Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
en:2.0:single_sign_on:oidc_mailman3 [2026/09/09 12:39] – [Quick Overview] kainhoferen:2.0:single_sign_on:oidc_mailman3 [2026/09/09 13:55] (current) – [Setting up the Client (RP) in Admidio] kainhofer
Line 65: Line 65:
   * Go to the Accounts section and select "Social Apps", where you can add a new OpenID provider through Admidio (see below where the individual settings can be copied from):   * Go to the Accounts section and select "Social Apps", where you can add a new OpenID provider through Admidio (see below where the individual settings can be copied from):
 {{ :en:2.0:sso:sso_mailman3_oidc_02_mailman_socialapp.png?direct&600 |}} {{ :en:2.0:sso:sso_mailman3_oidc_02_mailman_socialapp.png?direct&600 |}}
-{{ :en:2.0:sso:sso_mailman3_oidc_03_mailman_socialappsettings.png?direct&600 |}} 
  
   * It is now a good idea to keep two browser windows open with Admidio and Mailman3's configuration so one can easily select and copy the settings.   * It is now a good idea to keep two browser windows open with Admidio and Mailman3's configuration so one can easily select and copy the settings.
Line 83: Line 82:
   * Enter the **scopes** you desire in the Mailman3 config and make sure that Admidio's config matches it. At least **openid must be included** (Admidio will implicitly add it).   * Enter the **scopes** you desire in the Mailman3 config and make sure that Admidio's config matches it. At least **openid must be included** (Admidio will implicitly add it).
   * In mailman, choose a provider_id, which will be part of the redirect URL that needs to be entered into Admidio. The Redirect URL for Admidio is:<code>https://[YOUR_MAILMAN]/accounts/[PROVIDER_ID]/login/callback/</code>   * In mailman, choose a provider_id, which will be part of the redirect URL that needs to be entered into Admidio. The Redirect URL for Admidio is:<code>https://[YOUR_MAILMAN]/accounts/[PROVIDER_ID]/login/callback/</code>
 +  * Enabling PKCE for increased security cannot fully be done in the UI. The ''"oauth_pkce_enabled": true'' setting is only one part. The overall PKCE enablement must be done in ''settings_local.py'': <code python>
 +# PKCE must be configured here, not in the "Settings" field in the Django admin. 
 +# Note: no "APPS" key here on purpose -- the app is configured in the Django admin, and
 +# declaring it in both places makes allauth fail with multiple matching apps.
 +SOCIALACCOUNT_PROVIDERS = {
 +    "openid_connect": {
 +        "OAUTH_PKCE_ENABLED": True,
 +    }
 +}
 +</code>
  
  
  • en/2.0/single_sign_on/oidc_mailman3.1788950373.txt.gz
  • Last modified: 2026/09/09 12:39
  • by kainhofer