Re: Add modern authentication (OAuth 2.0 + OIDC) to TortoiseSVN

Jon Martin via TortoiseSVN-dev <[email protected]> Wed, 10 Apr 2024 14:39:36 -0700 (PDT)
Newsgroups gmane.comp.version-control.subversion.tortoisesvn.devel
Message-ID <[email protected]>
------=_Part_326_1767728085.1712785176394
Content-Type: multipart/alternative; 
	boundary="----=_Part_327_374166198.1712785176394"

------=_Part_327_374166198.1712785176394
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable



It seems instead of (OAuth 2.0 + OIDC) I should be saying (OpenID Connect),=
=20
as "OpenID Connect (OIDC) is an open authentication protocol that works on=
=20
top of the OAuth 2.0 framework."=20

In my case OpenID Connect (OIDC) is implemented by the middle man (Azure=20
Application Proxy) not the SVN server.  However I can see the need during=
=20
development to authenticate to OIDC on the SVN server.  It looks like the=
=20
SVN server side is already taken care of by this Apache OIDC (OpenID=20
Connect) add on:=20

OpenID Certified=E2=84=A2 OpenID Connect Relying Party implementation for A=
pache=20
HTTP Server 2.x
https://github.com/OpenIDC/mod_auth_openidc

Once TSVN can authenticate via any OpenID Connect. It should work with all.
--Jon
On Wednesday, March 20, 2024 at 12:28:13=E2=80=AFAM UTC-7 daniel.l...@gmail=
.com=20
wrote:

> From what I understand, OAuth2 requires both server- and clientside=20
> support. So any solution would need to involve both TortoiseSVN and the=
=20
> Subversion project (or VisualSVN). I think it is a great idea but I think=
=20
> some additional development resources would be required to make this=20
> happen. Any chance that you (or your company) can get involved in making=
=20
> this happen?
>
> Kind regards,
> Daniel
>
>
> onsdag 20 mars 2024 kl. 08:11:28 UTC+1 skrev [email protected]:
>
> We have run into a problem trying to implement SVN on our secure cloud=20
> platform.  Is it possible to pay someone to add modern authentication to=
=20
> TortoiseSVN?
>
>  Specifically we wish to use TortoiseSVN client to access VisualSVN Serve=
r=20
> via Microsoft Azure Application Proxy.  This requires TSVN to be conversa=
nt=20
> in "OAuth 2.0 with OpenID Connect (OIDC)".  See=20
> https://auth0.com/docs/authenticate/protocols/openid-connect-protocol
>
> You can see the error we get by using TortoiseSVN to open this test=20
> repository https://visualsvn.parabilis-space.com/svn/test/=20
> Error: Repository moved temporarily to ...Oath2/authorize...
>
> Thank You,
>
> --Jon
>
>

--=20
You received this message because you are subscribed to the Google Groups "=
TortoiseSVN-dev" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to [email protected].
To view this discussion on the web visit https://groups.google.com/d/msgid/=
tortoisesvn-dev/5d07c8f2-c2a8-4cfb-b8df-502b87f66ca0n%40googlegroups.com.

------=_Part_327_374166198.1712785176394
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<p>It seems instead of (OAuth 2.0 + OIDC) I should be saying
(OpenID Connect), as "OpenID Connect (OIDC) is an open authentication
protocol that works on top of the OAuth 2.0 framework."=C2=A0</p>

<p>In my case OpenID Connect (OIDC) is implemented by the middle
man (<span style=3D"font-family: Aptos, serif; font-size: 11pt;">Azure Appl=
ication Proxy)=C2=A0</span>not the SVN server.=C2=A0 However I can
see the need during development to authenticate to OIDC on the SVN server.=
=C2=A0 It looks like the SVN server side is already
taken care of by this Apache OIDC (OpenID Connect) add on:=C2=A0</p>

<p>OpenID Certified=E2=84=A2 OpenID Connect Relying Party
implementation for Apache HTTP Server 2.x<br />
<a href=3D"https://github.com/OpenIDC/mod_auth_openidc">https://github.com/=
OpenIDC/mod_auth_openidc</a></p><p>Once TSVN can authenticate via any OpenI=
D Connect. It should work with all.</p>--Jon<div class=3D"gmail_quote"><div=
 dir=3D"auto" class=3D"gmail_attr">On Wednesday, March 20, 2024 at 12:28:13=
=E2=80=AFAM UTC-7 [email protected] wrote:<br/></div><blockquote class=
=3D"gmail_quote" style=3D"margin: 0 0 0 0.8ex; border-left: 1px solid rgb(2=
04, 204, 204); padding-left: 1ex;">From what I understand, OAuth2 requires =
both server- and clientside support. So any solution would need to involve =
both TortoiseSVN and the Subversion project (or VisualSVN). I think it is a=
 great idea but I think some additional development resources would be requ=
ired to make this happen. Any chance that you (or your company) can get inv=
olved in making this happen?<div><br></div><div>Kind regards,</div><div>Dan=
iel</div><div><br><br><div><div dir=3D"auto">onsdag 20 mars 2024 kl. 08:11:=
28 UTC+1 skrev <a href data-email-masked rel=3D"nofollow">j...@parabilis-sp=
ace.com</a>:<br></div><blockquote style=3D"margin:0px 0px 0px 0.8ex;border-=
left:1px solid rgb(204,204,204);padding-left:1ex"><p>We have run into a pro=
blem trying to implement SVN on our
secure cloud platform.=C2=A0 Is it possible to pay someone to add modern au=
thentication to TortoiseSVN?</p>

<p>=C2=A0Specifically we wish to use TortoiseSVN client to access
VisualSVN Server via Microsoft Azure Application Proxy.=C2=A0 This requires=
 TSVN to be conversant in &quot;OAuth 2.0
with OpenID Connect (OIDC)&quot;.=C2=A0 See=C2=A0<a href=3D"https://auth0.c=
om/docs/authenticate/protocols/openid-connect-protocol" rel=3D"nofollow" ta=
rget=3D"_blank" data-saferedirecturl=3D"https://www.google.com/url?hl=3Den&=
amp;q=3Dhttps://auth0.com/docs/authenticate/protocols/openid-connect-protoc=
ol&amp;source=3Dgmail&amp;ust=3D1712865473204000&amp;usg=3DAOvVaw1nQfr0PRs7=
10qGG_3bN0qP">https://auth0.com/docs/authenticate/protocols/openid-connect-=
protocol</a></p>

<p>You can see the error we get by using TortoiseSVN to open
this test repository <a href=3D"https://visualsvn.parabilis-space.com/svn/t=
est/" rel=3D"nofollow" target=3D"_blank" data-saferedirecturl=3D"https://ww=
w.google.com/url?hl=3Den&amp;q=3Dhttps://visualsvn.parabilis-space.com/svn/=
test/&amp;source=3Dgmail&amp;ust=3D1712865473204000&amp;usg=3DAOvVaw0hUKOdL=
HzCmeBUXXqS-tYF">https://visualsvn.parabilis-space.com/svn/test/</a>=C2=A0<=
br><span style=3D"font-family:Calibri,sans-serif;font-size:11pt">Error: Rep=
ository
moved temporarily to ...Oath2/authorize...</span></p>

<p></p>

<p>Thank You,<br></p>

<p>--Jon<br></p></blockquote></div></div></blockquote></div>

<p></p>

-- <br />
You received this message because you are subscribed to the Google Groups &=
quot;TortoiseSVN-dev&quot; group.<br />
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to <a href=3D"mailto:[email protected]">tor=
[email protected]</a>.<br />
To view this discussion on the web visit <a href=3D"https://groups.google.c=
om/d/msgid/tortoisesvn-dev/5d07c8f2-c2a8-4cfb-b8df-502b87f66ca0n%40googlegr=
oups.com?utm_medium=3Demail&utm_source=3Dfooter">https://groups.google.com/=
d/msgid/tortoisesvn-dev/5d07c8f2-c2a8-4cfb-b8df-502b87f66ca0n%40googlegroup=
s.com</a>.<br />

------=_Part_327_374166198.1712785176394--

------=_Part_326_1767728085.1712785176394--