Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
31 commits
Select commit Hold shift + click to select a range
cd482e9
refactor: use new \core\context namespaced classes
patmr7 Apr 27, 2026
35f2144
refactor: use \core\url instead of moodle_url
patmr7 Apr 27, 2026
4be3b70
Merge remote-tracking branch 'origin/wip-123995-m501' into MOODLE_501…
weilai-irl Apr 27, 2026
a13728f
Re-organise configuration pages for auth_oidc and local_o365 to make …
weilai-irl Apr 27, 2026
07b7bac
add hide_if helper for conditional settings visibility
theqoocjil Mar 24, 2026
508f1ed
fix coding standard errors
weilai-irl Apr 27, 2026
1f39352
Post-exit event adjustments
theqoocjil Mar 23, 2026
6c0163c
Update logout redirect URL logic for Microsoft IdP, fix coding standa…
weilai-irl Apr 27, 2026
9b30743
Only block login redirects when user actually logged out. Fixes #3102
FMCorz Mar 24, 2026
3e79ed5
improve logout redirect handling
weilai-irl Apr 28, 2026
60ddea7
Update README, SECURITY and CODE_OF_CONDUCT files
weilai-irl Apr 30, 2026
937e32c
Force Moodle guest user logout before SSO starts
weilai-irl Apr 30, 2026
9e6b6be
Fix a bug in the logic to determine if username has changed
weilai-irl Apr 30, 2026
26bd093
Support field mapping from custom token claim
weilai-irl May 5, 2026
32bfba5
Fix occasional unit test failure in boundary conditions
weilai-irl May 5, 2026
d37cfbe
Update auth code validation according to RFC 6749
weilai-irl May 5, 2026
d80c453
Add unique constraint to the combination of "oidcuniqid" and "resourc…
weilai-irl May 5, 2026
a7068cb
Save wantsurl in OIDC state data
weilai-irl May 6, 2026
d40a838
Merge branch 'wip-127711-m501' into MOODLE_501_STABLE
weilai-irl May 8, 2026
d7d0c0b
Merge branch 'wip-129292-m501' into MOODLE_501_STABLE
weilai-irl May 8, 2026
bab6db3
Merge wip-129692-m501
weilai-irl May 11, 2026
5539d36
Merge wip-129711-m501
weilai-irl May 11, 2026
2b132c5
Merge wip-129719-m501
weilai-irl May 11, 2026
7a705f8
Merge wip-129941-m501
weilai-irl May 13, 2026
ed5ca66
Merge wip-129951-m501
weilai-irl May 13, 2026
e50eb63
Merge wip-129956-m501
weilai-irl May 13, 2026
458e0f6
Remove referencing to local_o365 language strings from auth_oidc when…
weilai-irl May 13, 2026
7087964
Merge wip-129960-m501
weilai-irl May 20, 2026
8b2fc05
Merge wip-130014-m501
weilai-irl May 20, 2026
f21f33d
Merge branch 'wip-130378-m501' into MOODLE_501_STABLE
weilai-irl May 20, 2026
5762563
Update plugin version for 5.1.2 release
weilai-irl May 20, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions CODE_OF_CONDUCT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# Microsoft Open Source Code of Conduct

This project has adopted the [Microsoft Open Source Code of Conduct](https://opensource.microsoft.com/codeofconduct/).

Resources:

- [Microsoft Open Source Code of Conduct](https://opensource.microsoft.com/codeofconduct/)
- [Microsoft Code of Conduct FAQ](https://opensource.microsoft.com/codeofconduct/faq/)
- Contact [opencode@microsoft.com](mailto:opencode@microsoft.com) with questions or concerns
- Employees can reach out at [aka.ms/opensource/moderation-support](https://aka.ms/opensource/moderation-support)
10 changes: 6 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,7 @@
# Microsoft 365 and Microsoft Entra ID Plugins for Moodle
# Moodle Plugins for Microsoft Services
*including* **Microsoft 365** *and other Microsoft services*

## OpenID Connect Authentication Plugin.
## OpenID Connect Authentication Plugin

The OpenID Connect plugin provides single-sign-on functionality using configurable identity providers.

Expand All @@ -12,16 +13,17 @@ This repository is updated with stable releases. To follow active development, s

1. Unpack the plugin into /auth/oidc within your Moodle install.
2. From the Moodle Administration block, expand Site Administration and click "Notifications".
3. Follow the on-screen instuctions to install the plugin.
3. Follow the on-screen instructions to install the plugin.
4. To configure the plugin, from the Moodle Administration block, go to Site Administration > Plugins > Authentication > Manage Authentication.
5. Click the icon to enable the plugin, then visit the settings page to configure the plugin. Follow the directions below each setting.

For more documentation, visit https://docs.moodle.org/34/en/Office365
For more documentation, visit https://docs.moodle.org/501/en/Microsoft_365

For more information including support and instructions on how to contribute, please see: https://github.com/Microsoft/o365-moodle/blob/master/README.md

## Issues and Contributing
Please post issues for this plugin to: https://github.com/Microsoft/o365-moodle/issues/

Pull requests for this plugin should be submitted against our main repository: https://github.com/Microsoft/o365-moodle

## Copyright
Expand Down
41 changes: 7 additions & 34 deletions SECURITY.md
Original file line number Diff line number Diff line change
@@ -1,41 +1,14 @@
<!-- BEGIN MICROSOFT SECURITY.MD V0.0.7 BLOCK -->
<!-- BEGIN MICROSOFT SECURITY.MD V1.0.0 BLOCK -->

## Security

Microsoft takes the security of our software products and services seriously, which includes all source code repositories managed through our GitHub organizations, which include [Microsoft](https://github.com/Microsoft), [Azure](https://github.com/Azure), [DotNet](https://github.com/dotnet), [AspNet](https://github.com/aspnet), [Xamarin](https://github.com/xamarin), and [our GitHub organizations](https://opensource.microsoft.com/).

If you believe you have found a security vulnerability in any Microsoft-owned repository that meets [Microsoft's definition of a security vulnerability](https://aka.ms/opensource/security/definition), please report it to us as described below.

## Reporting Security Issues
Microsoft takes the security of our software products and services seriously, which
includes all source code repositories in our GitHub organizations.

**Please do not report security vulnerabilities through public GitHub issues.**

Instead, please report them to the Microsoft Security Response Center (MSRC) at [https://msrc.microsoft.com/create-report](https://aka.ms/opensource/security/create-report).

If you prefer to submit without logging in, send email to [secure@microsoft.com](mailto:secure@microsoft.com). If possible, encrypt your message with our PGP key; please download it from the [Microsoft Security Response Center PGP Key page](https://aka.ms/opensource/security/pgpkey).

You should receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received your original message. Additional information can be found at [microsoft.com/msrc](https://aka.ms/opensource/security/msrc).

Please include the requested information listed below (as much as you can provide) to help us better understand the nature and scope of the possible issue:

* Type of issue (e.g. buffer overflow, SQL injection, cross-site scripting, etc.)
* Full paths of source file(s) related to the manifestation of the issue
* The location of the affected source code (tag/branch/commit or direct URL)
* Any special configuration required to reproduce the issue
* Step-by-step instructions to reproduce the issue
* Proof-of-concept or exploit code (if possible)
* Impact of the issue, including how an attacker might exploit the issue

This information will help us triage your report more quickly.

If you are reporting for a bug bounty, more complete reports can contribute to a higher bounty award. Please visit our [Microsoft Bug Bounty Program](https://aka.ms/opensource/security/bounty) page for more details about our active programs.

## Preferred Languages

We prefer all communications to be in English.

## Policy

Microsoft follows the principle of [Coordinated Vulnerability Disclosure](https://aka.ms/opensource/security/cvd).
For security reporting information, locations, contact information, and policies,
please review the latest guidance for Microsoft repositories at
[https://aka.ms/SECURITY.md](https://aka.ms/SECURITY.md).

<!-- END MICROSOFT SECURITY.MD BLOCK -->
<!-- END MICROSOFT SECURITY.MD BLOCK -->
116 changes: 86 additions & 30 deletions auth.php
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,8 @@
* @copyright (C) 2014 onwards Microsoft, Inc. (http://microsoft.com/)
*/

use core\url;

defined('MOODLE_INTERNAL') || die();

require_once($CFG->libdir . '/authlib.php');
Expand Down Expand Up @@ -104,6 +106,33 @@ public function set_httpclient(\auth_oidc\httpclientinterface $httpclient) {
return $this->loginflow->set_httpclient($httpclient);
}

/**
* Hook for overriding behaviour of logout page.
*/
public function logoutpage_hook() {
global $redirect;

// No need for custom logic if we don't force the redirect on login.
if (!isset($this->config->forceredirect) || !$this->config->forceredirect) {
return;
}

// When we log out and are redirecting to the login page, add the noredirect to prevent our own redirect.
if (empty($redirect)) {
return;
}

$redirecturl = is_string($redirect) ? new url($redirect) : $redirect;
if (!($redirecturl instanceof url)) {
return;
}

if ($redirecturl->compare(new url('/login/index.php'), URL_MATCH_BASE)) {
$redirecturl->param('noredirect', 1);
$redirect = $redirecturl->out(false);
}
}

/**
* Hook for overriding behaviour of login page.
* This method is called from login/index.php page for all enabled auth plugins.
Expand All @@ -123,7 +152,7 @@ public function loginpage_hook() {
* @return bool If this returns true then redirect
*/
public function should_login_redirect() {
global $CFG, $SESSION;
global $SESSION;

$oidc = optional_param('oidc', null, PARAM_BOOL);
// Also support noredirect param - used by other auth plugins.
Expand All @@ -148,17 +177,6 @@ public function should_login_redirect() {
return false;
}

// If the user is redirectred to the login page immediately after logging out, don't redirect.
$silentloginmodesetting = get_config('auth_oidc', 'silentloginmode');
$forceredirectsetting = get_config('auth_oidc', 'forceredirect');
$forceloginsetting = get_config('core', 'forcelogin');
if (
$silentloginmodesetting && $forceredirectsetting && $forceloginsetting && isset($_SERVER['HTTP_REFERER']) &&
strpos($_SERVER['HTTP_REFERER'], $CFG->wwwroot) !== false
) {
return false;
}

// Never redirect if requested so.
if ($oidc === 0) {
$SESSION->oidc = $oidc;
Expand Down Expand Up @@ -196,16 +214,16 @@ public function handleredirect() {
* @param bool $justremovetokens If true, just remove the stored OIDC tokens for the user, otherwise revert login methods.
* @param bool $donotremovetokens If true, do not remove tokens when disconnecting. This migrates from a login account to a
* "linked" account.
* @param moodle_url|null $redirect Where to redirect if successful.
* @param moodle_url|null $selfurl The page this is accessed from. Used for some redirects.
* @param url|null $redirect Where to redirect if successful.
* @param url|null $selfurl The page this is accessed from. Used for some redirects.
* @param null $userid
* @return mixed
*/
public function disconnect(
$justremovetokens = false,
$donotremovetokens = false,
?\moodle_url $redirect = null,
?\moodle_url $selfurl = null,
?url $redirect = null,
?url $selfurl = null,
$userid = null
) {
return $this->loginflow->disconnect($justremovetokens, $donotremovetokens, $redirect, $selfurl, $userid);
Expand Down Expand Up @@ -273,7 +291,7 @@ public function user_authenticated_hook(&$user, $username, $password) {
if (!empty($tokenrec)) {
// If the token record username is out of sync (ie username changes), update it.
if ($tokenrec->username != $user->username) {
$updatedtokenrec = new \stdClass();
$updatedtokenrec = new stdClass();
$updatedtokenrec->id = $tokenrec->id;
$updatedtokenrec->username = $user->username;
$DB->update_record('auth_oidc_token', $updatedtokenrec);
Expand All @@ -285,7 +303,7 @@ public function user_authenticated_hook(&$user, $username, $password) {
$tokenrec = $DB->get_record('auth_oidc_token', ['username' => $username]);
if (!empty($tokenrec)) {
$tokenrec->userid = $user->id;
$updatedtokenrec = new \stdClass();
$updatedtokenrec = new stdClass();
$updatedtokenrec->id = $tokenrec->id;
$updatedtokenrec->userid = $user->id;
$DB->update_record('auth_oidc_token', $updatedtokenrec);
Expand All @@ -303,6 +321,46 @@ public function user_authenticated_hook(&$user, $username, $password) {
}
}

/**
* Build logout URL with appropriate IdP-specific parameters.
*
* @param string $logouturl Base logout URL from config.
* @param string $idptype IdP type (from constants).
* @param stdClass $user User object.
* @return string|null Logout URL, or null if logout should be skipped.
*/
private function build_logout_url(string $logouturl, string $idptype, stdClass $user): ?string {
global $CFG, $DB;

$params = [
'post_logout_redirect_uri' => $CFG->wwwroot,
];

switch ($idptype) {
case AUTH_OIDC_IDP_TYPE_MICROSOFT_ENTRA_ID:
case AUTH_OIDC_IDP_TYPE_MICROSOFT_IDENTITY_PLATFORM:
if (!$logouturl) {
$logouturl = 'https://login.microsoftonline.com/organizations/oauth2/logout';
}
$url = new url($logouturl, $params);
return $url->out(false);

case AUTH_OIDC_IDP_TYPE_OTHER:
if (!$logouturl) {
return null;
}
$token = $DB->get_record('auth_oidc_token', ['userid' => $user->id]);
if ($token) {
$params['id_token_hint'] = $token->idtoken;
}
$url = new url($logouturl, $params);
return $url->out(false);

default:
return null;
}
}

/**
* Log out user from Microsoft 365 if single sign off integration is enabled.
*
Expand All @@ -326,21 +384,19 @@ public function postlogout_hook($user) {
}
}

// Do not redirect to logout endpoint when using loginas feature.
if (!empty($user->loginascontext)) {
$redirect = false;
}

if ($redirect) {
$logouturl = get_config('auth_oidc', 'logouturi');
if (!$logouturl) {
$logouturl = 'https://login.microsoftonline.com/organizations/oauth2/logout?post_logout_redirect_uri=' .
urlencode($CFG->wwwroot);
} else {
if (
preg_match("/^https:\/\/login.microsoftonline.com\//", $logouturl) &&
preg_match("/\/oauth2\/logout$/", $logouturl)
) {
$logouturl .= '?post_logout_redirect_uri=' . urlencode($CFG->wwwroot);
}
}
$idptype = get_config('auth_oidc', 'idptype');

redirect($logouturl);
$redirecturl = $this->build_logout_url($logouturl, $idptype, $user);
if ($redirecturl) {
redirect($redirecturl);
}
}
}

Expand Down
115 changes: 0 additions & 115 deletions binding_username_claim.php

This file was deleted.

Loading
Loading