Skip to content

คู่มือการใช้งาน (UAT) ​

คู่มือการใช้งาน

KKU Single Sign On (SSONext)
(UAT - Stage)

สิ่งที่ผู้พัฒนาหรือผู้ขอใช้บริการต้องเตรียม ​

  1. Redirect URL เป็นลิ้งค์ที่ใช้ redirect กลับ เมื่อ user ทำการล็อคอินเรียบร้อยแล้ว เช่น https://digital.kku.ac.th/auth/callback/login
  2. Redirect Logout URL เป็นลิ้งก์ที่ใช้ redirect กลับ เมื่อ user ทำการล็อคเอ้าท์ออกจากระบบแล้ว

สิ่งที่ผู้ให้บริการจะส่งข้อมูล หลังจากขอใช้บริการ มีข้อมูลดังนี้ ​

  1. App ID
  2. Client ID
  3. Client Secret

ขั้นตอนการใช้ KKU Single Sign On (SSONext) ​

Login endpoint: ​

https://sso-uat-web.kku.ac.th/login?app=<AppID>

ตัวอย่างการใช้งาน

html
<a href="https://sso-uat-web.kku.ac.th/login?app=<AppID>">Login</a>

Redirect Callback Login URL:

เมื่อ user ล็อกอินสำเร็จแล้วจะ redirect กลับมาที่เว็บไซต์ของผู้ขอใช้บริการ เช่น
https://digital.kku.ac.th/auth/callback/login?code=0190e7fe-fd00-7d8c-b823-5cdd79f04769

ให้ทำการรับค่าจากพารามิเตอร์ code เพื่อนำไปขอ Access token เพื่อเข้าถึง Resources อื่นต่อไป


REST Service:

  1. ระบบที่เชื่อมต่อร้องขอ Access Token ด้วยการใช้ REST service ตามตัวอย่างนี้ ​

HTTP Request

ส่วนประกอบรายละเอียด
HTTP MethodPOST
URLhttps://sso-uat-api.kku.ac.th/auth.token

Request Body raw (json)

json
{ 
    "code": "<code>",
    "redirectUrl": "<redirectUrl>",
    "clientId": "<clientId>",
    "clientSecret": "<clientSecret>"
}

ตัวอย่างการใช้งานด้วย cURL

shell
curl --location --request POST 'https://sso-uat-api.kku.ac.th/auth.token' \
--header 'Content-Type: application/json' \
--data '{
    "code": "<code from Query Params>",
    "redirectUrl": "<Redirect Url>",
    "clientId": "<Client ID>",
    "clientSecret":"<Client Secret>"
}'

กรณีที่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้

json
{
    "ok": true,
    "accessToken": "",
    "email": "",
    "immutableId": "",
    "citizenId": "",
    "firstName": "",
    "lastName": "",
    "employeeId": ""
}

กรณีที่ไม่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้

json
{
    "ok": false,
    "error": "AUTH0001"
}
  1. ระบบที่เชื่อมต่อร้องขอ User Resource ด้วยการใช้ REST service ตามตัวอย่างนี้ ​

HTTP Request

ส่วนประกอบรายละเอียด
HTTP MethodPOST
URLhttps://sso-uat-api.kku.ac.th/user.profile

Request Headers

ฟิลด์ (Field)
AuthorizationBearer <Access Token>

ตัวอย่างการใช้งานด้วย cURL

json
curl --location --request POST 'https://sso-uat-api.kku.ac.th/user.profile' \
--header 'Authorization: Bearer <Access Token>' \
--data ''

กรณีที่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้

json
{
    "ok": true,
    "profile": {
        "email": "",
        "userId": "",
        "type": "",
        "citizenId": "",
        "title": "",
        "firstname": "",
        "lastname": "",
        "titleEng": "",
        "firstnameEng": "",
        "lastnameEng": "",
        "facultyName": "",
        "positionName": "",
        "positionTypeName": "",
        "levelId": "",
        "levelName": "",
        "gender": "",
        "workline": "",
        "phoneNumber": "",
        "personStatus": ""
        "lastVerify": ""
    }
}

กรณีที่ไม่สำเร็จระบบจะตอบ HTTP Status 401 Unauthorized

  1. ระบบที่เชื่อมต่อเพื่อร้องขอ Authen Status ด้วยการใช้ REST service ตามตัวอย่างนี้ ​

HTTP Request

ส่วนประกอบรายละเอียด
HTTP MethodPOST
URLhttps://sso-uat-api.kku.ac.th/auth.status

Request Headers

ฟิลด์ (Field)
AuthorizationBearer <Access Token>

ตัวอย่างการใช้งานด้วย cURL

shell
curl --location --request POST 'https://sso-uat-api/auth.status \
--header 'Authorization: Bearer <Access Token>' \
--data ''

กรณีที่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้

json
{
    "ok": true,
    "user": {
        "sessionId": "xxxxxxxxx-f674-73ed-b12b-xxxxxxxxxxxxx",
        "email": "xxxx@kku.ac.th",
        "role": "STAFF"
    }
}

กรณีที่ไม่สำเร็จระบบจะตอบ HTTP Status 401 Unauthorized


Logout endpoint: ​

https://sso-uat-web.kku.ac.th/logout?app=<AppID>

ตัวอย่างการใช้งาน

html
<a href="https://sso-uat-web.kku.ac.th/logout?app=<AppID>">Logout</a>

Redirect Callback Logout URL:

เมื่อ user ล็อกเอ้าท์สำเร็จแล้วจะ redirect กลับมาที่เว็บไซต์ของผู้ขอใช้บริการ ตามข้อมูลที่ระบบไว้ในแบบฟอร์มขอใช้งาน เช่น
https://digital.kku.ac.th/auth/callback/logout


ติดต่อสอบถามเพิ่มเติมได้ที่ :

  • ธีรวัฒน์ พูลสวัสดิ์ นักวิชาการคอมพิวเตอร์ อีเมล: teerpo@kku.ac.th
  • สำนักเทคโนโลยีดิจิทัล มหาวิทยาลัยขอนแก่น

คู่มือการใช้งาน (Production) ​

คู่มือการใช้งาน

KKU Single Sign On (SSONext)
(Production - Stage)

สิ่งที่ผู้พัฒนาหรือผู้ขอใช้บริการต้องเตรียม ​

  1. Redirect URL เป็นลิ้งค์ที่ใช้ redirect กลับ เมื่อ user ทำการล็อคอินเรียบร้อยแล้ว เช่น https://digital.kku.ac.th/auth/callback/login
  2. Redirect Logout URL เป็นลิ้งก์ที่ใช้ redirect กลับ เมื่อ user ทำการล็อคเอ้าท์ออกจากระบบแล้ว

สิ่งที่ผู้ให้บริการจะส่งข้อมูล หลังจากขอใช้บริการ มีข้อมูลดังนี้ ​

  1. App ID
  2. Client ID
  3. Client Secret

ขั้นตอนการใช้ KKU Single Sign On (SSONext) ​

Login endpoint: ​

https://ssonext.kku.ac.th/login?app=<AppID>

ตัวอย่างการใช้งาน

html
<a href="https://ssonext.kku.ac.th/login?app=<AppID>">Login</a>

Redirect Callback Login URL:

เมื่อ user ล็อกอินสำเร็จแล้วจะ redirect กลับมาที่เว็บไซต์ของผู้ขอใช้บริการ เช่น
https://digital.kku.ac.th/auth/callback/login?code=0190e7fe-fd00-7d8c-b823-5cdd79f04769

ให้ทำการรับค่าจากพารามิเตอร์ code เพื่อนำไปขอ Access token เพื่อเข้าถึง Resources อื่นต่อไป


REST Service:

  1. ระบบที่เชื่อมต่อร้องขอ Access Token ด้วยการใช้ REST service ตามตัวอย่างนี้ ​

HTTP Request

ส่วนประกอบรายละเอียด
HTTP MethodPOST
URLhttps://ssonext-api.kku.ac.th/auth.token

Request Body raw (json)

json
{ 
    "code": "<code>",
    "redirectUrl": "<redirectUrl>",
    "clientId": "<clientId>",
    "clientSecret": "<clientSecret>"
}

ตัวอย่างการใช้งานด้วย cURL

shell
curl --location --request POST 'https://ssonext-api.kku.ac.th/auth.token' \
--header 'Content-Type: application/json' \
--data '{
    "code": "<code from Query Params>",
    "redirectUrl": "<Redirect Url>",
    "clientId": "<Client ID>",
    "clientSecret":"<Client Secret>"
}'

กรณีที่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้

json
{
    "ok": true,
    "accessToken": "",
    "email": "",
    "immutableId": "",
    "citizenId": "",
    "firstName": "",
    "lastName": "",
    "employeeId": ""
}

กรณีที่ไม่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้

json
{
    "ok": false,
    "error": "AUTH0001"
}
  1. ระบบที่เชื่อมต่อร้องขอ User Resource ด้วยการใช้ REST service ตามตัวอย่างนี้ ​

HTTP Request

ส่วนประกอบรายละเอียด
HTTP MethodPOST
URLhttps://ssonext-api.kku.ac.th/user.profile

Request Headers

ฟิลด์ (Field)
AuthorizationBearer <Access Token>

ตัวอย่างการใช้งานด้วย cURL

shell
curl --location --request POST 'https://ssonext-api.kku.ac.th/user.profile' \
--header 'Authorization: Bearer <Access Token>' \
--data ''

กรณีที่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้

json
{
    "ok": true,
    "profile": {
        "email": "",
        "userId": "",
        "type": "",
        "citizenId": "",
        "title": "",
        "firstname": "",
        "lastname": "",
        "titleEng": "",
        "firstnameEng": "",
        "lastnameEng": "",
        "facultyName": "",
        "positionName": "",
        "positionTypeName": "",
        "levelId": "",
        "levelName": "",
        "gender": "",
        "workline": "",
        "phoneNumber": "",
        "personStatus": ""
        "lastVerify": ""
    }
}

กรณีที่ไม่สำเร็จระบบจะตอบ HTTP Status 401 Unauthorized

  1. ระบบที่เชื่อมต่อเพื่อร้องขอ Authen Status ด้วยการใช้ REST service ตามตัวอย่างนี้ ​

HTTP Request

ส่วนประกอบรายละเอียด
HTTP MethodPOST
URLhttps://ssonext-api.kku.ac.th/auth.status

Request Headers

ฟิลด์ (Field)
AuthorizationBearer <Access Token>

ตัวอย่างการใช้งานด้วย cURL

shell
curl --location --request POST 'https://ssonext-api.kku.ac.th/auth.status \
--header 'Authorization: Bearer <Access Token>' \
--data ''

กรณีที่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้

json
{
    "ok": true,
    "user": {
        "sessionId": "xxxxxxxxx-f674-73ed-b12b-xxxxxxxxxxxxx",
        "email": "xxxx@kku.ac.th",
        "role": "STAFF"
    }
}

กรณีที่ไม่สำเร็จระบบจะตอบ HTTP Status 401 Unauthorized


Logout endpoint: ​

https://ssonext.kku.ac.th/logout?app=<AppID>

ตัวอย่างการใช้งาน

html
<a href="https://ssonext.kku.ac.th/logout?app=<AppID>">Logout</a>

Redirect Callback Logout URL:

เมื่อ user ล็อกเอ้าท์สำเร็จแล้วจะ redirect กลับมาที่เว็บไซต์ของผู้ขอใช้บริการ ตามข้อมูลที่ระบบไว้ในแบบฟอร์มขอใช้งาน เช่น
https://digital.kku.ac.th/auth/callback/logout


ติดต่อสอบถามเพิ่มเติมได้ที่ :

  • ธีรวัฒน์ พูลสวัสดิ์ นักวิชาการคอมพิวเตอร์ อีเมล: teerpo@kku.ac.th
  • สำนักเทคโนโลยีดิจิทัล มหาวิทยาลัยขอนแก่น

Working docs. STATE.md is the status file and lives at the repo root, not here.