';
$wgVirtualDomainsMapping['virtual-oauth'] = [ 'db' => '<oauth-db>' ];
Konfigurasi
Parameters
| Variable name | Default value | Deskripsi |
|---|---|---|
$wgMWOAuthCentralWiki
|
false
|
Wiki ID of OAuth management wiki. On wiki farms, it makes sense to set this to a wiki that acts as a portal site, is dedicated to management, or just handles login/authentication. It can, however, be set to any wiki in the farm. For single-wiki sites or farms where each wiki manages consumers separately, it should be left as false.
|
$wgMWOAuthSharedUserIDs
|
false
|
(deprecated) Use $wgMWOAuthSharedUserSource instead
Whether shared global user IDs are stored in the oauth tables.
On wiki farms with a central authentication system (with integer user IDs) that share a single OAuth management wiki, this must be set to |
$wgMWOAuthSharedUserSource
|
null
|
Central ID provider when sharing OAuth credentials over a wiki farm
Source of shared user IDs, if enabled.
If CentralIdLookup is available, this is the |
$wgMWOAuthRequestExpirationAge
|
2.592.000 (30 days)
|
Seconds after which an idle request for a new Consumer is marked as "expired" |
$wgMWOAuthSecureTokenTransfer
|
true
|
Require SSL/TLS for returning Consumer and user secrets. This is required by RFC 5849, however if a wiki wants to use OAuth, but doesn't support SSL, this option makes this configuration possible. This should be set to true for most production settings.
|
$wgOAuthSecretKey
|
$wgSecretKey
|
A secret configuration string (random 32-bit string generated using base64_encode(random_bytes(32))) used to hmac the database-stored secret to produce the shared secrets for Consumers. This provides some protection against an attacker reading the values out of the consumer table (the attacker would also need $wgOAuthSecretKey to generate valid secrets), and some protection against potential weaknesses in the secret generation. If this string is compromised, the site should generate a new $wgOAuthSecretKey, which will invalidate Consumer authorizations that use HMAC/shared secret signatures instead of public/private keys. Consumers can regenerate their new shared secret by using the "Reset the secret key to a new value" option under Special:MWOAuthConsumerRegistration/update. If null, the value is set to $wgSecretKey.
|
$wgOAuthGroupsToNotify
|
[]
|
The list of user groups which should be notified about new consumer proposals. Setting this will only have an effect when Echo is installed. |
$wgMWOauthDisabledApiModules
|
[]
|
List of API module classes to disable when OAuth is used for the request |
$wgMWOAuthReadOnly
|
false
|
Prevent write activity to the database. When this is set, consumers cannot be added or updated, and new authorizations are prohibited. Authorization headers for existing authorizations will continue to work. Useful for migrating database tables |
$wgMWOAuthSessionCacheType
|
$wgSessionCacheType
|
The storage mechanism for various temporary data (although not actual session data). One of the cache types defined via $wgObjectCaches. If null, it defaults to $wgSessionCacheType.
|
$wgMWOAuthNonceCacheType
|
$wgMWOAuthSessionCacheType
|
The storage mechanism for OAuth 1.0 nonces. |
$wgOAuthAutoApprove
|
[]
|
Allows automatic immediate approval of low-risk apps. In the form of [ 'grants' => [ 'grant1', 'grant2', ... ] ]
|
$wgOAuth2EnabledGrantTypes
|
[
"authorization_code",
"refresh_token",
"client_credentials"
]
|
List of OAuth2 grants that client applications can be allowed to use. Actual grants client application will be allowed to use can be any subset of grants listed here. Grants, other than the ones listed here, are considered legacy grants, and are not supported by this extension |
$wgOAuth2PrivateKey
|
""
|
Private key or a path to the private key used to sign OAuth2 JWT being transmitted. See the OAuth 2.0 Server documentation for how to generate the keys. |
$wgOAuth2PublicKey
|
""
|
Public key or a path to the public key used to verify OAuth2 resource requests. |
$wgOAuth2Passphrase
|
""
|
Passphrase to use, when the private key is encrypted. |
$wgOAuth2RequireCodeChallengeForPublicClients
|
true
|
Controls whether clients are required to send code challenges with OAuth2 requests. This only applies to non-confidential clients. |
$wgOAuth2GrantExpirationInterval
|
"PT1H" (1 hour)
|
Controls validity period for access tokens (stored in the cache configured in $wgMWOAuthSessionCacheType). Does not apply to owner-only clients, whose access tokens are always non-expiring. Accepts ISO 8601 durations or can be set to infinity or false for non-expiring tokens.
|
$wgOAuth2RefreshTokenTTL
|
"P1M" (1 month)
|
Controls validity period for refresh tokens (stored in the cache configured in $wgMWOAuthSessionCacheType). Accepts ISO 8601 durations or can be set to infinity or false for non-expiring tokens.
|
User rights
| Right | Deskripsi |
|---|---|
mwoauthproposeconsumer |
Propose new OAuth consumers |
mwoauthupdateownconsumer |
Update OAuth consumers you control |
mwoauthmanageconsumer |
Manage OAuth consumers |
mwoauthsuppress |
Suppress OAuth consumers |
mwoauthviewsuppressed |
View suppressed OAuth consumers |
mwoauthviewprivate |
View private OAuth data |
mwoauthmanagemygrants |
Manage OAuth grants |
Endpoints
The following REST endpoints are provided for OAuth 2.0 interaction
Get authorization code
Used for retrieving authorization code when using authorization_code grant.
- Path
- /oauth2/authorize
- Allowed method
- GET
- Allowed parameters
Name Required? Description response_type Ya client_id Ya redirect_uri Tidak if present, must match the URI that was set when client was registered exactly scope Tidak state Tidak code_challenge Tidak required if $wgOAuth2RequireCodeChallengeForPublicClientsistruecode_challenge_method Tidak required if $wgOAuth2RequireCodeChallengeForPublicClientsistrue
Get access token
Used for requesting access tokens
- Path
- /oauth2/access_token
- Allowed method
- POST
- Allowed parameters
Name Required? Description grant_type Ya type of grant used client_id Tidak client_secret Tidak required if client is confidentialredirect_uri Tidak if present, must match the URI that was set when client was registered exactly scope Tidak code Tidak required if authorization_codegrant is usedrefresh_token Tidak required if refresh_tokengrant is usedcode_verifier Tidak
Get user or client information
Used for retrieving protected resources using the access token issued previously.
Currently, two resource types can be retrieved using this endpoint, by replacing {{type}} placeholder with the type key:
profile- retrieve the user profile of the user that is represented by the access token used to make the request - usually used for logging users in on 3rd party websites using MediaWikiscopes- retrieve all scopes client (application) is allowed to use with the current access token
- Path
- /oauth2/resource/{{type}}
- Allowed method
- GET
- POST
- Allowed parameters
- No parameters are allowed, apart from the
{{type}}parameter that is included in the path
List clients
Lists OAuth 1.0a or 2.0 clients for the logged-in user. Authentication can be achieved over CentralAuth or by including an access token in the authorization header.
- Path
- /oauth2/client
- Allowed method
- GET
- Allowed parameters
Name Required? Description Default oauth_versionOpsional either 1 (to return only OAuth 1.0a clients) or 2 (to return only OAuth 2.0 clients). 2
- Pagination parameters
Name Required? Description Default limitOpsional maximum number of clients to return. 25 offsetOpsional number of clients to skip before returning the first result. 0
| Response example |
|---|
{
"clients": [
{
"client_key": "xxxxxxxxxxxxxx",
"name": "TestFromCurl1807",
"version": "2.0",
"email": "admin@example.com",
"callback_url": "http://example.com",
"scopes": [
"authonly"
],
"registration": "20200818230806",
"stage": 0,
"oauth_version": 2,
"description": "foo",
"allowed_grants": [
"authorization_code"
],
"registration_formatted": "23:08, 18 August 2020"
}
],
"total": 1
}
|
Reset client secret
Resets a client secret. For owner-only clients, this endpoint also resets the access token.
- Path
- /oauth2/client/{client_key}/reset_secret
- Allowed method
- POST
- Allowed parameters
Name Required? Description Default client_keyDiperlukan client identifier reasonOpsional string containing the reason for resetting the secret. ''
| Response example |
|---|
{
"name": "Example",
"client_key": "xxxxxxxxxx",
"secret": "xxxxxxxxxx",
"access_token": "xxxxxxxxxx"
}
|
Create OAuth 2.0 client
Creates an OAuth 2.0 client.
- Path
- /oauth2/client
- Allowed method
- POST
- Allowed parameters
Name Required? Description Default nameDiperlukan client name descriptionDiperlukan client description emailDiperlukan contact email is_confidentialDiperlukan set to trueif the client is confidential; set tofalsefor public clients like mobile and desktop appsgrant_typesDiperlukan OAuth 2.0 grant types used by the client, one or more of the following: authorization_code,refresh_token,client_credentialsscopesDiperlukan OAuth 2.0 scopes, either mwoauth-authonly,mwoauth-authonlyprivateor the set of applicable grantsversionOpsional client version. 1.0 wikiOpsional applicable project. * for all wikis owner_only? set to truefor a client used only by the creating usercallback_urlOpsional Return URL for authorizing users. ''callback_is_prefixOpsional set to trueto allow the client to specify a callback in requests and use the callback URL as a required prefix.false
| Response example |
|---|
{
"name": "Example",
"client_key": "xxxxxxxxxx",
"secret": "xxxxxxxxxx",
"access_token": "xxxxxxxxxx"
}
|
Lihat pula
- Extension:OATHAuth – A similarly named extension which implements a second authentication factor using OATH-based one-time passwords.
- Extension:WSOAuth – A MediaWiki extension that lets your wiki delegate authentication to any OAuth provider using PluggableAuth, including a wiki that is running Extension:OAuth.
- oauthclient-php – A client library for OAuth consumers.
| Pengaya ini sedang digunakan di salah satu atau lebih proyek Wikimedia. Ini kemungkinan berarti pengaya ini stabil dan bekerja cukup baik untuk digunakan oleh situs web berlalu lintas tinggi. Cari nama pengaya ini di berkas konfigurasi CommonSettings.php dan InitialiseSettings.php Wikimedia untuk melihat di mana ia dipasang. Daftar lengkap pengayakulit yang dipasang di suatu wiki bisa dilihat di halaman Special:Version wiki. |
| Pengaya ini disertakan di wiki farm/hos dan/atau paket berikut: |
- Stable extensions/id
- User identity extensions/id
- User rights extensions/id
- API extensions/id
- Extensions which add rights/id
- AbuseFilter-builder extensions/id
- AbuseFilter-computeVariable extensions/id
- AbuseFilter-generateUserVars extensions/id
- ApiRsdServiceApis extensions/id
- BeforeCreateEchoEvent extensions/id
- ChangeTagCanCreate extensions/id
- ChangeTagsListActive extensions/id
- GetPreferences extensions/id
- ListDefinedTags extensions/id
- LoadExtensionSchemaUpdates extensions/id
- LoginFormValidErrorMessages extensions/id
- MediaWikiServices extensions/id
- MergeAccountFromTo extensions/id
- MessagesPreLoad extensions/id
- SetupAfterCache extensions/id
- SpecialPageAfterExecute extensions/id
- SpecialPageBeforeFormDisplay extensions/id
- TestCanonicalRedirect extensions/id
- GPL licensed extensions/id
- Extensions in Wikimedia version control/id
- All extensions/id
- Extensions requiring Composer with git/id
- Extensions used on Wikimedia/id
- Extensions included in Canasta/id
- Extensions included in Miraheze/id
- Extensions included in ProWiki/id
- Extensions included in Telepedia/id
- Extensions included in Weird Gloop/id
- Extensions included in wiki.gg/id
