使用MediaWiki ClientLogin实现SSO登录验证遇问题求助
Hey there, let's break this down clearly since you're dealing with a newer MediaWiki instance where the old ClientLogin approach doesn't play nice anymore.
Is ClientLogin the right direction?
Short answer: No.
ClientLogin was deprecated back in MediaWiki 1.27 when the AuthManager system was introduced, and it’s not compatible with modern authentication workflows. The error you’re seeing—Authmanager-authn-no-primary—is exactly this mismatch: ClientLogin tries to use the old authentication pipeline, but your wiki is using the new AuthManager which doesn’t recognize ClientLogin’s approach as a valid primary authentication method. You can scratch ClientLogin off your list; it’s not supported for newer MediaWiki versions.
Should you connect directly to the MediaWiki database?
While technically possible, this is a bad idea for a few key reasons:
- MediaWiki stores passwords as salted hashes (using algorithms like bcrypt), so you can’t validate user credentials directly—you’d have to replicate MediaWiki’s exact password hashing logic, which is error-prone and could break if MediaWiki updates its hashing method.
- Database schemas change between MediaWiki versions. If your wiki gets updated, your app could break suddenly if you’re relying on specific table structures.
- Security risk: Giving your PHP app direct access to the MediaWiki database exposes you to potential data leaks or accidental data modification if your app has vulnerabilities.
Better alternatives for SSO with your PHP app
Here are the recommended approaches, ordered by ease of implementation:
1. Use the modern MediaWiki Action API (Login endpoint)
The official, supported way to authenticate users via API is using the login action in the Action API. It’s designed to work with AuthManager, and follows a two-step process:
Step 1: Get a login token
First, fetch a valid login token from the wiki:
$apiUrl = 'http://127.0.0.1/wiki/api.php'; $tokenParams = [ 'action' => 'query', 'meta' => 'tokens', 'type' => 'login', 'format' => 'json' ]; $tokenUrl = $apiUrl . '?' . http_build_query($tokenParams); $tokenResponse = json_decode(file_get_contents($tokenUrl), true); $loginToken = $tokenResponse['query']['tokens']['logintoken'];
Step 2: Submit credentials for authentication
Send a POST request with the username, password, and login token:
$loginParams = [ 'action' => 'login', 'username' => 'example', 'password' => '12345678', 'logintoken' => $loginToken, 'format' => 'json' ]; $ch = curl_init($apiUrl); curl_setopt($ch, CURLOPT_POST, true); curl_setopt($ch, CURLOPT_POSTFIELDS, http_build_query($loginParams)); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); // Important: Store the cookies returned by the wiki to maintain session state curl_setopt($ch, CURLOPT_COOKIEJAR, '/tmp/wiki_cookies.txt'); curl_setopt($ch, CURLOPT_COOKIEFILE, '/tmp/wiki_cookies.txt'); $loginResponse = json_decode(curl_exec($ch), true); curl_close($ch); // Check if login succeeded if ($loginResponse['login']['result'] === 'Success') { // Get user info to confirm $userInfoParams = [ 'action' => 'query', 'meta' => 'userinfo', 'format' => 'json' ]; $userInfoUrl = $apiUrl . '?' . http_build_query($userInfoParams); $userInfoResponse = json_decode(file_get_contents($userInfoUrl, false, stream_context_create([ 'http' => ['header' => 'Cookie: ' . file_get_contents('/tmp/wiki_cookies.txt')] ])), true); $userData = $userInfoResponse['query']['userinfo']; // Now you can create a session in your PHP app using $userData }
This approach uses the official API, is maintained by MediaWiki, and avoids the pitfalls of direct database access.
2. Use the MediaWiki OAuth Extension
If you want a more robust, secure SSO flow (especially if users should stay logged in across sessions without re-entering passwords), the OAuth extension is the way to go. It lets users authorize your app to access their wiki account without sharing their password, and follows standard OAuth 1.0a or 2.0 flows.
You’ll need to install the OAuth extension on your MediaWiki instance, register your app as a consumer, then implement the OAuth flow in your PHP app. This is ideal if you plan to build more integrations with the wiki later.
3. Session Sharing (Same Domain/Server)
If your PHP app and MediaWiki share the same domain (or subdomain) and are on the same server, you can try sharing session data. MediaWiki uses PHP sessions by default (though this can be configured to use other stores like Redis).
To make this work:
- Ensure both apps use the same session save path (check
session.save_pathin php.ini) or a shared session store. - Use the same
session.name(PHP session cookie name) in both apps. - Note: MediaWiki adds extra validation to sessions, so you’ll need to verify the session data matches MediaWiki’s expectations (e.g., checking the
mwUsersession variable). This is more hacky than the API approach, but works for tight, same-server integrations.
Final Recommendation
Start with the Action API Login flow—it’s the simplest, most supported method for your use case. It avoids direct database access, works with modern MediaWiki versions, and doesn’t require installing extra extensions. Once you have that working, you can explore OAuth if you need a more seamless SSO experience.
内容的提问来源于stack exchange,提问作者lightcycle

