Merge pull request #5234 from backstage/timbonicus/onelogin-doc

Add OneLogin auth documentation
This commit is contained in:
Tim
2021-04-07 08:13:41 -06:00
committed by GitHub
3 changed files with 57 additions and 2 deletions
+1 -1
View File
@@ -22,7 +22,7 @@ Backstage comes with many common authentication providers in the core library:
- [GitLab](gitlab/provider.md)
- [Google](google/provider.md)
- [Okta](okta/provider.md)
- OneLogin
- [OneLogin](onelogin/provider.md)
These built-in providers handle the authentication flow for a particular service
including required scopes, callbacks, etc. These providers are each added to a
+54
View File
@@ -0,0 +1,54 @@
---
id: provider
title: OneLogin Authentication Provider
sidebar_label: OneLogin
description: Adding OneLogin OIDC as an authentication provider in Backstage
---
The Backstage `core-api` package comes with a OneLogin authentication provider
that can authenticate users using OpenID Connect.
## Create an Application on OneLogin
To support OneLogin authentication, you must create an Application:
1. From the OneLogin Admin portal, choose Applications
2. Click `Add App` and select `OpenID Connect`
- Display Name: Backstage (or your custom app name)
3. Click Save
4. Go to the Configuration tab for the Application and set:
- `Login Url`: `http://localhost:3000`
- `Redirect URIs`: `http://localhost:7000/api/auth/onelogin/handler/frame`
5. Click Save
6. Go to the SSO tab for the Application and set:
- `Token Endpoint` > `Authentication Method`: `POST`
7. Click Save
## Configuration
The provider configuration can then be added to your `app-config.yaml` under the
root `auth` configuration:
```yaml
auth:
environment: development
providers:
onelogin:
development:
clientId: ${AUTH_ONELOGIN_CLIENT_ID}
clientSecret: ${AUTH_ONELOGIN_CLIENT_SECRET}
issuer: https://<company>.onelogin.com/oidc/2
```
The OneLogin provider is a structure with three configuration keys; **these are
found on the SSO tab** for the OneLogin Application:
- `clientId`: The client ID
- `clientSecret`: The client secret
- `issuer`: The issuer URL
## Adding the provider to the Backstage frontend
To add the provider to the frontend, add the `oneloginAuthApi` reference and
`SignInPage` component as shown in
[Adding the provider to the sign-in page](../index.md#adding-the-provider-to-the-sign-in-page).