Download the PHP package dmlab/module-admin-sso without Composer

On this page you can find all versions of the php package dmlab/module-admin-sso. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package module-admin-sso

DmLab_AdminSso

Provider-agnostic single sign-on for the Magento 2 admin panel (OIDC).

License Magento PHP Version

The admin-login capability core: it logs staff into the Magento admin backend over OIDC, but never references a concrete IdP. Install a provider plugin (admin-sso-okta, admin-sso-azure, …) that supplies the IdP; the plugin pulls this core, which in turn pulls the shared OIDC engine sso-core.

Features

Installation

Normally installed via a provider plugin (e.g. admin-sso-okta), which pulls this core and sso-core:

Direct install of the core only:

Register the callback URL in your IdP: https://<admin-host>/<admin-path>/adminsso/sso/callback, where <admin-path> is the backend frontName (default admin). It must exactly match the admin URL used at runtime.

Configuration

Admin → Stores → Configuration → DMLab → Admin SSO → General (config path dmlab_admin_sso/general/*).

Field Path Notes
Enable Admin SSO enabled Master switch; off by default.
Identity Provider active_provider Dropdown populated by installed provider plugins.
Client ID client_id OIDC client id from the IdP.
Client Secret client_secret Stored encrypted.
Enforce SSO enforce_sso Disables the native login form. See below.
Allow Break-Glass Login break_glass Guarded local-admin path under enforce. On by default.
Group to Role Map group_role_map IdP group → ACL role rules. See below.
Default Role default_role Fallback role when no group matches; empty = deny.

A "Sign in with SSO" button appears on the admin login page when the module is enabled and a provider is selected, using the active preset's branding.

Group → role mapping

group_role_map takes one rule per line as idp_group=role_id, where role_id is a Magento authorization_role id. Blank lines and # comments are ignored; on duplicate groups the later line wins.

Roles are (re)assigned on every login, so IdP group changes take effect at next sign-in. An identity whose groups match no rule gets default_role; if that is empty the user is denied a role.

Enforce SSO + break-glass

With Enforce SSO on, the native username/password admin form is rejected — all sign-in goes through the IdP. To stay recoverable if the IdP is misconfigured, keep Allow Break-Glass Login on: a local admin can still sign in by adding break_glass=1 to the login request:

With break-glass off and enforce on, a lockout is not recoverable from the UI — only by disabling enforce_sso via CLI/DB. Leave break-glass on unless you have another recovery path.

How it works

  1. User clicks "Sign in with SSO" → adminsso/sso/start builds the OIDC auth URL (state + nonce + PKCE) via sso-core and the active preset, then redirects to the IdP.
  2. The IdP redirects back to adminsso/sso/callback, which validates state, exchanges the code, and normalizes claims into an Identity via sso-core.
  3. JIT: the admin user is matched by IdP sub (stored on a unique admin_user.dmlab_sso_subject_id column added at setup:upgrade), falling back to email, and created if absent (with a suffixed username on any local collision).
  4. Roles are mapped from IdP groups and the admin backend session is established.
  5. The IdP-authenticated session satisfies Magento core 2FA (Magento_TwoFactorAuth), so users are not double-prompted.

Requirements

Part of the DMLab identity suite

Repo Role
sso-core Shared OIDC engine (installed automatically)
admin-sso · admin-sso-<idp> Admin-panel SSO login
customer-sso · customer-sso-<idp> Storefront SSO login
admin-scim · admin-scim-<idp> Admin-user provisioning (SCIM 2.0)

License

https://dmlab.work.


All versions of module-admin-sso with dependencies

PHP Build Version
Package Version
Requires php Version ~8.3.0||~8.4.0||~8.5.0
magento/framework Version >=103.0
dmlab/module-sso-core Version *
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package dmlab/module-admin-sso contains the following files

Loading the files please wait ...