Download the PHP package dmlab/module-customer-sso without Composer

On this page you can find all versions of the php package dmlab/module-customer-sso. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package module-customer-sso

DmLab_CustomerSso

Provider-agnostic single sign-on for the Magento 2 storefront (OIDC).

License Magento PHP Version

This is the storefront-login capability core: it logs shoppers in over OIDC but never references a concrete IdP. Install a provider plugin (e.g. customer-sso-okta) to bind it to an identity provider.

Features

Installation

Usually installed via a provider plugin, which pulls this core (which pulls sso-core):

Direct install of the core alone:

Register the module callback URL in your IdP: https://<store-host>/customersso/sso/callback. It must exactly match the storefront URL used at runtime.

Configuration

Admin → Stores → Configuration → DMLab → Customer SSO → General (config path dmlab_customer_sso/general/*). Settings are store-scoped, so SSO can be enabled and tuned per store view.

Field Path Notes
Enable Customer SSO enabled Master switch; off by default.
Identity Provider active_provider Dropdown populated by installed provider plugins.
Client ID client_id OIDC client id from the IdP.
Client Secret client_secret Stored encrypted.
Keep Password Login allow_password_login On (default): native email/password form stays visible alongside SSO. Off: form is hidden once SSO is live, making login SSO-only.
Account Linking by Email auto_link_policy auto vs require_verification. See below.
Group to Customer-Group Map group_customer_group_map IdP group → customer-group rules. See below.

The "Sign in with SSO" button appears on the customer login page when the module is enabled and a provider is selected; it uses the active preset's branding. Setting Keep Password Login to No hides the native form once SSO is live. As a break-glass, the form stays visible on an unconfigured or broken install (no active provider), so a mis-set toggle can never lock shoppers out.

Account linking

An SSO identity is matched to a customer in this order:

  1. By IdP sub — the stable subject stored in dmlab_customer_sso_subject on first link. A customer is EAV/API-backed, so the link lives in its own table rather than a column on the entity.
  2. By email, governed by auto_link_policy:
    • auto — a matching email signs straight into the existing customer.
    • require_verification (default) — email linking is refused until the email is proven, preventing account takeover via an unverified IdP email.
  3. JIT create — no match → a new customer_entity is provisioned from the identity, and the sub is stored for stable re-login.

require_verification is the safe default; switch to auto only when the IdP guarantees verified emails.

Group → customer-group mapping

group_customer_group_map takes one rule per line as idp_group=customer_group_id, where customer_group_id is a Magento customer_group id. Blank lines and # comments are ignored; on duplicate groups the later line wins.

With no rules configured this is inert: customer groups are never touched, so a store using SSO only for login keeps its manually assigned groups. Once a map exists, groups are resolved on JIT create and refreshed on every login, so IdP group changes take effect at next sign-in. An identity whose groups match no rule reverts to the store's default customer group (GroupManagementInterface::getDefaultGroup) — customers always hold a valid group. A rule pointing at a non-existent group id is skipped, leaving the current group unchanged.

How it works

  1. Shopper clicks "Sign in with SSO" → customersso/sso/start builds the OIDC auth URL (state + nonce + PKCE) via sso-core and the active preset, persists that state in the customer session, then redirects to the IdP.
  2. IdP redirects back to customersso/sso/callback, which validates state, exchanges the code, and normalizes claims into an Identity via sso-core. IdP error responses return to the login page with a message.
  3. The customer is matched (sub → email-under-policy → JIT create) and the sub link is stored.
  4. The customer group is resolved from IdP groups and the storefront customer session is established.

Requirements

Part of the DMLab identity suite

Repo Role
sso-core Shared OIDC engine (installed automatically)
admin-sso · admin-sso-<idp> Admin-panel SSO login
customer-sso · customer-sso-<idp> Storefront SSO login
admin-scim · admin-scim-<idp> Admin-user provisioning (SCIM 2.0)

License

https://dmlab.work.


All versions of module-customer-sso with dependencies

PHP Build Version
Package Version
Requires php Version ~8.3.0||~8.4.0||~8.5.0
magento/framework Version >=103.0
dmlab/module-sso-core Version *
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package dmlab/module-customer-sso contains the following files

Loading the files please wait ...