Hi

Here is my use case :
a) 2 domains (with different TLD) set up using Domain access module and enabled as SSO clients:
* domain1.com : can be accessed by "user1" and editor
* domain2.com : can be accessed by "user2" and editor
b) controller.com is the SSO controller.

SSO works fine. Each user can access to its respective domain and editor can log into the 2 domains. The problem is that user1 can log in domain2.com and user2 can log in domain1.com (though they can only view nodes in the domain they don't belong to). However, this is very confusing for users.

Is there a way to restrict the login to the only domain that user shall access (tables sharing ? several $cookie_domain per settings.php? )

Thanks

Laurent

Comments

meba’s picture

Status: Active » Postponed (maintainer needs more info)

Well. Then why you are using SSO? The whole point of SSO is sharing users and logins across sites?

agence web coheractio’s picture

Not exacty. I'd like to share logins but only for the sites that the users can access as per their domain access set up e.g. a user may be authorised to log into only 3 sites out of the 5 sites managed with domain access.

Is this feasible ?

Laurent

meba’s picture

I see. What is supposed to happen when user1 logs at domain2 (where he doesn't have access) - it should report login failed?

agence web coheractio’s picture

Exact.

azinck’s picture

I, too, am interested in this. But mightn't this be a Domain Access issue rather than an SSO issue? This problem exists with or without the SSO module.

meba’s picture

Status: Postponed (maintainer needs more info) » Closed (won't fix)

I think so. Please open a ticket at DA