Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. WordPress (Developer)
  3. Can no longer access most of my WordPress sites

Can no longer access most of my WordPress sites

Scheduled Pinned Locked Moved WordPress (Developer)
oidc
6 Posts 3 Posters 668 Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • jdaviescoatesJ Online
    jdaviescoatesJ Online
    jdaviescoates
    wrote on last edited by jdaviescoates
    #1

    None of them work with Cloudron SSO OIDC.

    I just get e.g.

    9fea821e-1861-49f2-bff3-6e4ac59ab1ce-image.png

    One of the older ones I can still access just using my username/ password, but I'm completely locked out of nearly all of them 😞

    I use Cloudron with Gandi & Hetzner

    1 Reply Last reply
    0
    • jdaviescoatesJ Online
      jdaviescoatesJ Online
      jdaviescoates
      wrote on last edited by
      #2

      I tried renaming either or both of these but it didn't help 😞

      image.png

      I use Cloudron with Gandi & Hetzner

      1 Reply Last reply
      0
      • jdaviescoatesJ Online
        jdaviescoatesJ Online
        jdaviescoates
        wrote on last edited by jdaviescoates
        #3

        Aha! I think this was because even though I'm logged into my.cloudron as jdaviescoates in terms of OIDC in this browser I was logged in as 'josef' which didn't have access! I added josef to the relevant group and then I was back in.

        Confusing!

        @staff it'd be good if the OIDC somehow prompted to choose which user you want to use/ gave the option of logging in as a different user like on Google etc - would that be possible?

        Also - how do I actually end/ close the OIDC session for josef so I can login to these sites as jdaviescoates instead?

        And/ or is it somehow possible to be logged into both and then be prompted to choose which one I want to use when logging into a new app? This would be ideal as I use josef for some apps and jdaviescoates for others.

        I use Cloudron with Gandi & Hetzner

        jdaviescoatesJ 1 Reply Last reply
        1
        • jdaviescoatesJ jdaviescoates

          Aha! I think this was because even though I'm logged into my.cloudron as jdaviescoates in terms of OIDC in this browser I was logged in as 'josef' which didn't have access! I added josef to the relevant group and then I was back in.

          Confusing!

          @staff it'd be good if the OIDC somehow prompted to choose which user you want to use/ gave the option of logging in as a different user like on Google etc - would that be possible?

          Also - how do I actually end/ close the OIDC session for josef so I can login to these sites as jdaviescoates instead?

          And/ or is it somehow possible to be logged into both and then be prompted to choose which one I want to use when logging into a new app? This would be ideal as I use josef for some apps and jdaviescoates for others.

          jdaviescoatesJ Online
          jdaviescoatesJ Online
          jdaviescoates
          wrote on last edited by
          #4

          @jdaviescoates said in Can no longer access most of my WordPress sites:

          Also - how do I actually end/ close the OIDC session for josef so I can login to these sites as jdaviescoates instead?

          The ony way I seemed to be able to do this was to first logout of my.cloudron as jdaviescoates. I was still logged into my.cloudron as josef so I logged out as that too. Then log back in as jdaviescoates. Then I was able to login the the WordPress sitest as 'jdaviescoates' as I wanted. And interestingly I'm still logged into my Mastodon and Element apps as josef.

          Seems we need some sort of "switch user" capability if that's possible with OIDC?

          I use Cloudron with Gandi & Hetzner

          1 Reply Last reply
          1
          • imc67I Online
            imc67I Online
            imc67
            translator
            wrote on last edited by
            #5
            • 1 from me, asked this before because IMHO it is still a security issue that you can't OIDC logout from apps.
            1 Reply Last reply
            1
            • nebulonN Offline
              nebulonN Offline
              nebulon
              Staff
              wrote on last edited by
              #6

              In OpenID there is no well supported way to log out users from services which used the OpenID for authentication (in Cloudron case the apps). Those app have their own session and session handling. So there is mostly likely no way around this unless an app would start using OAuth2 access and refresh tokens (but implementation of that was spotty in the past which sparked OpenID connect in the first place)

              For a start if you logout of the dashboard, subsequent app logins (from a state where the app has no login session) then Cloudron will prompt you to login with a username. If that is not happening the Oidc session was still alive.

              The best way I found was to use container tabs in like firefox and probably other browsers, which maintain isolated sessions. This is also how I use other services like Digitalocean where we have multiple accounts with different roles.

              1 Reply Last reply
              1
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


              • Login

              • Don't have an account? Register

              • Login or register to search.
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • Bookmarks
              • Search