Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Announcements
  3. OAuth support

OAuth support

Scheduled Pinned Locked Moved Announcements
35 Posts 14 Posters 5.1k Views 15 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • iamthefijI Offline
    iamthefijI Offline
    iamthefij
    App Dev
    wrote on last edited by
    #7

    It would seem that supporting Keycloak would be a great way to still only really have to maintain LDAP on the Cloudron side and then add support for OpenID Connect, OAuth 2.0
    and SAML 2.0.

    I've never set up Keycloak though, so I can't speak to it's ease of use or maintaining, but it is often recommended when people talk about FOSS Identity and Access Management tools.

    1 Reply Last reply
    3
    • girishG Offline
      girishG Offline
      girish
      Staff
      wrote on last edited by girish
      #8

      keycloak is a really good idea, didn't think about that. By which, i mean if we could have apps that provide additional saml/oidc support to cloudron, that is definitely way better than us re-inventing all this. Some of the universities Cloudron is deployed in uses Shibboleth which I am told support LDAP and OAuth2

      1 Reply Last reply
      4
      • J Offline
        J Offline
        jk
        wrote on last edited by
        #9

        I've wished for OAuth support for quite a few times already to support SSO to non-Cloudron apps. So in that case, Cloudron would serve as the identity provider for a third-party app. Kind of like Login with Cloudron.

        That would require that one can register third party apps with their client id, client secret and callback URL though.

        I have a little bit of experience with Keycloak. I know that U=using Keycloak would (also) support this use case, provided a Cloudron user has access to the Keycload administration interface.

        iamthefijI 1 Reply Last reply
        2
        • J jk

          I've wished for OAuth support for quite a few times already to support SSO to non-Cloudron apps. So in that case, Cloudron would serve as the identity provider for a third-party app. Kind of like Login with Cloudron.

          That would require that one can register third party apps with their client id, client secret and callback URL though.

          I have a little bit of experience with Keycloak. I know that U=using Keycloak would (also) support this use case, provided a Cloudron user has access to the Keycload administration interface.

          iamthefijI Offline
          iamthefijI Offline
          iamthefij
          App Dev
          wrote on last edited by
          #10

          @jk That actually used to be possible, but the OAuth provider is now gone.

          Adding something like Keycloak or even Shibboleth would add back an OAuth provider.

          1 Reply Last reply
          2
          • LonkleL Offline
            LonkleL Offline
            Lonkle
            wrote on last edited by
            #11

            I know it's gonna be a long time away from adding a replacement to OAuth, but are there any alternatives that stand out now more than they did before. Or are we still looking for a solution that doesn't require upstream changes?

            imc67I 1 Reply Last reply
            0
            • LonkleL Lonkle

              I know it's gonna be a long time away from adding a replacement to OAuth, but are there any alternatives that stand out now more than they did before. Or are we still looking for a solution that doesn't require upstream changes?

              imc67I Offline
              imc67I Offline
              imc67
              translator
              wrote on last edited by
              #12

              @Lonk @nebulon @girish indeed I’m also very curious for this, I think it would make Cloudron even more unique if you could click an app in your Dashboard and you’re “Cloudron-magically” logged in!

              1 Reply Last reply
              2
              • girishG Offline
                girishG Offline
                girish
                Staff
                wrote on last edited by
                #13

                @imc67 @Lonk Nothing has changed and I don't expect it to either. Without upstream changes to apps, this is not possible. As far as I have noticed, most apps are not adding support for OAuth.

                1 Reply Last reply
                1
                • jdaviescoatesJ Offline
                  jdaviescoatesJ Offline
                  jdaviescoates
                  wrote on last edited by jdaviescoates
                  #14

                  I note that the lovely people at Indiehosters (all in French) have launched a new service called Liiibre which by default is a nicely integrated Nextcloud, OnlyOffice, Rocket.Chat, and Jitsi Meet.

                  And I read over on the Meet.coop forum that they are using Keycloak to power their SSO stuff, so that might be worth exploring.

                  Here is the relevant thread for info:
                  https://forum.meet.coop/t/hi-from-indiehosters-onboarding-process/343?u=jdaviescoates

                  But see especially this post:
                  https://forum.meet.coop/t/hi-from-indiehosters-onboarding-process/343/8?u=jdaviescoates

                  Edit: and looking back up the thread I see Keycloak has already been proposed/ discussed above too.

                  I use Cloudron with Gandi & Hetzner

                  1 Reply Last reply
                  1
                  • LonkleL Offline
                    LonkleL Offline
                    Lonkle
                    wrote on last edited by
                    #15

                    In summary, I am going to list all alternatives to OAuth that have been listed in this thread:

                    • OpenID Connect
                    • SAML
                    • OAuth2 (a Sign in with Cloudron feature of some kind I think)
                    • Liiibre
                    • Keycloak

                    Did I miss any of them?

                    marcusquinnM jdaviescoatesJ 2 Replies Last reply
                    0
                    • LonkleL Lonkle

                      In summary, I am going to list all alternatives to OAuth that have been listed in this thread:

                      • OpenID Connect
                      • SAML
                      • OAuth2 (a Sign in with Cloudron feature of some kind I think)
                      • Liiibre
                      • Keycloak

                      Did I miss any of them?

                      marcusquinnM Offline
                      marcusquinnM Offline
                      marcusquinn
                      wrote on last edited by
                      #16

                      @Lonk Gluu perhaps?

                      Web Design https://www.evergreen.je
                      Development https://brandlight.org
                      Life https://marcusquinn.com

                      1 Reply Last reply
                      0
                      • LonkleL Lonkle

                        In summary, I am going to list all alternatives to OAuth that have been listed in this thread:

                        • OpenID Connect
                        • SAML
                        • OAuth2 (a Sign in with Cloudron feature of some kind I think)
                        • Liiibre
                        • Keycloak

                        Did I miss any of them?

                        jdaviescoatesJ Offline
                        jdaviescoatesJ Offline
                        jdaviescoates
                        wrote on last edited by
                        #17

                        @Lonk said in OAuth support:

                        • Liiibre
                        • Keycloak

                        Liiibre is not an alternative to OAuth, it's the name of a service provided by Indiehosters, which uses Keycloak for SSO.

                        I use Cloudron with Gandi & Hetzner

                        1 Reply Last reply
                        1
                        • LonkleL Offline
                          LonkleL Offline
                          Lonkle
                          wrote on last edited by
                          #18

                          Redoing the list. Thank you guys for your feedback:

                          • OpenID Connect
                          • SAML
                          • OAuth2 (a Sign in with Cloudron feature of some kind I think)
                          • Keycloak
                          • Gluu

                          Did I miss any others anyone can think of? Not thinking of trying to integrate this anytime soon, just want to talk about what's the future to be prepared for it.

                          jdaviescoatesJ 1 Reply Last reply
                          0
                          • LonkleL Lonkle

                            Redoing the list. Thank you guys for your feedback:

                            • OpenID Connect
                            • SAML
                            • OAuth2 (a Sign in with Cloudron feature of some kind I think)
                            • Keycloak
                            • Gluu

                            Did I miss any others anyone can think of? Not thinking of trying to integrate this anytime soon, just want to talk about what's the future to be prepared for it.

                            jdaviescoatesJ Offline
                            jdaviescoatesJ Offline
                            jdaviescoates
                            wrote on last edited by
                            #19

                            @Lonk said in OAuth support:

                            • OAuth2 (a Sign in with Cloudron feature of some kind I think)

                            I'm pretty sure OAuth2 is just version two of OAuth aka OAuth 2.0

                            https://oauth.net/2/

                            I use Cloudron with Gandi & Hetzner

                            LonkleL 1 Reply Last reply
                            0
                            • jdaviescoatesJ jdaviescoates

                              @Lonk said in OAuth support:

                              • OAuth2 (a Sign in with Cloudron feature of some kind I think)

                              I'm pretty sure OAuth2 is just version two of OAuth aka OAuth 2.0

                              https://oauth.net/2/

                              LonkleL Offline
                              LonkleL Offline
                              Lonkle
                              wrote on last edited by Lonkle
                              #20

                              @jdaviescoates said in OAuth support:

                              @Lonk said in OAuth support:

                              • OAuth2 (a Sign in with Cloudron feature of some kind I think)

                              I'm pretty sure OAuth2 is just version two of OAuth aka OAuth 2.0

                              https://oauth.net/2/

                              It'd added because it's one of the alternative solutions suggested in the comments, the "Sign in with Cloudron" suggestion would most likely be based on it and I was listing protocols. I can't remember who suggested it and I'm not voting for it but I thought it deserved to be included with the list the community came up with. What do you think? 🤔

                              1 Reply Last reply
                              0
                              • mehdiM Offline
                                mehdiM Offline
                                mehdi
                                App Dev
                                wrote on last edited by mehdi
                                #21

                                Guys, this discussion is moot.

                                The devs have already said that support for SSO is not happening in Cloudron until way more apps support it upstream, and it does not look like it's headed that way on the apps side.

                                Like they said, Cloudron used to support SSO with OAuth2, but almost no app used it, so they removed it. They're not gonna implement other SSO protocols in cloudron when app support is also just as bad.

                                LonkleL ruihildtR 2 Replies Last reply
                                1
                                • mehdiM mehdi

                                  Guys, this discussion is moot.

                                  The devs have already said that support for SSO is not happening in Cloudron until way more apps support it upstream, and it does not look like it's headed that way on the apps side.

                                  Like they said, Cloudron used to support SSO with OAuth2, but almost no app used it, so they removed it. They're not gonna implement other SSO protocols in cloudron when app support is also just as bad.

                                  LonkleL Offline
                                  LonkleL Offline
                                  Lonkle
                                  wrote on last edited by Lonkle
                                  #22

                                  @mehdi Well, that’s why I kept this conversation going. To see if it was pointless. I know that anything would need widespread app support upstream adoption and I was curious which ones winning the race, if anyone knew. Maybe none of them are.

                                  1 Reply Last reply
                                  0
                                  • nebulonN Offline
                                    nebulonN Offline
                                    nebulon
                                    Staff
                                    wrote on last edited by
                                    #23

                                    Btw OAuth3 is around the corner and as far as I understood it wont help much in the mess OAuth generally has caused.

                                    All OAuth versions are structurally not well suited for a use-case like Cloudron. The issue is, that they have a central auth authority in mind (google, facebook, ...) where on Cloudron each Cloudron is its own authority, which leads to even more issues within app support. So this is one reason which led us to simply not pursuing this further.

                                    To give more insight into our decision: LDAP won thus far. It has drawbacks (lack of 2fa and real SSO) but generally works well also with the applications UI flows and is by far the most supported and standardized one.

                                    LonkleL 1 Reply Last reply
                                    1
                                    • mehdiM mehdi

                                      Guys, this discussion is moot.

                                      The devs have already said that support for SSO is not happening in Cloudron until way more apps support it upstream, and it does not look like it's headed that way on the apps side.

                                      Like they said, Cloudron used to support SSO with OAuth2, but almost no app used it, so they removed it. They're not gonna implement other SSO protocols in cloudron when app support is also just as bad.

                                      ruihildtR Offline
                                      ruihildtR Offline
                                      ruihildt
                                      wrote on last edited by ruihildt
                                      #24

                                      @mehdi Doesn't software like Gluu and Keycloak abstract different auth methods (LDAP, oauth, saml,...) under a single system to provide SSO?

                                      I was looking at Gluu, and under the hood it is a LDAP implementation, so I could imagine it could replace or interface with the current system. (I haven't looked into Keycloak but I guess it's a similar concept?)

                                      So SSO/2FA with only oauth on cloudron is dead but maybe Keycloak or Gluu is still something worth to be looked at?

                                      1 Reply Last reply
                                      1
                                      • nebulonN nebulon

                                        Btw OAuth3 is around the corner and as far as I understood it wont help much in the mess OAuth generally has caused.

                                        All OAuth versions are structurally not well suited for a use-case like Cloudron. The issue is, that they have a central auth authority in mind (google, facebook, ...) where on Cloudron each Cloudron is its own authority, which leads to even more issues within app support. So this is one reason which led us to simply not pursuing this further.

                                        To give more insight into our decision: LDAP won thus far. It has drawbacks (lack of 2fa and real SSO) but generally works well also with the applications UI flows and is by far the most supported and standardized one.

                                        LonkleL Offline
                                        LonkleL Offline
                                        Lonkle
                                        wrote on last edited by
                                        #25

                                        @nebulon said in OAuth support:

                                        . It has drawbacks (lack of 2fa and real SSO)
                                        Thank you for explaining to me the decision behind the decision and I def agree with it.

                                        Ya know, is the LDAP protocol still being updated? Maybe it'll get 2FA. And as for "real SSO" - I'd kind of say it's real enough. Or when you say real, you mean, once you login to Cloudron, if it was "real SSO" - you could click on a supported app and already be logged in? That...sounds technically feasible, but I'm just curious if that's what you meant by "real" (instead of just re-using the same credentials).

                                        mehdiM iamthefijI 2 Replies Last reply
                                        0
                                        • LonkleL Lonkle

                                          @nebulon said in OAuth support:

                                          . It has drawbacks (lack of 2fa and real SSO)
                                          Thank you for explaining to me the decision behind the decision and I def agree with it.

                                          Ya know, is the LDAP protocol still being updated? Maybe it'll get 2FA. And as for "real SSO" - I'd kind of say it's real enough. Or when you say real, you mean, once you login to Cloudron, if it was "real SSO" - you could click on a supported app and already be logged in? That...sounds technically feasible, but I'm just curious if that's what you meant by "real" (instead of just re-using the same credentials).

                                          mehdiM Offline
                                          mehdiM Offline
                                          mehdi
                                          App Dev
                                          wrote on last edited by
                                          #26

                                          @Lonk Yeah, that's it.

                                          1 Reply Last reply
                                          1
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Don't have an account? Register

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • Bookmarks
                                          • Search