[CWB] Support OIDC authentication, please
Martin Wynne
martin.wynne at ling-phil.ox.ac.uk
Thu Jul 18 10:50:22 CEST 2024
Dear Andrew et al,
We've been thinking about this in Oxford, and it would be extremely
useful to have OIDC, or some other way of allowing users to log in with
their institutional credentials, rather than issuing and managing user
accounts ourselves.
I did get Shibboleth working in the past with BNCweb (for the benefit of
other listeners, BNCweb is a modified version of CQPweb) in the past,
and, once we had the server set up and registered as a Shibboleth
service provider, with the relevant keys and certificates in place it
was only a matter of changing the apache configuration to require
Shibboleth authentication to access the BNCweb application. It appears
that OIDC is a preferred way to do this nowadays, rather than native
Shibboleth.
I discussed this briefly with technical folks in the CLARIN research
infrastructure, who recommended OIDC as a solution, but I also don't
know enough about how to implement it without looking into it further. I
do know that as well as the technical setup, you'd need to register with
the UK Federation as a trusted Shibboleth service provider, which would
probably involve going through your institutional contact in IT Services
in your university, but shouldn't be too onerous.
There are a number of online services which use shibboleth-based login
(you can see a list at
https://www.clarin.eu/content/easy-access-protected-resources) but as
far as I can see, none of them are instances of CQPweb, and I can't tell
if they use OICD.
I'd be interested in taking this further and getting more advice on how
to implement OIDC and how to make it work with CQPweb, and could ask
CLARIN experts in this domain to help.
Best wishes,
Martin
On 27/06/2024 04:52, Hardie, Andrew wrote:
>
> Speaking only for myself, I don’t understand enough about OIDC
> authentication to say whether or not this is possible – I certainly
> couldn’t implement it without a lot of work learning about it.
>
> What do others think – is this a necessary feature, or not?
>
> best
>
> Andrew.
>
> *From:* cwb-bounces at sslmit.unibo.it <cwb-bounces at sslmit.unibo.it> *On
> Behalf Of *???
> *Sent:* Friday, June 14, 2024 9:46 PM
> *To:* cwb at sslmit.unibo.it
> *Subject:* [CWB] Support OIDC authentication, please
>
> Thus, we can integrate CQPweb with other systems.
>
>
>
>
>
> ---------
>
> Vincent
>
>
> _______________________________________________
> CWB mailing list
> CWB at sslmit.unibo.it
> http://liste.sslmit.unibo.it/mailman/listinfo/cwb
--
Senior Researcher in Corpus Linguistics
Faculty of Linguistics, Philology and Phonetics, University of Oxford
National Co-ordinator, CLARIN-UK
martin.wynne at ling-phil.ox.ac.uk
https://orcid.org/0000-0002-4155-0530
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://liste.sslmit.unibo.it/pipermail/cwb/attachments/20240718/77b93382/attachment.html>
More information about the CWB
mailing list