ธีม
คู่มือการใช้งาน (UAT)
คู่มือการใช้งาน
KKU Single Sign On (SSONext)
(UAT - Stage)
สิ่งที่ผู้พัฒนาหรือผู้ขอใช้บริการต้องเตรียม
- Redirect URL เป็นลิ้งค์ที่ใช้ redirect กลับ เมื่อ user ทำการล็อคอินเรียบร้อยแล้ว เช่น https://digital.kku.ac.th/auth/callback/login
- Redirect Logout URL เป็นลิ้งก์ที่ใช้ redirect กลับ เมื่อ user ทำการล็อคเอ้าท์ออกจากระบบแล้ว
สิ่งที่ผู้ให้บริการจะส่งข้อมูล หลังจากขอใช้บริการ มีข้อมูลดังนี้
- App ID
- Client ID
- Client Secret
ขั้นตอนการใช้ KKU Single Sign On (SSONext)
Login endpoint:
https://sso-uat-web.kku.ac.th/login?app=<AppID>
ตัวอย่างการใช้งาน
html
<a href="https://sso-uat-web.kku.ac.th/login?app=<AppID>">Login</a>Redirect Callback Login URL:
เมื่อ user ล็อกอินสำเร็จแล้วจะ redirect กลับมาที่เว็บไซต์ของผู้ขอใช้บริการ เช่น
https://digital.kku.ac.th/auth/callback/login?code=0190e7fe-fd00-7d8c-b823-5cdd79f04769
ให้ทำการรับค่าจากพารามิเตอร์ code เพื่อนำไปขอ Access token เพื่อเข้าถึง Resources อื่นต่อไป
REST Service:
ระบบที่เชื่อมต่อร้องขอ Access Token ด้วยการใช้ REST service ตามตัวอย่างนี้
HTTP Request
| ส่วนประกอบ | รายละเอียด |
|---|---|
| HTTP Method | POST |
| URL | https://sso-uat-api.kku.ac.th/auth.token |
Request Body raw (json)
json
{
"code": "<code>",
"redirectUrl": "<redirectUrl>",
"clientId": "<clientId>",
"clientSecret": "<clientSecret>"
}ตัวอย่างการใช้งานด้วย cURL
shell
curl --location --request POST 'https://sso-uat-api.kku.ac.th/auth.token' \
--header 'Content-Type: application/json' \
--data '{
"code": "<code from Query Params>",
"redirectUrl": "<Redirect Url>",
"clientId": "<Client ID>",
"clientSecret":"<Client Secret>"
}'กรณีที่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้
json
{
"ok": true,
"accessToken": "",
"email": "",
"immutableId": "",
"citizenId": "",
"firstName": "",
"lastName": "",
"employeeId": ""
}กรณีที่ไม่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้
json
{
"ok": false,
"error": "AUTH0001"
}ระบบที่เชื่อมต่อร้องขอ User Resource ด้วยการใช้ REST service ตามตัวอย่างนี้
HTTP Request
| ส่วนประกอบ | รายละเอียด |
|---|---|
| HTTP Method | POST |
| URL | https://sso-uat-api.kku.ac.th/user.profile |
Request Headers
| ฟิลด์ (Field) | |
|---|---|
| Authorization | Bearer <Access Token> |
ตัวอย่างการใช้งานด้วย cURL
json
curl --location --request POST 'https://sso-uat-api.kku.ac.th/user.profile' \
--header 'Authorization: Bearer <Access Token>' \
--data ''กรณีที่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้
json
{
"ok": true,
"profile": {
"email": "",
"userId": "",
"type": "",
"citizenId": "",
"title": "",
"firstname": "",
"lastname": "",
"titleEng": "",
"firstnameEng": "",
"lastnameEng": "",
"facultyName": "",
"positionName": "",
"positionTypeName": "",
"levelId": "",
"levelName": "",
"gender": "",
"workline": "",
"phoneNumber": "",
"personStatus": ""
"lastVerify": ""
}
}กรณีที่ไม่สำเร็จระบบจะตอบ HTTP Status 401 Unauthorized
ระบบที่เชื่อมต่อเพื่อร้องขอ Authen Status ด้วยการใช้ REST service ตามตัวอย่างนี้
HTTP Request
| ส่วนประกอบ | รายละเอียด |
|---|---|
| HTTP Method | POST |
| URL | https://sso-uat-api.kku.ac.th/auth.status |
Request Headers
| ฟิลด์ (Field) | |
|---|---|
| Authorization | Bearer <Access Token> |
ตัวอย่างการใช้งานด้วย cURL
shell
curl --location --request POST 'https://sso-uat-api/auth.status \
--header 'Authorization: Bearer <Access Token>' \
--data ''กรณีที่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้
json
{
"ok": true,
"user": {
"sessionId": "xxxxxxxxx-f674-73ed-b12b-xxxxxxxxxxxxx",
"email": "xxxx@kku.ac.th",
"role": "STAFF"
}
}กรณีที่ไม่สำเร็จระบบจะตอบ HTTP Status 401 Unauthorized
Logout endpoint:
https://sso-uat-web.kku.ac.th/logout?app=<AppID>
ตัวอย่างการใช้งาน
html
<a href="https://sso-uat-web.kku.ac.th/logout?app=<AppID>">Logout</a>Redirect Callback Logout URL:
เมื่อ user ล็อกเอ้าท์สำเร็จแล้วจะ redirect กลับมาที่เว็บไซต์ของผู้ขอใช้บริการ ตามข้อมูลที่ระบบไว้ในแบบฟอร์มขอใช้งาน เช่น
https://digital.kku.ac.th/auth/callback/logout
ติดต่อสอบถามเพิ่มเติมได้ที่ :
- ธีรวัฒน์ พูลสวัสดิ์ นักวิชาการคอมพิวเตอร์ อีเมล: teerpo@kku.ac.th
- สำนักเทคโนโลยีดิจิทัล มหาวิทยาลัยขอนแก่น
คู่มือการใช้งาน (Production)
คู่มือการใช้งาน
KKU Single Sign On (SSONext)
(Production - Stage)
สิ่งที่ผู้พัฒนาหรือผู้ขอใช้บริการต้องเตรียม
- Redirect URL เป็นลิ้งค์ที่ใช้ redirect กลับ เมื่อ user ทำการล็อคอินเรียบร้อยแล้ว เช่น https://digital.kku.ac.th/auth/callback/login
- Redirect Logout URL เป็นลิ้งก์ที่ใช้ redirect กลับ เมื่อ user ทำการล็อคเอ้าท์ออกจากระบบแล้ว
สิ่งที่ผู้ให้บริการจะส่งข้อมูล หลังจากขอใช้บริการ มีข้อมูลดังนี้
- App ID
- Client ID
- Client Secret
ขั้นตอนการใช้ KKU Single Sign On (SSONext)
Login endpoint:
https://ssonext.kku.ac.th/login?app=<AppID>
ตัวอย่างการใช้งาน
html
<a href="https://ssonext.kku.ac.th/login?app=<AppID>">Login</a>Redirect Callback Login URL:
เมื่อ user ล็อกอินสำเร็จแล้วจะ redirect กลับมาที่เว็บไซต์ของผู้ขอใช้บริการ เช่น
https://digital.kku.ac.th/auth/callback/login?code=0190e7fe-fd00-7d8c-b823-5cdd79f04769
ให้ทำการรับค่าจากพารามิเตอร์ code เพื่อนำไปขอ Access token เพื่อเข้าถึง Resources อื่นต่อไป
REST Service:
ระบบที่เชื่อมต่อร้องขอ Access Token ด้วยการใช้ REST service ตามตัวอย่างนี้
HTTP Request
| ส่วนประกอบ | รายละเอียด |
|---|---|
| HTTP Method | POST |
| URL | https://ssonext-api.kku.ac.th/auth.token |
Request Body raw (json)
json
{
"code": "<code>",
"redirectUrl": "<redirectUrl>",
"clientId": "<clientId>",
"clientSecret": "<clientSecret>"
}ตัวอย่างการใช้งานด้วย cURL
shell
curl --location --request POST 'https://ssonext-api.kku.ac.th/auth.token' \
--header 'Content-Type: application/json' \
--data '{
"code": "<code from Query Params>",
"redirectUrl": "<Redirect Url>",
"clientId": "<Client ID>",
"clientSecret":"<Client Secret>"
}'กรณีที่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้
json
{
"ok": true,
"accessToken": "",
"email": "",
"immutableId": "",
"citizenId": "",
"firstName": "",
"lastName": "",
"employeeId": ""
}กรณีที่ไม่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้
json
{
"ok": false,
"error": "AUTH0001"
}ระบบที่เชื่อมต่อร้องขอ User Resource ด้วยการใช้ REST service ตามตัวอย่างนี้
HTTP Request
| ส่วนประกอบ | รายละเอียด |
|---|---|
| HTTP Method | POST |
| URL | https://ssonext-api.kku.ac.th/user.profile |
Request Headers
| ฟิลด์ (Field) | |
|---|---|
| Authorization | Bearer <Access Token> |
ตัวอย่างการใช้งานด้วย cURL
shell
curl --location --request POST 'https://ssonext-api.kku.ac.th/user.profile' \
--header 'Authorization: Bearer <Access Token>' \
--data ''กรณีที่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้
json
{
"ok": true,
"profile": {
"email": "",
"userId": "",
"type": "",
"citizenId": "",
"title": "",
"firstname": "",
"lastname": "",
"titleEng": "",
"firstnameEng": "",
"lastnameEng": "",
"facultyName": "",
"positionName": "",
"positionTypeName": "",
"levelId": "",
"levelName": "",
"gender": "",
"workline": "",
"phoneNumber": "",
"personStatus": ""
"lastVerify": ""
}
}กรณีที่ไม่สำเร็จระบบจะตอบ HTTP Status 401 Unauthorized
ระบบที่เชื่อมต่อเพื่อร้องขอ Authen Status ด้วยการใช้ REST service ตามตัวอย่างนี้
HTTP Request
| ส่วนประกอบ | รายละเอียด |
|---|---|
| HTTP Method | POST |
| URL | https://ssonext-api.kku.ac.th/auth.status |
Request Headers
| ฟิลด์ (Field) | |
|---|---|
| Authorization | Bearer <Access Token> |
ตัวอย่างการใช้งานด้วย cURL
shell
curl --location --request POST 'https://ssonext-api.kku.ac.th/auth.status \
--header 'Authorization: Bearer <Access Token>' \
--data ''กรณีที่สำเร็จระบบจะตอบ HTTP Status 200 และมีโครงสร้างดังนี้
json
{
"ok": true,
"user": {
"sessionId": "xxxxxxxxx-f674-73ed-b12b-xxxxxxxxxxxxx",
"email": "xxxx@kku.ac.th",
"role": "STAFF"
}
}กรณีที่ไม่สำเร็จระบบจะตอบ HTTP Status 401 Unauthorized
Logout endpoint:
https://ssonext.kku.ac.th/logout?app=<AppID>
ตัวอย่างการใช้งาน
html
<a href="https://ssonext.kku.ac.th/logout?app=<AppID>">Logout</a>Redirect Callback Logout URL:
เมื่อ user ล็อกเอ้าท์สำเร็จแล้วจะ redirect กลับมาที่เว็บไซต์ของผู้ขอใช้บริการ ตามข้อมูลที่ระบบไว้ในแบบฟอร์มขอใช้งาน เช่น
https://digital.kku.ac.th/auth/callback/logout
ติดต่อสอบถามเพิ่มเติมได้ที่ :
- ธีรวัฒน์ พูลสวัสดิ์ นักวิชาการคอมพิวเตอร์ อีเมล: teerpo@kku.ac.th
- สำนักเทคโนโลยีดิจิทัล มหาวิทยาลัยขอนแก่น