Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

O365 IMAP Auth end of life 2022-10-01

未关闭
#205 5 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
5/5
预计耗时
一周以上
新手友好度
25/100
Issue 类型
功能
描述清晰度
需要澄清
活跃度
停滞

调研方向

Start by tracing the IMAP authentication path in user_external and review the linked Microsoft Exchange guidance on basic-authentication deprecation. Define a supported replacement for O365 authentication and migration expectations; done means affected users can authenticate after basic authentication is disabled without relying on manual SQL changes.

由索引模型根据 Issue 内容生成。

描述

0. Needs triage bug

IMAP Authentication in user_external uses basic authentication.

As of October 1, 2022 Microsoft will begin disabling basic authentication in Exchange365.

(There is information in the Microsoft link above describing how you can opt out of having Microsoft disable IMAP basic authentication for your tenant.)

Normally it is not possible to set a password in /settings/users for accounts authenticating through user_external. However, if you manually create an entry in oc_users with a uid that matches an entry in oc_users_external, it becomes possible to set a local nextcloud password.

My plan at the moment is to move my existing users from IMAP auth to internal Nextcloud Auth, then require twofactor_email for the migrated users.

The code snippet below works on my system to create entries in oc_users with matching uid values from oc_users_external.

My database settings from config.php:

  'dbtype' => 'pgsql',
  'dbname' => 'nextcloud',
  'dbtableprefix' => 'oc_',
  1. Connect to the sql database

    sudo -u postgres psql -t -d nextcloud
    
  2. Manually create an entry in 'oc_users' using the same value for uid and displayname used in oc_users_external:

    insert into oc_users(uid,displayname,uid_lower)
    select uid, displayname,lower(uid) from  oc_users_external where uid like '<uid-from-oc_users_external>';
    
  3. Once there is an entry in "oc_users" with a uid that matches an entry in oc_users_external, the user's password can be set in /settings/users

  4. The User now sees the same files & shares if logging in using the original IMAP password or the new locally set password

  5. Requring two factor auth using twofactor_email ensures that security remains tied to the user's email

There is some fine-tuning that could be applied to this procedure:

  • All accounts could be migrated (remove the "where..." clause)
  • All accounts could have a pre-defined password applied
    • Create a bogus user
    • Set the password for the bogus user
    • Get the encrypted password info from oc_users for the bogus user
    • Add the encrypted password to the sql 'insert' command

This code snippet sets the selected user's local password to "badPassword" -

insert into oc_users(uid,displayname,uid_lower,password)
select 
  uid, 
  displayname,
  lower(uid),
  '3|$argon2id$v=19$m=65536,t=4,p=1$aWZKcTZsV08yczguSHlNWA$3Tdbsc4hVuiM4o6zLtsR1xxhL9T27HzE2cM1umYl7nI' 
from  oc_users_external where uid like '<uid-from-oc_users_external>';
主要语言
JavaScript
星标
121
派生
73
PR 合并指标
30 天内没有已合并 PR

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

nextcloud/user_external 的其他 Issue

查看 nextcloud/user_external 的全部 Issue

相似的 Issue

更多 JavaScript Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。