Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -33,12 +33,21 @@ and this project adheres to
- Bump the Elasticsearch test service to `8.8.1` so its bundled JDK can read
cgroup v2 hosts, fixing the `test-python` CI jobs
- Fix XAPI definitions extensions not accepting empty strings as values.
- Fix type of OIDC ID tokens
- Fix error with OIDC scopes unrelated to Ralph
- Fix oidc test `test_api_auth_oidc_get_whoami_invalid_backend`
being misconfigured
- Keep CORS disabled by default in `.env.dist` so a bootstrapped `.env` no
longer breaks the `RUNSERVER_CORS_ALLOW_ORIGINS` settings unit tests

### Changed

- Refactor statements' ExtensionMap
- Auth: changed default TTL of cache to 60 seconds
- OIDC: Add query to `/userinfo` endpoint when receiving a
token to support more OIDC IdPs
- OIDC: Add token introspection to support querying from OIDC clients
(Client Credentials flow)

## [5.0.1] - 2024-07-11

Expand Down
18 changes: 12 additions & 6 deletions docs/tutorials/lrs/authentication/oidc.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,20 @@

Ralph LRS also supports OpenID Connect on top of OAuth 2.0 for authentication and authorization.

To enable OpenID Connect authentication mode, we should change the `RALPH_RUNSERVER_AUTH_BACKENDS` environment variable to `oidc` and we should define the `RALPH_RUNSERVER_AUTH_OIDC_ISSUER_URI` environment variable with the identity provider's Issuer Identifier URI as follows:
To enable OpenID Connect authentication mode, we should change the `RALPH_RUNSERVER_AUTH_BACKENDS` environment variable to `oidc` and we should define the environment variables as follows:

- `RALPH_RUNSERVER_AUTH_OIDC_ISSUER_URI` the identity provider's Issuer Identifier URI
This address must be accessible to the LRS on startup as it will perform OpenID Connect Discovery to retrieve public keys and other information about the OpenID Connect environment.
- `RALPH_RUNSERVER_AUTH_OIDC_CLIENT_ID` the OIDC client id issued by the identity provider for this instance
- `RALPH_RUNSERVER_AUTH_OIDC_CLIENT_SECRET` the OIDC client secret issued by the identity provider for this instance

```bash
RALPH_RUNSERVER_AUTH_BACKENDS=oidc
RALPH_RUNSERVER_AUTH_OIDC_ISSUER_URI=http://{provider_host}:{provider_port}/auth/realms/{realm_name}
RALPH_RUNSERVER_AUTH_OIDC_CLIENT_ID=some_client_id
RALPH_RUNSERVER_AUTH_OIDC_CLIENT_SECRET=some_client_secret
```

This address must be accessible to the LRS on startup as it will perform OpenID Connect Discovery to retrieve public keys and other information about the OpenID Connect environment.

It is also strongly recommended to set the optional `RALPH_RUNSERVER_AUTH_OIDC_AUDIENCE` environment variable to the origin address of Ralph LRS itself (e.g. "http://localhost:8100") to enable verification that a given token was issued specifically for that Ralph LRS.

Expand Down Expand Up @@ -74,7 +80,7 @@ services:
networks:
ralph:
external: true

```

Again, we need to create the `.ralph` directory:
Expand Down Expand Up @@ -102,7 +108,7 @@ Now that both Keycloak and Ralph LRS server are up and running, we should be abl
```

```bash
{"access_token":"<access token content>","expires_in":300,"refresh_expires_in":1800,"refresh_token":"<refresh token content>","token_type":"Bearer","not-before-policy":0,"session_state":"0889b3a5-d742-45fb-98b3-20e967960e74","scope":"email profile"}
{"access_token":"<access token content>","expires_in":300,"refresh_expires_in":1800,"refresh_token":"<refresh token content>","token_type":"Bearer","not-before-policy":0,"session_state":"0889b3a5-d742-45fb-98b3-20e967960e74","scope":"email profile"}
```
=== "HTTPie"

Expand Down Expand Up @@ -134,12 +140,12 @@ Now that both Keycloak and Ralph LRS server are up and running, we should be abl
With this access token, we can now make a request to the Ralph LRS server:

=== "curl"

```bash
curl -H 'Authorization: Bearer <access token content>' \
http://localhost:8100/whoami
```

```bash
{"agent":{"openid":"http://localhost:8080/auth/realms/fun-mooc/b6e85bd0-ce6e-4b24-9f0e-6e18d8744e54"},"scopes":["email","profile"]}
```
Expand Down
4 changes: 2 additions & 2 deletions src/helm/ralph/templates/cm_lrs.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ data:
RALPH_APP_DIR: {{ .Values.lrs.appDir | quote }}
RALPH_RUNSERVER_BACKEND: {{ .Values.lrs.backend | quote }}
RALPH_RUNSERVER_MAX_SEARCH_HITS_COUNT: {{ .Values.lrs.maxSearchHitsCount | quote }}

# CLI
RALPH_CONVERTER_EDX_XAPI_UUID_NAMESPACE: {{ .Values.lrs.converterNamespace | quote }}

Expand All @@ -31,6 +31,7 @@ data:
{{- if .Values.lrs.auth.oidc.enabled }}
RALPH_RUNSERVER_AUTH_OIDC_AUDIENCE: {{ .Values.lrs.authOIDCAudience | quote }}
RALPH_RUNSERVER_AUTH_OIDC_ISSUER_URI: {{ .Values.lrs.authOIDCIssuerURI | quote }}
RALPH_AUTH_OIDC_CACHE_TTL: {{ .Values.lrs.auth.oidc.cacheTTL | quote }}
{{ end }}

# Sentry
Expand All @@ -41,4 +42,3 @@ data:
RALPH_SENTRY_LRS_TRACES_SAMPLE_RATE: {{ .Values.lrs.sentry.lrsSampleRate | quote }}
RALPH_SENTRY_IGNORE_HEALTH_CHECKS: {{ .Values.lrs.sentry.ignoreHealthChecks | quote }}
{{- end }}

2 changes: 1 addition & 1 deletion src/helm/ralph/templates/cronjob.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -36,7 +36,7 @@ spec:
{{- toYaml .Values.podSecurityContext | nindent 12 }}
containers:
- name: "{{ template "ralph.fullname" . }}-{{ $job.name }}"
securityContext:
securityContext:
{{- toYaml .Values.securityContext | nindent 16 }}
image: "{{ .Values.image.repository }}:{{ .Values.image.tag | default .Chart.AppVersion }}"
imagePullPolicy: {{ .Values.image.pullPolicy }}
Expand Down
1 change: 1 addition & 0 deletions src/helm/ralph/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -139,6 +139,7 @@ lrs:
enabled: false
audience: "http://localhost:8100"
issuerURI: "http://learning-analytics-playground_keycloak_1:8080/auth/realms/fun-mooc"
cacheTTL: 60
sentry:
enabled: false
dsn: "https://fake@key.ingest.sentry.io/1234567"
Expand Down
Loading