Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Wikipedia: Mediawiki

Authentication question

 

 

Wikipedia mediawiki RSS feed   Index | Next | Previous | View Threaded


Nina.McHale at ucdenver

May 20, 2009, 10:53 AM

Post #1 of 2 (640 views)
Permalink
Authentication question

Hi, all!

Back with an authentication question. I set up Tom Mollerus' single sign on method yesterday:

http://www.mollerus.net/tom/blog/2008/09/single_signon_to_mediawiki_113_using_active_direct.html

...and before that I'd set the following in the LocalSettings.php settings file:

$wgGroupPermissions['*']['edit'] = false; $wgGroupPermissions['*']['read'] = false;

Per staff request, we also have an .htaccess file that restricts access to campus IPs (apparently, we're the freaking CIA). I know some of this may be redundant now, but I'm still trying to sort out the best way to set up authentication.

However, the single sign on seems to have negated those $wgGroupPermissions settings in LocalSettings.php. As in, I can log in with my network password, then log out, but still see and edit pages. Any ideas?

So basically, I'm looking for the best method to provide single sign on that requires network password to view and edit. (I think I can lose the IP settings in the .htaccess file now that we're hooked in to LDAP, as long as I don't let anyone create new accounts.)

Yours in authentication ineptitude, :)

Nina
_______________________________________________
MediaWiki-l mailing list
MediaWiki-l [at] lists
https://lists.wikimedia.org/mailman/listinfo/mediawiki-l


Ryan.Lane at ocean

May 20, 2009, 11:45 AM

Post #2 of 2 (570 views)
Permalink
Re: Authentication question [In reply to]

> However, the single sign on seems to have negated those
> $wgGroupPermissions settings in LocalSettings.php. As in, I
> can log in with my network password, then log out, but still
> see and edit pages. Any ideas?
>

The method posted on that site uses an auto-authentication plugin. As long
as you are authenticated to Apache, you'll be logged into the wiki - no
logging out until you close the browser.

I recommend using the LDAP Authentication plugin. It'll do what you are
looking for.

http://www.mediawiki.org/wiki/Extension:LDAP_Authentication

http://www.mediawiki.org/wiki/Extension:LDAP_Authentication/AD_Configuration
_Examples

http://ryandlane.com/wprdl/2009/03/23/using-the-ldap-authentication-plugin-f
or-mediawiki-the-basics-part-1/

V/r,

Ryan Lane

Wikipedia mediawiki RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.