如何为MediaWiki设置外部单点登录


How to setup external Single Sign On for MediaWiki?

我正试图为ExtAuthDB扩展的MediaWiki设置单点登录。目的是当用户登录主网站www.mysite.com时,自动从外部用户系统对用户进行身份验证。Mediawiki位于子域:www.wiki.mysite.com.

我已经安装了扩展,因为它在指南中说。所有特权都是正确的。但是它不工作。

ExtAuthDB.php是:

<?php
/**
* Authentication plugin interface. Instantiate a subclass of AuthPlugin
* and set $wgAuth to it to authenticate against some external tool.
*
* The default behavior is not to do anything, and use the local user
* database for all authentication. A subclass can require that all
* accounts authenticate externally, or use it only as a fallback; also
* you can transparently create internal wiki accounts the first time
* someone logs in who can be authenticated externally.
*
* This interface is a derivation of AuthJoomla and might change a bit before 1.4.0 final is done...
*
*/
$wgExtensionCredits['parserhook'][] = array (
'name' => 'ExtAuthDB',
'author' => 'Alessandra Bilardi',
'description' => 'Authenticate users about external MySQL database',
'url' => 'https://www.mediawiki.org/wiki/Extension:ExtAuthDB',
'version' => '0.1',
);
require_once ( "$IP/includes/AuthPlugin.php" );
class ExtAuthDB extends AuthPlugin
{
/**
* Add into LocalSettings.php the following code: 
*
* MySQL Host Name.
* $wgExtAuthDB_MySQL_Host = '';
* MySQL Username.      
* $wgExtAuthDB_MySQL_Username = '';
* MySQL Password.        
* $wgExtAuthDB_MySQL_Password = '';
* MySQL Database Name.    
* $wgExtAuthDB_MySQL_Database = '';
* MySQL Database Table of users data.
* $wgExtAuthDB_MySQL_Table = '';
* MySQL Database username column label.
* $wgExtAuthDB_MySQL_Login = '';
* MySQL Database login password column label
* $wgExtAuthDB_MySQL_Pswrd = '';
* MySQL Database email column label
* $wgExtAuthDB_MySQL_Email = '';
* MySQL Database user real name column label
* $wgExtAuthDB_MySQL_RealN = '';
* require_once("$IP/extensions/ExtAuthDB/ExtAuthDB.php");
* $wgAuth = new ExtAuthDB();
*
* @return Object Database
*/
private function connectToDB()
{
    $db = & Database :: newFromParams(
    $GLOBALS['wgExtAuthDB_MySQL_Host'],
    $GLOBALS['wgExtAuthDB_MySQL_Username'],
    $GLOBALS['wgExtAuthDB_MySQL_Password'],
    $GLOBALS['wgExtAuthDB_MySQL_Database']);
    $this->userTable = $GLOBALS['wgExtAuthDB_MySQL_Table'];
    $this->userLogin = $GLOBALS['wgExtAuthDB_MySQL_Login'];
    $this->userPswrd = $GLOBALS['wgExtAuthDB_MySQL_Pswrd'];//.$GLOBALS['$wgExtAuthDB_MySQL_Salt'];
    $this->userEmail = $GLOBALS['wgExtAuthDB_MySQL_Email'];
    $this->userRealN = $GLOBALS['wgExtAuthDB_MySQL_RealN'];
    wfDebug("ExtAuthDB::connectToDB() : DB failed to open'n");
    return $db;
}
/**
 * Check whether there exists a user account with the given name.
 * The name will be normalized to MediaWiki's requirements, so
 * you might need to munge it (for instance, for lowercase initial
 * letters).
 *
 * @param $username String: username.
 * @return bool
 * @public
 */
function userExists( $username ) {
    # Override this!
    return true;
}
/**
 * Check if a username+password pair is a valid login.
 * The name will be normalized to MediaWiki's requirements, so
 * you might need to munge it (for instance, for lowercase initial
 * letters).
 *
 * @param $username String: username.
 * @param $password String: user password.
 * @return bool
 * @public
 */
function authenticate( $username, $password )
{
    $db = $this->connectToDB();
    $hash_password = $db->selectRow($this->userTable,array ($this->userPswrd), array ($this->userLogin => $username ), __METHOD__ );
    if ($password == $hash_password->{$this->userPswrd}) {
        return true;
    }
    return false;
}
/**
 * Set the domain this plugin is supposed to use when authenticating.
 *
 * @param $domain String: authentication domain.
 * @public
 */
function setDomain( $domain ) {
    $this->domain = $domain;
}
/**
 * Check to see if the specific domain is a valid domain.
 *
 * @param $domain String: authentication domain.
 * @return bool
 * @public
 */
function validDomain( $domain ) {
    # Override this!
    return true;
}
/**
 * When a user logs in, optionally fill in preferences and such.
 * For instance, you might pull the email address or real name from the
 * external user database.
 *
 * The User object is passed by reference so it can be modified; don't
 * forget the & on your function declaration.
 *
 * @param User $user
 * @public
 */
function updateUser( &$user )
{
    $db = $this->connectToDB();
    $euser = $db->selectRow($this->userTable,array ( '*' ), array ($this->userLogin => $user->mName ), __METHOD__ );
    $user->setRealName($euser->{$this->userRealN});
    $user->setEmail($euser->{$this->userEmail});
    $user->mEmailAuthenticated = wfTimestampNow();
    $user->saveSettings();
    //exit;
    # Override this and do something
    return true;
}
function disallowPrefsEditByUser() {
    return array (
        'wpRealName' => true,
        'wpUserEmail' => true,
        'wpNick' => true
    );
}
/**
 * Return true if the wiki should create a new local account automatically
 * when asked to login a user who doesn't exist locally but does in the
 * external auth database.
 *
 * If you don't automatically create accounts, you must still create
 * accounts in some way. It's not possible to authenticate without
 * a local account.
 *
 * This is just a question, and shouldn't perform any actions.
 *
 * @return bool
 * @public
 */
function autoCreate() {
    return true;
}
/**
 * Can users change their passwords?
 *
 * @return bool
 */
function allowPasswordChange() {
    return false;
}
/**
 * Set the given password in the authentication database.
 * As a special case, the password may be set to null to request
 * locking the password to an unusable value, with the expectation
 * that it will be set later through a mail reset or other method.
 *
 * Return true if successful.
 *
 * @param $user User object.
 * @param $password String: password.
 * @return bool
 * @public
 */
function setPassword( $user, $password ) {
    return true;
}
/**
 * Update user information in the external authentication database.
 * Return true if successful.
 *
 * @param $user User object.
 * @return bool
 * @public
 */
function updateExternalDB( $user ) {
    $db = $this->connectToDB();
    $euser = $db->selectRow($this->userTable,array ( '*' ), array ($this->userLogin => $user->mName ), __METHOD__ );
    $user->setRealName($euser->{$this->userRealN});
    $user->setEmail($euser->{$this->userEmail});
    $user->mEmailAuthenticated = wfTimestampNow();
    $user->saveSettings();
    return true;
}
/**
 * Check to see if external accounts can be created.
 * Return true if external accounts can be created.
 * @return bool
 * @public
 */
function canCreateAccounts() {
    return false;
}
/**
 * Add a user to the external authentication database.
 * Return true if successful.
 *
 * @param User $user - only the name should be assumed valid at this point
 * @param string $password
 * @param string $email
 * @param string $realname
 * @return bool
 * @public
 */
function addUser( $user, $password, $email='', $realname='' ) {
    return false;
}

/**
 * Return true to prevent logins that don't authenticate here from being
 * checked against the local database's password fields.
 *
 * This is just a question, and shouldn't perform any actions.
 *
 * @return bool
 * @public
 */
function strict() {
    return true;
}
/**
 * When creating a user account, optionally fill in preferences and such.
 * For instance, you might pull the email address or real name from the
 * external user database.
 *
 * The User object is passed by reference so it can be modified; don't
 * forget the & on your function declaration.
 *
 * @param $user User object.
 * @param $autocreate bool True if user is being autocreated on login
 * @public
 */
function initUser( $user, $autocreate=false ) {
    # Override this to do something.
}
/**
 * If you want to munge the case of an account name before the final
 * check, now is your chance.
 */
function getCanonicalName( $username ) {
    return $username;
}
}

在LocalSettings.php中,我应该添加以下代码:

// add ExtAuthDB
// MySQL Host Name.
$wgExtAuthDB_MySQL_Host = 'localhost';
// MySQL Username.
$wgExtAuthDB_MySQL_Username = 'dbuser';
// MySQL Password.
$wgExtAuthDB_MySQL_Password = 'dbpassword';
// MySQL Database Name.
$wgExtAuthDB_MySQL_Database = 'base';
// MySQL Database Table of users data.
$wgExtAuthDB_MySQL_Table = 'members';
// MySQL Database username column label.
$wgExtAuthDB_MySQL_Login = 'username';
// MySQL Database login password column label
$wgExtAuthDB_MySQL_Pswrd = 'password';
$wgExtAuthDB_MySQL_Salt='salt';
// MySQL Database email column label
$wgExtAuthDB_MySQL_Email = 'email';
// MySQL Database user real name column label
$wgExtAuthDB_MySQL_RealN = 'real_name';
require_once("$IP/extensions/ExtAuthDB/ExtAuthDB.php");
$wgAuth = new ExtAuthDB();

对不起,我不得不复制完整的脚本,因为我不知道确切的错误在哪里。我的问题是:为什么它不起作用?错在哪里?

编辑:

我的外部用户表包含id,用户名,密码,salt, email, real_name。我认为这可能是因为单独的密码和盐字段,所以我试图在ExtAuthDB.php文件手动实现盐。不幸的是,它也没有起作用。然后我注释了这一行

我能够使用OAuth 2.0服务器从WordPress设置SSO(单点登录)到media wiki,我已经在这个帖子上发布了我的解决方案

或者您可以按照以下步骤:

  1. 首先你需要一个OAuth 2.0服务器,你可以自己实现它,详见这里运行你自己的OAuth 2.0服务器,或者最简单的方法是使用WordPress插件WP OAuth 2.0服务器,你不必购买专业版,你也可以通过使用免费的授予类型Authorization codes实现SSO

  2. 你需要在你的媒体wiki上安装OAuth 2.0客户端扩展,扩展可以在这里找到,按照那里的安装说明。

  3. 转到WordPress插件页面并激活OAuth服务器,然后导航到OAuth服务器并添加一个新客户端,给您的客户端一个名称,并在重定向URI中添加媒体wiki扩展页面上提到的链接,即http://your.wiki.domain/path/to/wiki/Special:OAuth2Client/callback,然后转到OAuth>客户端页面,您可以看到您新创建的客户端,单击编辑,在这里您可以看到clientIDClient secret在您的媒体wiki的localSettings.php中添加此ID和秘密。

  4. 在WordPress上创建一个页面,并将以下按钮与您的客户端id放在其中

    < a href="https://your-Domain-Where-OAuth-server-is-running.de/oauth/authorize?response_type=code&client_id=YOURCLIENTID&state=RANDOM-STRING&scope=basic"> go to wiki</a>不要忘记输入scope,否则你会得到一个媒体wiki内部错误。

  5. 如果一切正常,那么你应该在点击这个按钮后自动转到媒体wiki主页。Media wiki将显示您已登录。我花了一些时间才弄明白,我希望这对来这里的任何人都有帮助。

您需要为这个扩展运行MediaWiki更新脚本

许多扩展需要更新 update.php 脚本!

从浏览器

如果您无法访问服务器的命令行,则使用web更新器来运行更新脚本。

从命令行

命令行,或一个SSH shell或类似的:

  • 切换到维护目录!
  • 使用 php update.php 命令运行更新脚本!