Commit 361e5239 authored by Thibaut Vallee's avatar Thibaut Vallee
Browse files

0.0.13

parent d64665d2
Loading
Loading
Loading
Loading

CHANGELOG.md

0 → 100644
+10 −0
Changes for CHANGELOG.md: 10 added lines, 0 removed lines.
Original line number Diff line number Diff line
CHANGELOG
============

0.0.13 (24/03/2026)
------------------
- Authentification par CAS

0.0.12 (20/03/2026)
------------------
- Authentification par LDAP ou compte locaux
 No newline at end of file

README.md

0 → 100644
+85 −0
Changes for README.md: 85 added lines, 0 removed lines.
Original line number Diff line number Diff line
# Unicaen Authentification -- Api
============

Ce module est en charge de l'authentification via apiPlateforme 

## Types d'authentifications
Ce module gére pour le moment 3 types d'authentifications et 1 à venir
- Local
- [CAS.md](documentations/CAS.md) (plus local)
- [LDAP.md](documentations/LDAP.md)
- _Shib (à venir)_

## Installation
----------------------------------

### Prérequis
- [Docker-compose](https://docs.docker.com/compose/install/)

### Comande

```console
composer require unicaen-modern/authentification
```

### Config

L'utilisation des différentes méthodes d'authentification nécéssite de les configurer dans config/packages/security.yaml
```yaml
security:
    firewalls:
        main:
            entry_point: jwt # En cas d'accès refusé, c'est le système JWT qui répond

            # Configuration de la connexion initiale (Login)
            json_login:
                check_path: auth
                username_path: username # LDAP necessite obligatoirement d'utiliser le champs username et non l'email
                password_path: password
                success_handler: lexik_jwt_authentication.handler.authentication_success
                failure_handler: lexik_jwt_authentication.handler.authentication_failure

            # Active l'authentification par jeton JWT pour les requêtes suivantes
            jwt: ~

            # Gestion du renouvellement du jeton (Refresh Token)
            refresh_jwt:
                check_path: auth_refresh_token

            # Route de déconnexion
            logout:
                path: auth_logout

            # Authentificateurs personnalisés (Commenter ceux non utilisés)
            custom_authenticator:
                - Unicaen\Authentification\Security\CasAuthenticator
                - Unicaen\Authentification\Security\LdapAuthenticator

    # Contrôle d'accès : définit les rôles nécessaires pour chaque URL.
    access_control:
        - { path: ^/auth, roles: PUBLIC_ACCESS } # Connexion publique obligatoire
        - { path: ^/auth/cas, roles: PUBLIC_ACCESS }  # (commenter si CAS non utilisé)
```

La déclaration des routes d'authentification de l'api est à définir dans votre répertoire /config/routes/
Le fichier [unicaen_authentification.yaml.dist](documentations/config/unicaen_authentification.yaml.dist) est un exemple que l'on peut copier/coller

La déclaration des routes d'authentification de l'api est à définir dans votre répertoire /config/routes/
Le fichier [gesdinet_jwt_refresh_token.yaml.dist](documentations/config/gesdinet_jwt_refresh_token.yaml.dist) est un exemple que l'on peut copier/coller


## Améliorations a venir

- Paramètrage pour la création de l'utilisateur
- Système d'usurpation
- Paramètrage du type d'authentification 
- Authentification via Shibb

**Configuration des routes :**

Trouver comment intégrer directement la configuration des routes dans le bundle et ne plus avoir a copier/coller [unicaen_authentification.yaml.dist](./config/routes/unicaen_authentification.yaml.dist)

- Une approche qui vient de la v2 de Symfony : https://symfony.com/doc/2.x/routing/external_resources.html est fonctionnelle mais ne seras sans doute pas maintenue
- L'approche par déclaration de routes dans [CasController.php](src/Controller/CasController.php) (ou un autre) est fonctionnelle pour les routes de CAS, mais pas pour /auth/refresh qui repose sur un controlleur de JWT

_Ceci est une note en cours de rédaction, probablement incompléte. Toute contibution est la bienvenue_
+7 −1
Changes for composer.json: 7 added lines, 1 removed line.
Original line number Diff line number Diff line
@@ -20,7 +20,8 @@
        "api-platform/symfony": "*",
        "api-platform/core": "^4.2",
        "unicaen-modern/utilisateur": "^0.4",
        "unicaen-modern/privilege": "^1.4"
        "unicaen-modern/privilege": "^1.4",
        "symfony/security-bundle": "^7.3"
    },
    "require-dev": {
        "friendsofphp/php-cs-fixer": "^3.75",
@@ -32,5 +33,10 @@
                "Unicaen\\Authentification\\UnicaenAuthentificationBundle": "all"
            }
        }
    },
    "config": {
        "allow-plugins": {
            "symfony/runtime": true
        }
    }
}

config/services.yaml

0 → 100644
+45 −0
Changes for config/services.yaml: 45 added lines, 0 removed lines.
Original line number Diff line number Diff line
parameters:
    env(CAS_SERVER_URL): ''
    env(CAS_SERVICE_URL): ''
    env(CAS_SSL_VERIFY): 'false'
    env(LDAP_HOST): ''
    env(LDAP_PORT): ''
    env(LDAP_BASE_DN): ''
    env(LDAP_UID_KEY): ''
    env(LDAP_USER): ''
    env(LDAP_PASSWORD): ''

services:
    _defaults:
        autowire: true
        autoconfigure: true

    Unicaen\Authentification\:
        resource: '../src/*'

    #### Authentification par LDAP
    Unicaen\Authentification\Service\LdapService:
        arguments:
            $host: '%env(LDAP_HOST)%'
            $port: '%env(LDAP_PORT)%'
            $searchDn: '%env(LDAP_BASE_DN)%'
            $uidKey: '%env(LDAP_UID_KEY)%'
            $bindDn: '%env(LDAP_USER)%'
            $bindPassword: '%env(LDAP_PASSWORD)%'

    Unicaen\Authentification\Security\LdapAuthenticator:
        arguments:
            $successHandler: '@lexik_jwt_authentication.handler.authentication_success'
            $failureHandler: '@lexik_jwt_authentication.handler.authentication_failure'

    #### Authentification par LDAP
    Unicaen\Authentification\Service\CasService:
        arguments:
            $casServerUrl: '%env(CAS_SERVER_URL)%'
            $casServiceUrl: '%env(CAS_SERVICE_URL)%'
            $verifySsl: '%env(bool:CAS_SSL_VERIFY)%'

    Unicaen\Authentification\Security\CasAuthenticator:
        arguments:
            $successHandler: '@lexik_jwt_authentication.handler.authentication_success'
            $failureHandler: '@lexik_jwt_authentication.handler.authentication_failure'

documentations/CAS.md

0 → 100644
+52 −0
Changes for documentations/CAS.md: 52 added lines, 0 removed lines.
Original line number Diff line number Diff line
UnicaenAuthentification -- CAS
============

UnicaenAuthentification autorise l'authentification centralisé via un CAS

# Flux de l'authentification

1. Appel de la route api/auth/cas/redirect
2. Redirection vers le serveur CAS (\$CAS_SERVER_URL)
3. Demande d'authentification si l'utilisateur n'est pas connecté
4. Le serveur CAS redirige vers le front-end (\$CAS_SERVICE_URL) avec le paramètre ?ticket=ST-xxx
5. Le front-end extrait le ticjet et fait appel à l'url /auth/cas pour le valider et obtenir un JWT.
6. En cas de succès, redirige vers la page courante. En cas d'erreur, on affiche un message et un bouton de retour.


# Configuration

Les paramétres d'authentification par CAS repose par défaut sur trois variables d'environnement à définir dans votre .env

```
CAS_SERVER_URL=https://cas.xxxx.fr
CAS_SERVICE_URL=https://appname.xxx.fr/auth/cas/redirect
CAS_SSL_VERIFY=true
```

- CAS_SERVER_URL est l'url du serveur d'authentification
- CAS_SERVICE_URL est l'url front-end vers laquels le CAS doit être rediriger. Cette url front-end sera en charge de transformer le token du CAS en token jwt.
    Il est important que cette url corresponde à la route définie coté front-end dans `router/authentificationRouter.js`
- CAS_SSL_VERIFY détermine si l'on utilise un certificat SSL

Ces variables sont fournis aux services [CasService.php](../src/Service/CasService.php) via la configuration.
Vous pouvez les surchager dans votre fichier de config

``` /config/services.yaml
services:
    Unicaen\Authentification\Service\CasService:
        arguments:
            $casServerUrl: 'https://cas.yyyy.fr'
            $casServiceUrl: 'https://appname.yyyy.fr/auth/cas/redirect'
            $verifySsl: 'false'
```

Pour utiliser l'authentification du CAS, inclure l'authenticator [CasAuthenticator.php](../src/Security/CasAuthenticator.php)

```yaml
security:
    firewalls:
        main:
            #....
            custom_authenticator: 
              - Unicaen\Authentification\Security\CasAuthenticator
```
Loading