Glossary

Contents

Glossary#

audit log#

The record of every authentication event this package fires, and of the refusals that fire no event. It is an authentication event log, not a session ledger.

claim#

A statement a provider makes about a person, such as their name or email address. Drivers normalize the claims a provider sends into a fixed schema before anything else reads them.

client#

An application registered against a Plone site running the [server] layer, so that the application can sign its users in against that site. A client is identified by a client_id and authenticates with a secret this site stores only as a hash.

driver#

Static metadata describing what a kind of provider needs, plus a function turning that provider's answer into normalized claims. A driver holds no state and makes no decisions about accounts. Drivers are registered as named ZCA utilities, and the utility name is the driver id.

external identity#
identity#

The pair of a provider and that provider's own identifier for a person. One Plone user id may have many external identities. An identity is account data: deleting the provider that authenticated it does not delete it.

group#

A collection of users, stored as content in the same way a Profile is. Membership may be granted locally or by a provider that asserts it, and a login only ever takes back what that same provider granted.

issuer#

The URL that identifies an authorization server. A relying party compares the issuer field inside a discovery document to the URL it fetched the document from, byte for byte, and refuses the document if they differ.

Sign-in by an emailed, signed, single-use token, provided by the email driver. It needs no external provider, and it is the verification this package performs itself.

Markedly Structured Text#
MyST#

Markedly Structured Text (MyST) is a rich and extensible flavor of Markdown. This documentation is written in MyST.

nested group#

A group that is a member of another group. Written either by filing the group inside the other one or by naming it in the inner group's group_ids, and the two are unioned. Everybody in the inner group is in the outer one.

Plone#

Plone is an open source content management system used to create, edit, and manage digital content, such as websites, intranets, and custom solutions.

Plone Sphinx Theme#
plone-sphinx-theme#

Plone Sphinx Theme is a Sphinx theme for Plone 6 Documentation, Plone Conference Training, and documentation of various Plone packages.

preferred address#

The address a Profile's email resolves to: the first verified one in its emails list, or the first one at all when none is verified.

Profile#

A content object carrying one user's PAS property sheet. Its values are served from catalog metadata, so answering a property lookup never wakes the object.

provider#

A configured instance of a driver, holding this site's credentials for one particular service. Two GitHub organizations are two providers sharing one driver.

relying party#

An application that sends its users to an authorization server to sign in, and relies on what that server says about them.

Sphinx#

Sphinx is a documentation generator that builds this documentation into HTML.

subject#

A provider's own identifier for a person, sent as the sub claim in OpenID Connect. A subject is meaningful only within the provider that issued it.

userid#
user id#

The canonical Plone identifier for a person. On accounts this package creates it is a random uuid4 hex string, minted once and never rewritten. It survives a change of email address, of provider, and of the name the person signs in with.

verified address#

An address this site holds as proved, recorded as an email external identity owned by that user id. Either a magic link proved it, or a provider the operator marked as trusting vouched for it. A provider nobody marked does not make an address verified here, whatever it asserts.