[CWB] Support OIDC authentication, please

Martin Wynne martin.wynne at ling-phil.ox.ac.uk
Thu Jul 18 10:50:22 CEST 2024


Dear Andrew et al,

We've been thinking about this in Oxford, and it would be extremely 
useful to have OIDC, or some other way of allowing users to log in with 
their institutional credentials, rather than issuing and managing user 
accounts ourselves.

I did get Shibboleth working in the past with BNCweb (for the benefit of 
other listeners, BNCweb is a modified version of CQPweb) in the past, 
and, once we had the server set up and registered as a Shibboleth 
service provider, with the relevant keys and certificates in place it 
was only a matter of changing the apache configuration to require 
Shibboleth authentication to access the BNCweb application. It appears 
that OIDC is a preferred way to do this nowadays, rather than native 
Shibboleth.

I discussed this briefly with technical folks in the CLARIN research 
infrastructure, who recommended OIDC as a solution, but I also don't 
know enough about how to implement it without looking into it further. I 
do know that as well as the technical setup, you'd need to register with 
the UK Federation as a trusted Shibboleth service provider, which would 
probably involve going through your institutional contact in IT Services 
in your university, but shouldn't be too onerous.

There are a number of online services which use shibboleth-based login 
(you can see a list at 
https://www.clarin.eu/content/easy-access-protected-resources) but as 
far as I can see, none of them are instances of CQPweb, and I can't tell 
if they use OICD.

I'd be interested in taking this further and getting more advice on how 
to implement OIDC and how to make it work with CQPweb, and could ask 
CLARIN experts in this domain to help.

Best wishes,
Martin

On 27/06/2024 04:52, Hardie, Andrew wrote:
>
> Speaking only for myself, I don’t understand enough about OIDC 
> authentication to say whether or not this is possible – I certainly 
> couldn’t implement it without a lot of work learning about it.
>
> What do others think – is this a necessary feature, or not?
>
> best
>
> Andrew.
>
> *From:* cwb-bounces at sslmit.unibo.it <cwb-bounces at sslmit.unibo.it> *On 
> Behalf Of *???
> *Sent:* Friday, June 14, 2024 9:46 PM
> *To:* cwb at sslmit.unibo.it
> *Subject:* [CWB] Support OIDC authentication, please
>
> Thus, we can integrate CQPweb with other systems.
>
>
>
>
>
> ---------
>
> Vincent
>
>
> _______________________________________________
> CWB mailing list
> CWB at sslmit.unibo.it
> http://liste.sslmit.unibo.it/mailman/listinfo/cwb

-- 
Senior Researcher in Corpus Linguistics
Faculty of Linguistics, Philology and Phonetics, University of Oxford
National Co-ordinator, CLARIN-UK
martin.wynne at ling-phil.ox.ac.uk
https://orcid.org/0000-0002-4155-0530
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://liste.sslmit.unibo.it/pipermail/cwb/attachments/20240718/77b93382/attachment.html>


More information about the CWB mailing list