JuliaHEP / JuliaHEP-2023

Materials for the JuliaHEP 2023 Workshop
https://juliahep.github.io/JuliaHEP-2023/
Creative Commons Attribution 4.0 International
4 stars 4 forks source link

Logistics of using Binder #25

Closed Moelf closed 2 months ago

Moelf commented 10 months ago
aoanla commented 10 months ago

...what account do you need to use the Binder service? It doesn't like me using my UoG IdP apparently (I get "you are not authorized" after I log in)

Moelf commented 10 months ago

CERN SSO should work, also try ORCid

I tried my university (US) and it also works

aoanla commented 10 months ago

Well, first I have to work out how to clear my current login session (since it seems to be sticky, and I can't see a "logout and try a different IdP" button).

Moelf commented 10 months ago

Try in a private browser session for now just to figure out what auth works I suppose

aoanla commented 10 months ago

So, I've tapped out of options: my University account gets me through to the JupyterHub but hits a "not authorized" page, CERN SSO just doesn't seem to work (it refuses to auth me, despite my double-checking that username/password works on the CERN website), and ORCid gets to the Link Cilogon "confirm your email address" step, and then fails with "unexpected error contacting your identify provider".

Are we sure this thing works for people outside the USA?

Moelf commented 10 months ago

If you can get to Jupiter page you shouldn't be not authorized. Maybe give that a minute or use a less private browser. (I may have had similar issues with Firefox but now I'm fine on Firefox)

aoanla commented 10 months ago

I get the same thing in Firefox and Chromium [including if I turn off literally every privacy plugin I have in Chromium], so...

Do you know, is this thing using a login list, or should it just work for any account that can authenticate via an IdP?

Moelf commented 10 months ago

My understanding was they didn't have an allow list which was a concern for abuse at some point. Maybe now they have?

But CERN SSO should definitely work though if they have an allow list now. I will ask