Metadata-Version: 2.5
Name: oarepo-kerberos
Version: 0.2.0
Summary: A library for Kerberos integration in OARepo.
Project-URL: Homepage, https://github.com/oarepo/oarepo-kerberos
Requires-Python: <3.15,>=3.14
Requires-Dist: flask-gssapi
Requires-Dist: oarepo<15,>=14.2.1b11.dev1
Provides-Extra: dev
Requires-Dist: ruff; extra == 'dev'
Provides-Extra: oarepo14
Requires-Dist: oarepo[rdm,tests]<15.0.0,>=14.0.0; extra == 'oarepo14'
Provides-Extra: tests
Requires-Dist: oarepo-model; extra == 'tests'
Requires-Dist: pytest-flask; extra == 'tests'
Requires-Dist: pytest-invenio; extra == 'tests'
Requires-Dist: pytest-oarepo; extra == 'tests'
Requires-Dist: pytest>=7.1.2; extra == 'tests'
Requires-Dist: requests-kerberos; extra == 'tests'
Description-Content-Type: text/markdown

# OARepo Kerberos

Library for handling Kerberos authentication in OARepo repositories.

### How to use


1. Get a keytab file from your KDC and configure your repository to use it. This involves setting the `KRB5_KTNAME` flask application configuration to the location of the keytab file.

2. Configure your repository to use its hostname in gssapi. This involves setting the `'GSSAPI_HOSTNAME'` flask application configuration to the hostname of your repository.

3. Test the Kerberos authentication by making requests to your repository and verifying that they are authenticated using Kerberos.

### Limitations

#### Multi-leg SPNEGO is not supported

Authentication must complete in a single round trip. The negotiation cannot
be resumed either — a fresh GSSAPI security context is built per request, and the continuation
token is discarded unless that context completed — so a request needing a second leg is answered
with **501 Not Implemented**.

#### A session cookie and a Negotiate token cannot be combined

Successful Kerberos authentication logs the user in, which sets a session cookie. If a client
then sends that cookie *and* `Authorization: Negotiate ...` on a later request, it is presenting
two credentials that may name different principals, so the server refuses with **400 Bad
Request** rather than silently picking one.





