Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

O365 IMAP Auth end of life 2022-10-01

Đang mở
#205 5 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
25/100
Loại issue
Tính năng
Độ rõ ràng
Cần làm rõ
Mức độ hoạt động
Đình trệ
Lĩnh vực
authentication

Hướng nghiên cứu

Start by tracing the IMAP authentication path in user_external and review the linked Microsoft Exchange guidance on basic-authentication deprecation. Define a supported replacement for O365 authentication and migration expectations; done means affected users can authenticate after basic authentication is disabled without relying on manual SQL changes.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

0. Needs triage bug

IMAP Authentication in user_external uses basic authentication.

As of October 1, 2022 Microsoft will begin disabling basic authentication in Exchange365.

(There is information in the Microsoft link above describing how you can opt out of having Microsoft disable IMAP basic authentication for your tenant.)

Normally it is not possible to set a password in /settings/users for accounts authenticating through user_external. However, if you manually create an entry in oc_users with a uid that matches an entry in oc_users_external, it becomes possible to set a local nextcloud password.

My plan at the moment is to move my existing users from IMAP auth to internal Nextcloud Auth, then require twofactor_email for the migrated users.

The code snippet below works on my system to create entries in oc_users with matching uid values from oc_users_external.

My database settings from config.php:

  'dbtype' => 'pgsql',
  'dbname' => 'nextcloud',
  'dbtableprefix' => 'oc_',
  1. Connect to the sql database

    sudo -u postgres psql -t -d nextcloud
    
  2. Manually create an entry in 'oc_users' using the same value for uid and displayname used in oc_users_external:

    insert into oc_users(uid,displayname,uid_lower)
    select uid, displayname,lower(uid) from  oc_users_external where uid like '<uid-from-oc_users_external>';
    
  3. Once there is an entry in "oc_users" with a uid that matches an entry in oc_users_external, the user's password can be set in /settings/users

  4. The User now sees the same files & shares if logging in using the original IMAP password or the new locally set password

  5. Requring two factor auth using twofactor_email ensures that security remains tied to the user's email

There is some fine-tuning that could be applied to this procedure:

  • All accounts could be migrated (remove the "where..." clause)
  • All accounts could have a pre-defined password applied
    • Create a bogus user
    • Set the password for the bogus user
    • Get the encrypted password info from oc_users for the bogus user
    • Add the encrypted password to the sql 'insert' command

This code snippet sets the selected user's local password to "badPassword" -

insert into oc_users(uid,displayname,uid_lower,password)
select 
  uid, 
  displayname,
  lower(uid),
  '3|$argon2id$v=19$m=65536,t=4,p=1$aWZKcTZsV08yczguSHlNWA$3Tdbsc4hVuiM4o6zLtsR1xxhL9T27HzE2cM1umYl7nI' 
from  oc_users_external where uid like '<uid-from-oc_users_external>';
Ngôn ngữ chính
JavaScript
Star
121
Fork
73
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của nextcloud/user_external

Tất cả issue của nextcloud/user_external

Issue tương tự

Thêm issue về JavaScript

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.