配置 crafter-delivery 配置文件

Configuring crafter-delivery profile

我们需要我们的活动目录来管理站点的身份验证,有没有办法像我们在工作室中那样配置 crafter-delivery profile/security?

Users added to the internal database after the user’s first successful login through external authentication are marked as **Externally Managed**.

没有引擎配置-override.yaml所以我不知道该怎么做。

文档对此有所说明,但未在任何地方进行解释。

Crafter Profile is built on MongoDB for extensibility and extreme scalability and includes a multi-tenant profile attribute store, an admin console for user profile management, chained authentication with any existing authentication services including Active Directory

https://docs.craftercms.org/en/3.1/developers/projects/profile/index.html

Crafter Engine 使用 Crafter Security Provider 库,可以对其进行扩展以支持 LDAP/AD。

另一个可能 easier/better 选项是只使用 SAML2,这样用户不仅会针对 AD 进行身份验证,而且还会获得 SSO。

这是指南:https://docs.craftercms.org/en/3.0/site-administrators/engine/engine-site-security-guide.html#add-single-sign-on