[Pharo-project] SSO - CAS Client in Smalltalk ?
Hi all, I'd like to develop some web apps for our university but one prerequisite is to use the Central Authentication Service [1]. It's an open source authentication service and I wonder if somebody has ever worked with it and if there are any client available. Do you have any experience and/or pointers ? If not, I may dog into the protocol and see what I can do. I've spotted PHP implementation and also Ruby [2]. I think that could be a nice addition to Zinc even if not as widespread as OAuth/OpenID stuffs. TIA Cédrick [1] http://en.wikipedia.org/wiki/Central_Authentication_Service [2] https://github.com/rubycas/rubycas-client
as a complement, here are the links to CAS protocol: http://www.jasig.org/cas/protocol Cheers, Cédrick
Hi cedric Let us know because I like to get as protocol and solutions to interact with the world. May be such effort could be supported by esug too. Stef On May 11, 2012, at 2:18 PM, Cédrick Béler wrote:
Hi all,
I'd like to develop some web apps for our university but one prerequisite is to use the Central Authentication Service [1]. It's an open source authentication service and I wonder if somebody has ever worked with it and if there are any client available. Do you have any experience and/or pointers ?
If not, I may dog into the protocol and see what I can do. I've spotted PHP implementation and also Ruby [2].
I think that could be a nice addition to Zinc even if not as widespread as OAuth/OpenID stuffs.
TIA
Cédrick
[1] http://en.wikipedia.org/wiki/Central_Authentication_Service [2] https://github.com/rubycas/rubycas-client
Hi Steph, I'll let you know. CAS seems to be kind of standard for high organization SSO. It's just sad I didn't thought of it for Google Summer of Code. This could have been an opportunity. There's also ESUG. But maybe others should say of they find such an implementation useful (and not only me :) ). Cheers, Cédrick Le 12 mai 2012 à 10:33, Stéphane Ducasse a écrit :
Hi cedric
Let us know because I like to get as protocol and solutions to interact with the world. May be such effort could be supported by esug too.
Stef
On May 11, 2012, at 2:18 PM, Cédrick Béler wrote:
Hi all,
I'd like to develop some web apps for our university but one prerequisite is to use the Central Authentication Service [1]. It's an open source authentication service and I wonder if somebody has ever worked with it and if there are any client available. Do you have any experience and/or pointers ?
If not, I may dog into the protocol and see what I can do. I've spotted PHP implementation and also Ruby [2].
I think that could be a nice addition to Zinc even if not as widespread as OAuth/OpenID stuffs.
TIA
Cédrick
[1] http://en.wikipedia.org/wiki/Central_Authentication_Service [2] https://github.com/rubycas/rubycas-client
Bonjour Cédrick, Stépahane, On 14 May 2012, at 19:44, Cédrick Béler wrote:
I'll let you know.
CAS seems to be kind of standard for high organization SSO. It's just sad I didn't thought of it for Google Summer of Code. This could have been an opportunity. There's also ESUG. But maybe others should say of they find such an implementation useful (and not only me :) ).
Yes, these are interesting add-on projects. The basis (Pharo+Zn+Zdc) is there, I don't think these are major undertakings, but they can get stuck on some small seemingly insurmountable detail. Step 1 is to understand the specification and the foundation to start from. Looking at implementations in other languages helps. Regards, Sven PS: Cédrick, I remember the OAuth (Dropbox) stuff that you were trying. Any chance to start that again ? ;-) -- Sven Van Caekenberghe http://stfx.eu Smalltalk is the Red Pill
Hi guys, Just FYI, me and Cloudfork guys are just finishing the OpenID 2.0/OAuth 2.0 support for Iliad and Aida, based on Cloudfork SSO [1]. On Pharo and VW. On Pharo Zync with Zodiak SSL is used. Current goal is to develop a Google Docs API support. Let me also thanks in this ocasion to the Citilab Barcelona which sponsor our work. [1] http://blog.doit.st/2011/02/15/cloudforksso-openid-and-oauth-support-for-sma... Best regards Janko Dne 14. 05. 2012 19:58, piše Sven Van Caekenberghe:
Bonjour Cédrick, Stépahane,
On 14 May 2012, at 19:44, Cédrick Béler wrote:
I'll let you know.
CAS seems to be kind of standard for high organization SSO. It's just sad I didn't thought of it for Google Summer of Code. This could have been an opportunity. There's also ESUG. But maybe others should say of they find such an implementation useful (and not only me :) ).
Yes, these are interesting add-on projects. The basis (Pharo+Zn+Zdc) is there, I don't think these are major undertakings, but they can get stuck on some small seemingly insurmountable detail. Step 1 is to understand the specification and the foundation to start from. Looking at implementations in other languages helps.
Regards,
Sven
PS: Cédrick, I remember the OAuth (Dropbox) stuff that you were trying. Any chance to start that again ? ;-)
-- Sven Van Caekenberghe http://stfx.eu Smalltalk is the Red Pill
-- Janko Mivšek Aida/Web Smalltalk Web Application Server http://www.aidaweb.si
That is excellent news. I will check it out after the Pharo conference for sure. Thanks for the pointer, Janko. On 14 May 2012, at 21:07, Janko Mivšek wrote:
Hi guys,
Just FYI, me and Cloudfork guys are just finishing the OpenID 2.0/OAuth 2.0 support for Iliad and Aida, based on Cloudfork SSO [1]. On Pharo and VW. On Pharo Zync with Zodiak SSL is used. Current goal is to develop a Google Docs API support.
Let me also thanks in this ocasion to the Citilab Barcelona which sponsor our work.
[1] http://blog.doit.st/2011/02/15/cloudforksso-openid-and-oauth-support-for-sma...
Best regards Janko
Dne 14. 05. 2012 19:58, piše Sven Van Caekenberghe:
Bonjour Cédrick, Stépahane,
On 14 May 2012, at 19:44, Cédrick Béler wrote:
I'll let you know.
CAS seems to be kind of standard for high organization SSO. It's just sad I didn't thought of it for Google Summer of Code. This could have been an opportunity. There's also ESUG. But maybe others should say of they find such an implementation useful (and not only me :) ).
Yes, these are interesting add-on projects. The basis (Pharo+Zn+Zdc) is there, I don't think these are major undertakings, but they can get stuck on some small seemingly insurmountable detail. Step 1 is to understand the specification and the foundation to start from. Looking at implementations in other languages helps.
Regards,
Sven
PS: Cédrick, I remember the OAuth (Dropbox) stuff that you were trying. Any chance to start that again ? ;-)
-- Sven Van Caekenberghe http://stfx.eu Smalltalk is the Red Pill
-- Janko Mivšek Aida/Web Smalltalk Web Application Server http://www.aidaweb.si
On May 14, 2012, at 9:07 PM, Janko Mivšek wrote:
Hi guys,
Just FYI, me and Cloudfork guys are just finishing the OpenID 2.0/OAuth 2.0 support for Iliad and Aida, based on Cloudfork SSO [1]. On Pharo and VW. On Pharo Zync with Zodiak SSL is used. Current goal is to develop a Google Docs API support.
Hi janko is the library available as a library? I mean not linked to aida or iliad? Stef
Let me also thanks in this ocasion to the Citilab Barcelona which sponsor our work.
[1] http://blog.doit.st/2011/02/15/cloudforksso-openid-and-oauth-support-for-sma...
Best regards Janko
Dne 14. 05. 2012 19:58, piše Sven Van Caekenberghe:
Bonjour Cédrick, Stépahane,
On 14 May 2012, at 19:44, Cédrick Béler wrote:
I'll let you know.
CAS seems to be kind of standard for high organization SSO. It's just sad I didn't thought of it for Google Summer of Code. This could have been an opportunity. There's also ESUG. But maybe others should say of they find such an implementation useful (and not only me :) ).
Yes, these are interesting add-on projects. The basis (Pharo+Zn+Zdc) is there, I don't think these are major undertakings, but they can get stuck on some small seemingly insurmountable detail. Step 1 is to understand the specification and the foundation to start from. Looking at implementations in other languages helps.
Regards,
Sven
PS: Cédrick, I remember the OAuth (Dropbox) stuff that you were trying. Any chance to start that again ? ;-)
-- Sven Van Caekenberghe http://stfx.eu Smalltalk is the Red Pill
-- Janko Mivšek Aida/Web Smalltalk Web Application Server http://www.aidaweb.si
Dne 15. 05. 2012 00:01, piše Stéphane Ducasse:
Just FYI, me and Cloudfork guys are just finishing the OpenID 2.0/OAuth 2.0 support for Iliad and Aida, based on Cloudfork SSO [1]. On Pharo and VW. On Pharo Zync with Zodiak SSL is used. Current goal is to develop a Google Docs API support.
Hi janko
is the library available as a library? I mean not linked to aida or iliad?
Idea actually is to have WebCloudSSO library as independent as possible, but not without some web server/web framework, because OpenID/OAuth rely heavily on HTTP redirects. WebCloudSSO library currently works on Aida, now I'll start adapting it to Iliad, later someone can adapt it to Seaside or even to plain web server like Zync. Maybe it will even come under Cloudfork trademark at the end, we will see. Cloudfork otherwise already have a Seaside OpenID example. Janko
Stef
Let me also thanks in this ocasion to the Citilab Barcelona which sponsor our work.
[1] http://blog.doit.st/2011/02/15/cloudforksso-openid-and-oauth-support-for-sma...
Best regards Janko
Dne 14. 05. 2012 19:58, piše Sven Van Caekenberghe:
Bonjour Cédrick, Stépahane,
On 14 May 2012, at 19:44, Cédrick Béler wrote:
I'll let you know.
CAS seems to be kind of standard for high organization SSO. It's just sad I didn't thought of it for Google Summer of Code. This could have been an opportunity. There's also ESUG. But maybe others should say of they find such an implementation useful (and not only me :) ).
Yes, these are interesting add-on projects. The basis (Pharo+Zn+Zdc) is there, I don't think these are major undertakings, but they can get stuck on some small seemingly insurmountable detail. Step 1 is to understand the specification and the foundation to start from. Looking at implementations in other languages helps.
Regards,
Sven
PS: Cédrick, I remember the OAuth (Dropbox) stuff that you were trying. Any chance to start that again ? ;-)
-- Sven Van Caekenberghe http://stfx.eu Smalltalk is the Red Pill
-- Janko Mivšek Aida/Web Smalltalk Web Application Server http://www.aidaweb.si
On 15/05/12 3:00 AM, Janko Mivšek wrote:
Dne 15. 05. 2012 00:01, piše Stéphane Ducasse:
Just FYI, me and Cloudfork guys are just finishing the OpenID 2.0/OAuth 2.0 support for Iliad and Aida, based on Cloudfork SSO [1]. On Pharo and VW. On Pharo Zync with Zodiak SSL is used. Current goal is to develop a Google Docs API support.
Hi janko
is the library available as a library? I mean not linked to aida or iliad?
Idea actually is to have WebCloudSSO library as independent as possible, but not without some web server/web framework, because OpenID/OAuth rely heavily on HTTP redirects.
WebCloudSSO library currently works on Aida, now I'll start adapting it to Iliad, later someone can adapt it to Seaside or even to plain web server like Zync. Maybe it will even come under Cloudfork trademark at the end, we will see. Cloudfork otherwise already have a Seaside OpenID example.
Have I understood this right? You started with CloudforkSSO, "ported" it to Iliad and Aida (i.e. WebCloudSSO), and in future WebCloudSSO may merge back into CloudforkSSO. Was it just easier/faster to do it this way, rather than split the Seaside dependent parts out of CloudforkSSO? Is there any additional OpenID/OAuth functionality in WebCloudSSO, beyond what was in CloudforkSSO?
Dne 15. 05. 2012 16:41, piše Yanni Chiu:
On 15/05/12 3:00 AM, Janko Mivšek wrote:
Dne 15. 05. 2012 00:01, piše Stéphane Ducasse:
Just FYI, me and Cloudfork guys are just finishing the OpenID 2.0/OAuth 2.0 support for Iliad and Aida, based on Cloudfork SSO [1]. On Pharo and VW. On Pharo Zync with Zodiak SSL is used. Current goal is to develop a Google Docs API support.
is the library available as a library? I mean not linked to aida or iliad?
Idea actually is to have WebCloudSSO library as independent as possible, but not without some web server/web framework, because OpenID/OAuth rely heavily on HTTP redirects.
WebCloudSSO library currently works on Aida, now I'll start adapting it to Iliad, later someone can adapt it to Seaside or even to plain web server like Zync. Maybe it will even come under Cloudfork trademark at the end, we will see. Cloudfork otherwise already have a Seaside OpenID example.
Have I understood this right? You started with CloudforkSSO, "ported" it to Iliad and Aida (i.e. WebCloudSSO), and in future WebCloudSSO may merge back into CloudforkSSO. Was it just easier/faster to do it this way, rather than split the Seaside dependent parts out of CloudforkSSO?
WebCloudSSO uses and extends a bit updated original Cloudfork. I therefore didn't replace it. Separate package was chosen to more freely experiment and add OpenID/OAuth functionality to Aida and Iliad, now when WebCloudSSO stabilises, it is time to propose a merge back to Cloudfork. My idea and proposal is to have one "trademark" for all cloud related support and for all web frameworks. And Cloudfork is actually very good library, portable to many Smalltalks, so let me thank Jan van de Sandt and Ernest Micklei on this occasion for their excellent work!
Is there any additional OpenID/OAuth functionality in WebCloudSSO, beyond what was in CloudforkSSO?
Yes, OAuth 2.0 support, which is not in CloudforkSSO yet (just OAuth 1.0 there). An few OpenID 2.0 changes. Two main classes are added: OpenIDAuthenticator OAuthAuthorizator Best regards Janko -- Janko Mivšek Aida/Web Smalltalk Web Application Server http://www.aidaweb.si
Salut, Le 14 mai 2012 à 19:58, Sven Van Caekenberghe a écrit :
Bonjour Cédrick, Stépahane,
On 14 May 2012, at 19:44, Cédrick Béler wrote:
I'll let you know.
CAS seems to be kind of standard for high organization SSO. It's just sad I didn't thought of it for Google Summer of Code. This could have been an opportunity. There's also ESUG. But maybe others should say of they find such an implementation useful (and not only me :) ).
Yes, these are interesting add-on projects. The basis (Pharo+Zn+Zdc) is there, I don't think these are major undertakings, but they can get stuck on some small seemingly insurmountable detail. Step 1 is to understand the specification and the foundation to start from. Looking at implementations in other languages helps.
Yes, I've had a look at PHP and Ruby ones but I cannot at this moment dig more into it.
Regards,
Sven
PS: Cédrick, I remember the OAuth (Dropbox) stuff that you were trying. Any chance to start that again ? ;-)
Uhm, I fear it hasn't moved from what you've seen + what we've lost (squeaksource versions lost). The upload stuff wasn't working if I remember well. I may start again if useful but I cannot at this time + CAS would be my priority now if I could :( <OT - killers apps ?> Just for background, if I experiment that, it's because in our university, they plan to set up a Numeric Environment (ENT in french). Based on uPortal, called E-Sup. I find it sucks :) + it's expensive to deploy and configure (around 30k⬠!!!). This is Java ! What's working now is only CAS+LDAP. If I had CAS in Pharo, I could develop applications say in Seaside that could be integrated in this environment. I think something like E-Sup (uPortal) could be a great project in Pharo but... this is a long one. Maybe ESUG ? ObjectFusion ? :-) For management in uni, they use OS app suite called Coktail (Scholarix and friends...) and these tools are developed in web objects (woa), the Apple no more supported framework ! This is also an opportunity to develop applications in Pharo because Coktail seems alone in this field (being open source) </OT> Cheers, Cédrick
-- Sven Van Caekenberghe http://stfx.eu Smalltalk is the Red Pill
participants (5)
-
Cédrick Béler -
Janko Mivšek -
Stéphane Ducasse -
Sven Van Caekenberghe -
Yanni Chiu