magento2 icon indicating copy to clipboard operation
magento2 copied to clipboard

OAuth 2.0 and OpenID support

Open balabany opened this issue 3 years ago • 3 comments

One of the biggest problem for integrations is that Magento 2 supports already depreciated and insecure OAuth 1.0 instead of 2.0. On top of that, OpenID would helped third party apps to be securely integrated to Magento 2 increasing security and transparancy.

Its also adviseble to add in support Keycloak, Simplesamlphp (It has OAuth 2.0 and OpenID plugins) and also Gluu server as open source identity servers.

Thanks in advance.

Description (*)

OAuth 2.0 and OpenID support

Benefits

Integrations will become secure and Magento would be Identity Provider and also Identity Service

balabany avatar Dec 09 '21 09:12 balabany

Hi @balabany. Thank you for your report. To speed up processing of this issue, make sure that you provided the following information:

  • Summary of the issue
  • Information on your environment
  • Steps to reproduce
  • Expected and actual results

Make sure that the issue is reproducible on the vanilla Magento instance following Steps to reproduce. To deploy vanilla Magento instance on our environment, Add a comment to the issue:

@magento give me 2.4-develop instance - upcoming 2.4.x release

For more details, review the Magento Contributor Assistant documentation.

Add a comment to assign the issue: @magento I am working on this

To learn more about issue processing workflow, refer to the Code Contributions.


:warning: According to the Magento Contribution requirements, all issues must go through the Community Contributions Triage process. Community Contributions Triage is a public meeting.

:clock10: You can find the schedule on the Magento Community Calendar page.

:telephone_receiver: The triage of issues happens in the queue order. If you want to speed up the delivery of your contribution, join the Community Contributions Triage session to discuss the appropriate ticket.

:movie_camera: You can find the recording of the previous Community Contributions Triage on the Magento Youtube Channel

:pencil2: Feel free to post questions/proposals/feedback related to the Community Contributions Triage process to the corresponding Slack Channel

m2-assistant[bot] avatar Dec 09 '21 09:12 m2-assistant[bot]

Hello, with the update to Magento 2.4.4 it is by default now forbidden to use the integration access token as bearer token. The main reason is the security aspect. But now we are forced to use the oAuth 1.0a implementation of Magento, which is deprecated.

When can we expect the oAuth 2.0 implementation in Magento 2?

doldersma avatar Jun 20 '22 08:06 doldersma

Hello @doldersma @balabany @aredridel @jaywilliams @alepane21,

Hope you are well!

If you are still facing the same issue, then I have a solution for you of UPS OAuth2 Magento 2

For seamless UPS integration with Magento 2.4.3, 2.4.4, and beyond, consider using this comprehensive extension that supports UPS OAuth 2.0. It's compatible with all Magento 2 versions and ensures secure shipping integration.

Extension URL: https://expoundcoderz.com/ups-oauth2-magento-2-extension-secure-shipping-integration.html

This should resolve your UPS connectivity issue swiftly, allowing your website to process orders without interruption.

Please let me know If you have any questions or you can directly contact me at this: [email protected]

Thanks

ninja-jatin avatar Feb 27 '24 05:02 ninja-jatin

@ninja-jatin please do not ping me, I am not part of this project.

aredridel avatar Mar 05 '24 21:03 aredridel