How do I use Single Sign On for Wordpress and Java Spring?

Viewed 44

Let's say we have a site called example.com

Here, for example, I want to use some static content such as blog etc. and some pages in Wordpress. Wordpress build is using session-based authentication, with username and password strategy, also with third-party. (OAuth and OpenID).

I will design a custom and dynamic website section in Java Spring. And I want to use the same authentication mechanism with Wordpress.

For example, there is this path named examle.com/test. It is running from different server, which is based on Java Spring. But the session is shared with Wordpress. If there is a login from Wordpress (from example.com), it works on this server as well. Vice versa is also correct.

Login/logout should be possible from both Wordpress's pages and Java Spring's pages. Session must be shared. Wordpress already exists and the authentication mechanism is working. How can I use this in Java Spring? Or how can I do achieve this in some another way?

1 Answers

If

  • your Spring and WordPress apps are on the same top-level domain (for example https://spring.example.com and https://wordpress.example.com), and
  • your Spring app can read rows from the wp_users table in your WordPress MySQL database, and
  • your Spring app has access to the Authentication Unique Keys and Salts section of your wp-config.php file in your WordPress installation, and
  • your users always log in to WordPress before they use your Spring app ...

Then you can use the wordpress_logged_in_... cookie to authenticate your WordPress users to your Spring app. You'll have to rewrite the wp_validate_auth_cookie() in Java to do that. Explaining how to do that is far beyond the scope of a StackOverflow answer.

If any of those conditions aren't met you probably should explore some sort of federated login scheme. WordPress has several SAML plugins. Spring also supports SAML login. Again, it's too big a topic for StackOverflow.

Related