| Both sides previous revision Previous revision Next revision | Previous revision |
| en:2.0:single_sign_on:oidc_mailman3 [2026/09/09 12:39] – [Quick Overview] kainhofer | en:2.0:single_sign_on:oidc_mailman3 [2026/09/09 13:55] (current) – [Setting up the Client (RP) in Admidio] kainhofer |
|---|
| * Go to the Accounts section and select "Social Apps", where you can add a new OpenID provider through Admidio (see below where the individual settings can be copied from): | * Go to the Accounts section and select "Social Apps", where you can add a new OpenID provider through Admidio (see below where the individual settings can be copied from): |
| {{ :en:2.0:sso:sso_mailman3_oidc_02_mailman_socialapp.png?direct&600 |}} | {{ :en:2.0:sso:sso_mailman3_oidc_02_mailman_socialapp.png?direct&600 |}} |
| {{ :en:2.0:sso:sso_mailman3_oidc_03_mailman_socialappsettings.png?direct&600 |}} | |
| |
| * It is now a good idea to keep two browser windows open with Admidio and Mailman3's configuration so one can easily select and copy the settings. | * It is now a good idea to keep two browser windows open with Admidio and Mailman3's configuration so one can easily select and copy the settings. |
| * Enter the **scopes** you desire in the Mailman3 config and make sure that Admidio's config matches it. At least **openid must be included** (Admidio will implicitly add it). | * Enter the **scopes** you desire in the Mailman3 config and make sure that Admidio's config matches it. At least **openid must be included** (Admidio will implicitly add it). |
| * In mailman, choose a provider_id, which will be part of the redirect URL that needs to be entered into Admidio. The Redirect URL for Admidio is:<code>https://[YOUR_MAILMAN]/accounts/[PROVIDER_ID]/login/callback/</code> | * In mailman, choose a provider_id, which will be part of the redirect URL that needs to be entered into Admidio. The Redirect URL for Admidio is:<code>https://[YOUR_MAILMAN]/accounts/[PROVIDER_ID]/login/callback/</code> |
| | * Enabling PKCE for increased security cannot fully be done in the UI. The ''"oauth_pkce_enabled": true'' setting is only one part. The overall PKCE enablement must be done in ''settings_local.py'': <code python> |
| | # PKCE must be configured here, not in the "Settings" field in the Django admin. |
| | # Note: no "APPS" key here on purpose -- the app is configured in the Django admin, and |
| | # declaring it in both places makes allauth fail with multiple matching apps. |
| | SOCIALACCOUNT_PROVIDERS = { |
| | "openid_connect": { |
| | "OAUTH_PKCE_ENABLED": True, |
| | } |
| | } |
| | </code> |
| |
| |