From 66d9944311e2d67029583130ef4f94d2a03b4cae Mon Sep 17 00:00:00 2001 From: Mira Weller Date: Tue, 22 Sep 2026 16:56:35 +0200 Subject: [PATCH] Attempt to make customer account SSO configuration a bit less confusing --- src/pretix/control/forms/organizer.py | 23 +++++++++++++++---- .../organizers/ssoclient_edit.html | 19 ++++++++++++++- .../pretixcontrol/organizers/ssoclients.html | 11 +++++++-- .../organizers/ssoprovider_edit.html | 16 +++++++++++-- .../organizers/ssoproviders.html | 11 +++++++-- src/pretix/control/views/organizer.py | 9 ++++++-- 6 files changed, 75 insertions(+), 14 deletions(-) diff --git a/src/pretix/control/forms/organizer.py b/src/pretix/control/forms/organizer.py index 2bafd2d420..eb81cea6b0 100644 --- a/src/pretix/control/forms/organizer.py +++ b/src/pretix/control/forms/organizer.py @@ -1198,7 +1198,7 @@ OrganizerFooterLinkFormset = inlineformset_factory( class SSOProviderForm(I18nModelForm): config_oidc_base_url = forms.URLField( - label=pgettext_lazy('sso_oidc', 'Base URL'), + label=pgettext_lazy('sso_oidc', 'Base URL / issuer'), required=False, ) config_oidc_client_id = forms.CharField( @@ -1295,6 +1295,14 @@ class SSOProviderForm(I18nModelForm): class SSOClientForm(I18nModelForm): + disp_base_url = forms.CharField( + label=_('Base URL / issuer'), + disabled=True, + ) + disp_client_id = forms.CharField( + label=_('Client ID'), + disabled=True, + ) regenerate_client_secret = forms.BooleanField( label=_('Invalidate old client secret and generate a new one'), required=False, @@ -1302,7 +1310,8 @@ class SSOClientForm(I18nModelForm): class Meta: model = CustomerSSOClient - fields = ['is_active', 'name', 'client_id', 'client_type', 'authorization_grant_type', 'redirect_uris', + fields = ['is_active', 'name', 'disp_base_url', 'disp_client_id', 'regenerate_client_secret', + 'client_type', 'authorization_grant_type', 'redirect_uris', 'allowed_scopes', 'require_pkce'] widgets = { 'authorization_grant_type': forms.RadioSelect, @@ -1317,13 +1326,17 @@ class SSOClientForm(I18nModelForm): help_text=self.fields['allowed_scopes'].help_text, required=self.fields['allowed_scopes'].required, initial=self.fields['allowed_scopes'].initial, - choices=CustomerSSOClient.SCOPE_CHOICES, + choices=[(val, format_html('{} – {}', val, label)) for val, label in CustomerSSOClient.SCOPE_CHOICES], widget=forms.CheckboxSelectMultiple ) + organizer = kwargs['event'] + self.initial['disp_base_url'] = eventreverse_absolute(organizer, 'presale:organizer.index', {}).strip('/') if self.instance and self.instance.pk: - self.fields['client_id'].disabled = True + self.initial['disp_client_id'] = self.instance.client_id + self.initial['disp_client_secret'] = '****' else: - del self.fields['client_id'] + self.initial['disp_client_id'] = _('(will be generated)') + self.initial['disp_client_secret'] = _('(will be generated)') del self.fields['regenerate_client_secret'] diff --git a/src/pretix/control/templates/pretixcontrol/organizers/ssoclient_edit.html b/src/pretix/control/templates/pretixcontrol/organizers/ssoclient_edit.html index e1265ced37..aaebd0859f 100644 --- a/src/pretix/control/templates/pretixcontrol/organizers/ssoclient_edit.html +++ b/src/pretix/control/templates/pretixcontrol/organizers/ssoclient_edit.html @@ -1,12 +1,29 @@ {% extends "pretixcontrol/organizers/base.html" %} {% load i18n %} {% load bootstrap3 %} +{% block title %} + {% if client %} + {% trans "SSO client:" %} {{ client.name }} + {% else %} + {% trans "Create credentials for a new SSO client" %} + {% endif %} +{% endblock %} {% block inner %} {% if client %}

{% trans "SSO client:" %} {{ client.name }}

{% else %} -

{% trans "Create a new SSO client" %}

+

{% trans "Create credentials for a new SSO client" %}

+

+ {% blocktrans trimmed %} + After submitting this form, client credentials for your SSO client will be generated. + {% endblocktrans %} +

{% endif %} +

+ {% blocktrans trimmed with url="https://docs.pretix.eu/guides/customer-accounts/#using-pretix-as-an-sso-provider" %} + For more information, refer to our documentation on Using pretix as an SSO provider with external SSO clients. + {% endblocktrans %} +

{% csrf_token %} {% bootstrap_form form layout="control" %} diff --git a/src/pretix/control/templates/pretixcontrol/organizers/ssoclients.html b/src/pretix/control/templates/pretixcontrol/organizers/ssoclients.html index b9eec04176..97caff43f9 100644 --- a/src/pretix/control/templates/pretixcontrol/organizers/ssoclients.html +++ b/src/pretix/control/templates/pretixcontrol/organizers/ssoclients.html @@ -3,16 +3,23 @@ {% load bootstrap3 %} {% block title %}{% trans "SSO clients" %}{% endblock %} {% block inner %} -

{% trans "SSO clients" %}

+

{% trans "SSO clients" %} — {% blocktrans %} + "Login with pretix" in external systems + {% endblocktrans %}

{% blocktrans trimmed %} You can allow your customers to log into other systems using their customer account credentials by setting up your other systems as a Single-Sign-On (SSO) client based on OpenID Connect. {% endblocktrans %}

+

+ {% blocktrans trimmed with url="https://docs.pretix.eu/guides/customer-accounts/#using-pretix-as-an-sso-provider" %} + For more information, refer to our documentation on Using pretix as an SSO provider with external SSO clients. + {% endblocktrans %} +

- {% trans "Create a new SSO client" %} + {% trans "Create credentials for a new SSO client" %} diff --git a/src/pretix/control/templates/pretixcontrol/organizers/ssoprovider_edit.html b/src/pretix/control/templates/pretixcontrol/organizers/ssoprovider_edit.html index 1e98691078..fed6291776 100644 --- a/src/pretix/control/templates/pretixcontrol/organizers/ssoprovider_edit.html +++ b/src/pretix/control/templates/pretixcontrol/organizers/ssoprovider_edit.html @@ -1,12 +1,24 @@ {% extends "pretixcontrol/organizers/base.html" %} {% load i18n %} {% load bootstrap3 %} +{% block title %} + {% if provider %} + {% trans "External SSO provider:" %} {{ provider.name }} + {% else %} + {% trans "Connect to an external SSO provider" %} + {% endif %} +{% endblock %} {% block inner %} {% if provider %} -

{% trans "SSO provider:" %} {{ provider.name }}

+

{% trans "External SSO provider:" %} {{ provider.name }}

{% else %} -

{% trans "Create a new SSO provider" %}

+

{% trans "Connect to an external SSO provider" %}

{% endif %} +

+ {% blocktrans trimmed with url="https://docs.pretix.eu/guides/customer-accounts/#using-pretix-as-an-sso-client" %} + For more information, refer to our documentation on Using pretix as an SSO client. + {% endblocktrans %} +

{% csrf_token %} {% bootstrap_form form layout="control" %} diff --git a/src/pretix/control/templates/pretixcontrol/organizers/ssoproviders.html b/src/pretix/control/templates/pretixcontrol/organizers/ssoproviders.html index 248c347a1e..e813b53e97 100644 --- a/src/pretix/control/templates/pretixcontrol/organizers/ssoproviders.html +++ b/src/pretix/control/templates/pretixcontrol/organizers/ssoproviders.html @@ -3,16 +3,23 @@ {% load bootstrap3 %} {% block title %}{% trans "SSO providers" %}{% endblock %} {% block inner %} -

{% trans "SSO providers" %}

+

{% trans "SSO providers" %} — {% blocktrans %} + Connect to an external login provider + {% endblocktrans %}

{% blocktrans trimmed %} You can connect existing Single-Sign-On (SSO) providers to allow your customers to log in using your own account system. {% endblocktrans %}

+

+ {% blocktrans trimmed with url="https://docs.pretix.eu/guides/customer-accounts/#using-pretix-as-an-sso-client" %} + For more information, refer to our documentation on Using pretix as an SSO client. + {% endblocktrans %} +

- {% trans "Create a new SSO provider" %} + {% trans "Connect to an external SSO provider" %}
diff --git a/src/pretix/control/views/organizer.py b/src/pretix/control/views/organizer.py index 0eea804b53..ff223d4867 100644 --- a/src/pretix/control/views/organizer.py +++ b/src/pretix/control/views/organizer.py @@ -2817,10 +2817,15 @@ class SSOProviderCreateView(OrganizerDetailViewMixin, OrganizerPermissionRequire return get_object_or_404(CustomerSSOProvider, organizer=self.request.organizer, pk=self.kwargs.get('provider')) def get_success_url(self): - return reverse('control:organizer.ssoproviders', kwargs={ - 'organizer': self.request.organizer.slug, + return reverse('control:organizer.ssoprovider.edit', kwargs={ + 'organizer': self.request.organizer.slug, 'provider': self.object.pk, }) + def get_context_data(self, **kwargs): + ctx = super().get_context_data(**kwargs) + ctx['redirect_uri'] = _('(will be generated)') + return ctx + def get_form_kwargs(self): kwargs = super().get_form_kwargs() kwargs['event'] = self.request.organizer