Re: Add modern authentication (OAuth 2.0 + OIDC) to TortoiseSVN
Jon Martin via TortoiseSVN-dev <[email protected]> Wed, 10 Apr 2024 14:39:36 -0700 (PDT)
| Newsgroups | gmane.comp.version-control.subversion.tortoisesvn.devel |
|---|---|
| Message-ID | <[email protected]> |
------=_Part_326_1767728085.1712785176394 Content-Type: multipart/alternative; boundary="----=_Part_327_374166198.1712785176394" ------=_Part_327_374166198.1712785176394 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable It seems instead of (OAuth 2.0 + OIDC) I should be saying (OpenID Connect),= =20 as "OpenID Connect (OIDC) is an open authentication protocol that works on= =20 top of the OAuth 2.0 framework."=20 In my case OpenID Connect (OIDC) is implemented by the middle man (Azure=20 Application Proxy) not the SVN server. However I can see the need during= =20 development to authenticate to OIDC on the SVN server. It looks like the= =20 SVN server side is already taken care of by this Apache OIDC (OpenID=20 Connect) add on:=20 OpenID Certified=E2=84=A2 OpenID Connect Relying Party implementation for A= pache=20 HTTP Server 2.x https://github.com/OpenIDC/mod_auth_openidc Once TSVN can authenticate via any OpenID Connect. It should work with all. --Jon On Wednesday, March 20, 2024 at 12:28:13=E2=80=AFAM UTC-7 daniel.l...@gmail= .com=20 wrote: > From what I understand, OAuth2 requires both server- and clientside=20 > support. So any solution would need to involve both TortoiseSVN and the= =20 > Subversion project (or VisualSVN). I think it is a great idea but I think= =20 > some additional development resources would be required to make this=20 > happen. Any chance that you (or your company) can get involved in making= =20 > this happen? > > Kind regards, > Daniel > > > onsdag 20 mars 2024 kl. 08:11:28 UTC+1 skrev [email protected]: > > We have run into a problem trying to implement SVN on our secure cloud=20 > platform. Is it possible to pay someone to add modern authentication to= =20 > TortoiseSVN? > > Specifically we wish to use TortoiseSVN client to access VisualSVN Serve= r=20 > via Microsoft Azure Application Proxy. This requires TSVN to be conversa= nt=20 > in "OAuth 2.0 with OpenID Connect (OIDC)". See=20 > https://auth0.com/docs/authenticate/protocols/openid-connect-protocol > > You can see the error we get by using TortoiseSVN to open this test=20 > repository https://visualsvn.parabilis-space.com/svn/test/=20 > Error: Repository moved temporarily to ...Oath2/authorize... > > Thank You, > > --Jon > > --=20 You received this message because you are subscribed to the Google Groups "= TortoiseSVN-dev" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/= tortoisesvn-dev/5d07c8f2-c2a8-4cfb-b8df-502b87f66ca0n%40googlegroups.com. ------=_Part_327_374166198.1712785176394 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <p>It seems instead of (OAuth 2.0 + OIDC) I should be saying (OpenID Connect), as "OpenID Connect (OIDC) is an open authentication protocol that works on top of the OAuth 2.0 framework."=C2=A0</p> <p>In my case OpenID Connect (OIDC) is implemented by the middle man (<span style=3D"font-family: Aptos, serif; font-size: 11pt;">Azure Appl= ication Proxy)=C2=A0</span>not the SVN server.=C2=A0 However I can see the need during development to authenticate to OIDC on the SVN server.= =C2=A0 It looks like the SVN server side is already taken care of by this Apache OIDC (OpenID Connect) add on:=C2=A0</p> <p>OpenID Certified=E2=84=A2 OpenID Connect Relying Party implementation for Apache HTTP Server 2.x<br /> <a href=3D"https://github.com/OpenIDC/mod_auth_openidc">https://github.com/= OpenIDC/mod_auth_openidc</a></p><p>Once TSVN can authenticate via any OpenI= D Connect. It should work with all.</p>--Jon<div class=3D"gmail_quote"><div= dir=3D"auto" class=3D"gmail_attr">On Wednesday, March 20, 2024 at 12:28:13= =E2=80=AFAM UTC-7 [email protected] wrote:<br/></div><blockquote class= =3D"gmail_quote" style=3D"margin: 0 0 0 0.8ex; border-left: 1px solid rgb(2= 04, 204, 204); padding-left: 1ex;">From what I understand, OAuth2 requires = both server- and clientside support. So any solution would need to involve = both TortoiseSVN and the Subversion project (or VisualSVN). I think it is a= great idea but I think some additional development resources would be requ= ired to make this happen. Any chance that you (or your company) can get inv= olved in making this happen?<div><br></div><div>Kind regards,</div><div>Dan= iel</div><div><br><br><div><div dir=3D"auto">onsdag 20 mars 2024 kl. 08:11:= 28 UTC+1 skrev <a href data-email-masked rel=3D"nofollow">j...@parabilis-sp= ace.com</a>:<br></div><blockquote style=3D"margin:0px 0px 0px 0.8ex;border-= left:1px solid rgb(204,204,204);padding-left:1ex"><p>We have run into a pro= blem trying to implement SVN on our secure cloud platform.=C2=A0 Is it possible to pay someone to add modern au= thentication to TortoiseSVN?</p> <p>=C2=A0Specifically we wish to use TortoiseSVN client to access VisualSVN Server via Microsoft Azure Application Proxy.=C2=A0 This requires= TSVN to be conversant in "OAuth 2.0 with OpenID Connect (OIDC)".=C2=A0 See=C2=A0<a href=3D"https://auth0.c= om/docs/authenticate/protocols/openid-connect-protocol" rel=3D"nofollow" ta= rget=3D"_blank" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den&= amp;q=3Dhttps://auth0.com/docs/authenticate/protocols/openid-connect-protoc= ol&source=3Dgmail&ust=3D1712865473204000&usg=3DAOvVaw1nQfr0PRs7= 10qGG_3bN0qP">https://auth0.com/docs/authenticate/protocols/openid-connect-= protocol</a></p> <p>You can see the error we get by using TortoiseSVN to open this test repository <a href=3D"https://visualsvn.parabilis-space.com/svn/t= est/" rel=3D"nofollow" target=3D"_blank" data-saferedirecturl=3D"https://ww= w.google.com/url?hl=3Den&q=3Dhttps://visualsvn.parabilis-space.com/svn/= test/&source=3Dgmail&ust=3D1712865473204000&usg=3DAOvVaw0hUKOdL= HzCmeBUXXqS-tYF">https://visualsvn.parabilis-space.com/svn/test/</a>=C2=A0<= br><span style=3D"font-family:Calibri,sans-serif;font-size:11pt">Error: Rep= ository moved temporarily to ...Oath2/authorize...</span></p> <p></p> <p>Thank You,<br></p> <p>--Jon<br></p></blockquote></div></div></blockquote></div> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;TortoiseSVN-dev" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:[email protected]">tor= [email protected]</a>.<br /> To view this discussion on the web visit <a href=3D"https://groups.google.c= om/d/msgid/tortoisesvn-dev/5d07c8f2-c2a8-4cfb-b8df-502b87f66ca0n%40googlegr= oups.com?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.com/= d/msgid/tortoisesvn-dev/5d07c8f2-c2a8-4cfb-b8df-502b87f66ca0n%40googlegroup= s.com</a>.<br /> ------=_Part_327_374166198.1712785176394-- ------=_Part_326_1767728085.1712785176394--