How to implement OpenID Connect with multiple providers in Django?

Viewed 162

I'm trying to implement multiple SSO (OpenID Connect) logins in my application, besides the regular one.

The current provider requests are Azure and Okta, but there will be more. For every bigger customer using my application, I want to be able to enable them a custom SSO login that they can setup in the admin panel.

All the libraries I've tried using for this are either using settings.py and local django authentication, or they are deprecated.

The flow is like this:

User chooses their company and SSO login button -> Gets redirected to login -> I send the client id, secret etc. (which they entered in the admin panel when registering an sso connection) -> I get a token in return with the users name and email -> with this info (email) I find the already existing user in my local database and log him in

3 Answers

Your own applications usually prefers to trust only one provider and when you want to involve multiple providers, the best way is to add your own OIDC provider locally, that your applications and API's trust. And then your OIDC provider can trust various other providers. Like how this picture below shows:

enter image description here

  1. User chooses their company and SSO login button

OK, you can just simply put the buttons on your website.

  1. Gets redirected to login

You can imlpement /redirect endpoint and make sure do something to ready for getting user information from OAuth2 provider.

  1. I send the client id, secret etc. (which they entered in the admin panel when registering an sso connection)

This is also continue of step 2. but I don't know how to connect with Django admin panel. sorry.

  1. I get a token in return with the users name and email

Use OAuth2 provider's user info API. So you can get user's information whatever you want as much as they give.

  1. with this info (email) I find the already existing user in my local database and log him in

Just write a function with database. it is not hard.

I think that's enough to implement this. but that they can setup in the admin panel. I can't sure you can customize "already made" Django admin panel. That may be hard to do.

Related