Fix for OIDC XML validation error despite valid configuration & updated OIDC backend example file.

* Since Galaxy 23.1 using the api_url configuration parameter in the "oidc_backend_config.xml" file for authenticating with Azure will return an error when a user tries to log in. This bug has been documented before and can be seen here: https://github.com/galaxyproject/galaxy/issues/16373
* This problem can be solved by replacing the "api_url" parameter with the "tenant_id" parameter. However, this change of parameter name and expected value has not been documented in either the galaxy docs or in the oidc_backends_config.xml.sample example file since changes to the OIDC code have been made. This pull request attempts to solve that by updating the example file.
* In addition, since release_24.0, an XML validation is performed on the oidc_backends_config.xml file which causes the Galaxy process to return an error and exit on startup because it fails to acknowledge "tenant_id" as a legitimate parameter in the XML file. Even though this parameter is required since the OIDC changes in Galaxy 23.1. The changes to the oidc_backends_config.xsd file in this commit can fix that problem.
This commit is contained in:
Edwin
2024-05-09 08:58:42 +02:00
committed by mvdbeek
parent b9808b3e8e
commit f7b1f5e99e
2 changed files with 11 additions and 3 deletions
@@ -114,6 +114,13 @@
</xs:documentation>
</xs:annotation>
</xs:element>
<xs:element name="tenant_id" minOccurs="0" type="xs:string">
<xs:annotation>
<xs:documentation>
Tenant ID for the IdP.
</xs:documentation>
</xs:annotation>
</xs:element>
<xs:element name="pkce_support" minOccurs="0" type="xs:boolean">
<xs:annotation>
<xs:documentation>
@@ -192,12 +192,13 @@ Please mind `http` and `https`.
<client_id> ... </client_id>
<client_secret> ... </client_secret>
<redirect_uri>http://localhost:8080/authnz/azure/callback</redirect_uri>
<!-- Azure client_id, client_secret, and api_url can be obtained by folowing the instructions at
<!-- Azure client_id, client_secret, and tenant_id can be obtained by folowing the instructions at
https://docs.microsoft.com/en-us/azure/active-directory/develop/quickstart-register-app
The api_url will typiclly be https://login.microsoftonline.com/{tenant_id}/oauth2/v2.0/authorize
The required API URL will be automatically constructed from the provided tenant_id. In previous Galaxy versions
the entire "api_url" had to be provided including the tenant ID, this is no longer a valid configuration option.
-->
<api_url> ... </api_url>
<tenant_id> ... </tenant_id>
</provider>
<!-- Documentation: https://docs.egi.eu/providers/check-in/sp -->