WEBVTT

00:00.000 --> 00:21.840
Thank you, I hope it won't be the last applause I have because you haven't seen

00:21.840 --> 00:31.240
the presentation. Hello everybody, I'm very happy to be with you today to present

00:31.240 --> 00:40.680
a pro connect for the identity provider. My name is Gaiton Arquier, a little louder.

00:41.520 --> 00:55.240
Is it you hear me with my microphone or oh okay test of sound is it good like that better no no

00:55.240 --> 01:07.920
I can talk like that maybe to the other side so I can do that yeah yeah I would do

01:07.920 --> 01:19.360
like that now. Why two times thank you okay sorry for cause so I've been working on

01:19.360 --> 01:25.440
the pro connect project Federation project for two and a half years as the friends

01:25.440 --> 01:32.840
developer I mainly work on the Federation part which I will be presenting today I'm not

01:32.880 --> 01:38.560
G.S. developer and I also work on the project in rest. I'm here to share my

01:38.560 --> 01:45.400
perspective on this project is not official set statement please don't fire me if I say

01:45.400 --> 01:56.160
something strange okay we will be talking a lot about service provider and an

01:56.160 --> 02:05.000
identity provider to keep things symbols we can you can think that open ID

02:05.000 --> 02:10.440
providers identity providers and rolling party as service provider sometime I will use

02:10.440 --> 02:18.120
the S.P. for service provider and identity provider I will say EDP so no we can begin

02:18.120 --> 02:24.640
so every day thousands and thousands of public servants need to access to digital

02:24.640 --> 02:30.480
tools for example one very important thing in France we like to take a lift okay we

02:30.480 --> 02:34.440
do to take a lift without connection so pro connect help people to take some

02:34.440 --> 02:40.480
lifts private sector workers and association also may need to access public

02:40.480 --> 02:44.360
service for example as a freelancer when I work for for connect I need to

02:44.360 --> 02:49.960
declare the activity I do I can connect with pro connect to do that pro connect

02:49.960 --> 02:57.440
enable this user to secretly access multiple service through single login using

02:57.440 --> 03:02.480
I say ministerial identity providers but it's not just ministerial identity

03:02.480 --> 03:07.320
provider but to keep it simple we will say that if you let me do it if you again

03:07.320 --> 03:13.440
you can protest immediately and I will go out and in other words pro connect is a

03:13.440 --> 03:18.600
failureated open ID connect identity provider that enable single sign-on to

03:18.600 --> 03:25.960
public service the ministerial identity provider or just them identity provider

03:25.960 --> 03:36.200
call pro connect identity and we'll try to show you how it looks like that we are

03:36.200 --> 03:49.600
no sorry I need to catch you that yeah so we will make a small demo I just

03:49.600 --> 03:55.960
to know someone has already connected by any chance to pro connect on wow cool

03:55.960 --> 04:02.440
cool and here do you know France connect or nobody knows France connect not too

04:02.440 --> 04:10.960
much but okay do you think pro pro connect is better than France connect or why are

04:10.960 --> 04:18.640
you laughing I don't know stay okay demo demo so I will show you this demo we will

04:18.640 --> 04:23.600
use a gem of last suite numeric last suite numeric is a set of open source tool

04:23.600 --> 04:27.960
supported by the French government and design as an alternative to get

04:28.200 --> 04:34.960
the tool we will use today is one of the best it's a visual

04:38.600 --> 04:49.560
I will do that I want to connect with my team already connected I will look

04:49.560 --> 05:01.160
out okay I want to use the visual service to connect to my team so I go on

05:01.160 --> 05:09.640
so connect them I will arrive this is the first first page we can see on pro

05:09.640 --> 05:17.000
connect so for connecting I need the only thing I need to do is to give my

05:17.000 --> 05:23.760
teammate and with my email the pro connect will be able to deduce what

05:23.760 --> 05:29.960
identity provider I should be ready to because I'm not real a public servant I

05:29.960 --> 05:36.000
will be redirected not to a ministerial identity provider but to the other

05:36.000 --> 05:43.920
identity provider the pro connect identity provider so you can see we will try to

05:43.920 --> 05:48.960
harmonize the design so it doesn't look very different and the previous

05:48.960 --> 05:56.640
interface but we are in different your hand so now I just have to prove that I am

05:56.640 --> 06:06.800
why say I am so I will connect and no it won't work and it works so I'm

06:06.800 --> 06:14.160
connected and I can make a video and of course if I go another another tool

06:18.320 --> 06:22.480
without pro connect I will be a public servant I need to access to connect one

06:22.480 --> 06:25.920
time to a tool after I have to go to the other tool to connect again it's not

06:25.920 --> 06:32.720
like that I'm already connected so when I click connected it is called pro

06:32.720 --> 06:36.640
connect and you see yeah you're connected it's there so that's the is it clear we

06:36.640 --> 06:49.760
see a little more okay I use the open source tool for making my presentation

06:49.760 --> 07:05.840
so a little story about oh it appears at first it was in 2016

07:05.840 --> 07:12.080
France connect particularly was lunch and on the other side France

07:12.080 --> 07:16.680
connect particularly were for the every citizen French citizen but there is the other

07:16.680 --> 07:22.440
side for public servant is people think oh we can do a France connect agent that's why

07:22.440 --> 07:27.320
in the club sometimes you see FCA so France public agent for public servant it was just

07:27.320 --> 07:33.880
the concept and for four years it was just the concept and in 2020 some people of

07:33.880 --> 07:38.920
the France connect team say say we can do something we can do a small mock

07:38.920 --> 07:45.160
small mock sorry and the proof of concept you know how it works it becomes not a

07:45.160 --> 07:49.240
proof of concept anymore it becomes a real project so there will be a terrible

07:49.240 --> 07:58.840
infrastructure at first but for 2020 to 2023 the France connect team has succeeded

07:58.840 --> 08:05.720
to do this project and to deploy it and to make something that can be used and it's

08:05.720 --> 08:12.120
in 2023 2020 before pro connect become of an agent connect become pro connect

08:12.120 --> 08:19.560
to 2004 and it becomes independent and at this time it becomes something that's a tool

08:19.560 --> 08:27.400
that's try to be we put some developer on the tool we try to think another infrastructure

08:27.400 --> 08:36.040
of the tool some it has more resources in 2025 there is something very important in our

08:36.040 --> 08:46.680
history of the project we decide to fork with the France connect team it was a fork

08:47.400 --> 08:52.120
firstly it was an infrastructure fork we were on a book so it was not the best

08:52.120 --> 08:58.920
infrastructure at first it was difficult for the DevOps to work with the the pre-existing stack

08:59.480 --> 09:06.200
after we fork it with code and but it's not because we fork we're not still very

09:08.440 --> 09:15.720
thankful to the France connect team and they help us a lot to put the project outside

09:16.280 --> 09:22.840
and to go where we are now since last year we are full project independent autonomous

09:23.400 --> 09:34.040
we are managed by a looperator at the supermarket we are fast growing the project

09:34.760 --> 09:40.840
that's cool for us this day it works we have more than four thousand connection by week

09:42.840 --> 09:49.400
we are around 40 identity providers so it's quite a lot for compared to France

09:49.400 --> 09:57.800
for no purpose just six identity providers we have to to we have to explore more service and

09:57.800 --> 10:03.720
we do not have we cannot have as much users and France connect because our

10:04.520 --> 10:10.440
our user has supposed to be restricted to predict service as a student or someone who works for

10:10.440 --> 10:16.040
public service but for service provider we are very real compared to France connect we have

10:16.040 --> 10:21.960
2603 service provider right now maybe if you have a service provider that can help us you can join us

10:23.640 --> 10:32.920
but actually we are in a time of growth so it induces a lot of problem with the architecture

10:32.920 --> 10:41.080
or with infrastructure or with the code has to be stable external okay

10:41.480 --> 10:52.920
connect service provider and identity provider together as the connector is difficult to

10:52.920 --> 10:58.280
consider it as a standard component only you can actually say oh we are just in between

10:59.000 --> 11:05.160
when an identity provider full you know there is a problem the user they don't see

11:05.160 --> 11:10.680
they don't say oh the identity provider is broken it's not for it's not pro connect full so

11:10.680 --> 11:15.880
you know it's in general say our pro connect is done that's very bad what happened with pro connect

11:15.880 --> 11:22.360
so we are in a trust relationship with the identity provider and we try to think

11:23.080 --> 11:33.000
our project not just to be the identity provider at the end but as connecting service provider

11:33.000 --> 11:37.800
and identity provider where I go with that we have two main kind of mocks service provider and

11:37.800 --> 11:43.560
identity provider mock since the far from France connect we consider the mock as independent

11:43.560 --> 11:51.640
implication this is an opponent is still something that is relative no the mock are very simple

11:51.640 --> 11:56.760
it's very simple express application with minimal code I want to show you just one example

11:56.760 --> 12:02.280
you know that part of code is maybe no no one card one of four of the total code of the

12:02.280 --> 12:08.760
service provider mock we want something very very simple and we use this type of a client

12:08.760 --> 12:14.920
library so the client here we disappointed a library and here we can see how we create the

12:14.920 --> 12:21.000
authorized URL and that's all we don't go on a very something fancy thing we want something not

12:21.000 --> 12:29.080
very beautiful but the point is to be able to have something easy to integrate and that can

12:29.080 --> 12:36.200
help us to test all the cinematics we need before the before the fork the concept was a little different

12:36.840 --> 12:41.560
for us connect a share command or a display libraries with the core we completely change this

12:41.560 --> 12:48.520
padding there are no tele tele tele tele tele tele tele tele tele sorry very good English English

12:49.480 --> 12:57.560
change to so there are no fully autonomous sorry so change we do for a unlink or a display

12:57.560 --> 13:02.280
library is no longer affects the core it was something important I thought that a lot of confusion

13:02.280 --> 13:09.320
of what we change where is the federation but we work the mock help us to test the federation but

13:09.320 --> 13:14.840
it's not the federation for us so migration towards autonomy is still not complete so mocks

13:14.840 --> 13:19.560
still belong to the nest monorepo with the core and shares the same package isn't so it's not

13:19.560 --> 13:26.840
perfect something we've continued to do I want to show how it looks so as I say it's not

13:26.840 --> 13:34.440
something this time to be very pretty it's something we want to be efficient so you are that interface

13:34.440 --> 13:42.840
on this interface you have pre-configure to authorize a call or disconnect test you want to do

13:43.560 --> 13:49.000
you have an integration of the button of course and if you want you can send for the authorize

13:49.000 --> 13:55.240
some specific poems so that's all it's just a generator of authorize your whole with the

13:55.240 --> 14:05.800
configurated possibility this is identity provider mock I don't know identity provider mock

14:05.800 --> 14:12.440
it's if you want you can just very simply add your email the email you want the user has not to

14:12.440 --> 14:17.640
be existing in the in the identity mock and you can connect but if you want you can say no

14:17.640 --> 14:22.680
the identity provider needs to returns error where the lot of tests to do about the error because

14:22.680 --> 14:28.200
finally what we do is connecting people but it's also be able to return correct error when the

14:28.200 --> 14:35.000
people have problems and people can say service provider or an identity provider too and with

14:35.000 --> 14:41.480
if you want you know what we what we do is to return the user info of the identity providers

14:42.520 --> 14:48.360
we can decide what values are returned or not return for the identity provider

14:48.920 --> 14:58.920
of course for doing that we need an administration part if we add the service provider or if we add

14:58.920 --> 15:07.320
an identity provider we have to we have to configure that in an administration part so

15:08.040 --> 15:12.040
service something like that it exists I don't take too much time outside and

15:14.360 --> 15:19.880
so we talk about the mock we talk about the admin but now what we have to do is to talk about

15:19.880 --> 15:30.520
the main part is the core the core be and the mock sorry poca next standardize communication with

15:30.600 --> 15:37.560
identity providers and it defines its own user information model it's intelligently

15:37.560 --> 15:45.240
redirects user to the correct identity provider it works as an IDC provider and the service provider

15:45.240 --> 15:54.440
pro connect is for the service provider it's an identity provider but for I say for the identity

15:54.440 --> 15:59.560
provider it's a service provider and for the service provider it's an identity provider so we have to

15:59.560 --> 16:05.160
be the two at the same time so we integrate the two the library of pember with the

16:05.160 --> 16:11.480
signature and the separator originally originally pro connect inherited its IDC implementation from

16:11.480 --> 16:17.880
France connect where everything was heavily wrapped the paradigm of France connect is to say

16:17.880 --> 16:27.080
if there is a controller with the one and the link error or something like that with pember we

16:27.160 --> 16:33.720
always wrap it that's why the system they want it and sometimes they try to push inside

16:33.720 --> 16:39.080
some custom logic sorry it's a feature for them it's called SSO for example it's when you can

16:39.080 --> 16:45.320
reconnect with the same if you're already connected the other service provider recognizes you as

16:45.320 --> 16:52.280
connected and this is called SSO for this SSO there are ads on middleware around to bring the

16:52.280 --> 16:58.920
pember system and it was you know it's like it is to struggle between the integration

16:58.920 --> 17:05.080
custom integration and the wrapper of pember and one of the most surprising thing maybe

17:05.080 --> 17:10.440
it was the wrapping of the error I think it's still the same now but they decided to wrap all the

17:11.640 --> 17:17.880
all the error generated to pember to be sure the order is a provider to be sure there is no surprise

17:17.880 --> 17:23.160
so every time Pember change is this error they have to reformat all the error and they have to

17:23.160 --> 17:28.760
wrap it up is something we didn't want we say we keep it simple remove remove all the

17:28.760 --> 17:35.160
custom logic first we try to remove the session our custom logic we try to remove the only

17:35.160 --> 17:42.600
error and we try to be close to the pember library we are more or less that so a lot of

17:42.600 --> 17:51.160
part we have done last year is to remove this logic and to adapt it with Pember and there's a

17:51.160 --> 17:59.800
key feature we talk about before it's a red direction part we are finally we are a small

17:59.800 --> 18:05.000
wrapper of all these clients you know this is a provider but we are also a system that

18:05.000 --> 18:13.240
is available to redirect and user to the correct identity provider by this email so I say email

18:13.240 --> 18:18.600
but we expect one part the FQDN of the email and by the FQDN we can say this is your identity

18:18.600 --> 18:31.480
provider and so to be perfectly clear on that so you will show you the last time just with my

18:31.480 --> 18:36.440
email was beta-gouf.fr and I was redirected to pro connect identity if my email is in

18:36.440 --> 18:43.480
certain.fr and will be redirected to the in-sirm identity provider pro connect also support

18:43.480 --> 18:50.600
pesky authentication using the IMR pop for more detail to buy as a year and IMR don't

18:50.600 --> 18:57.160
talk a lot about today we can find this part we have an exciting feature at the moment called

18:57.160 --> 19:06.040
certification of the agent that that that I want to talk today I have limited this subject about

19:06.040 --> 19:17.160
this big presentation so another important part is we return an identity format this format

19:17.160 --> 19:24.520
is used to to return the identity of public servants in a professional context so

19:25.080 --> 19:31.720
pro connect always return one information important it's for this context is the CIRAT

19:31.720 --> 19:37.160
CIRAT is a French business identification number that uniquely identifies the company

19:37.160 --> 19:42.440
establishment and helps to determine the employer associated with it so like that we can say

19:42.440 --> 19:50.040
okay you form the the new mu for the this ministry you are from this company and it's very

19:50.200 --> 19:56.520
important the contextual protect a professional context sorry to know what you belong what is the

19:56.520 --> 20:02.680
company you belong additionally pro connect and under an optional parameter called is service

20:02.680 --> 20:09.720
public service public is are you private sector are you a public servant so we have that for no it's

20:09.720 --> 20:19.240
not perfectly share with service provider but we are working on it and finally there is something

20:19.240 --> 20:24.200
if you are an identity provider you share something you want to share something for some of you

20:24.200 --> 20:29.160
some service provider so you add the information inside you say the information first them you know

20:29.160 --> 20:35.640
something like that you have a parameter we can keep it but we don't publish it we put that in a

20:35.640 --> 20:40.120
custom property and we put all the stuff in custom property so maybe some service provider

20:40.680 --> 20:46.520
expect some specific property from specific identity providers that can use that I don't talk about

20:47.160 --> 20:54.600
for every identity provider we send service provider name we have a lot of documentation I think

20:54.600 --> 21:04.440
I put yeah in this link you can form one information integrating pro connect as a service provider

21:05.320 --> 21:11.000
is integrating a button a button of pro connect identity that makes the authorize

21:11.960 --> 21:20.600
we can try to do it very easily I want it just to say everybody can test it and the LGBT

21:20.600 --> 21:25.640
rules are public administration can integrate the pro connect button software vendor can

21:25.640 --> 21:34.520
can do it if they do it for one the applicant discretion they work for and private organization

21:34.520 --> 21:39.400
can also integrate pro connect button but only to authenticate public sector professional

21:41.880 --> 21:48.680
even if you don't do that you can try there is a soundbox mode if you have a service provider

21:48.680 --> 21:56.280
you can play with pro connect the soundbox pro connect so it's easy if you will have

21:56.280 --> 22:02.040
like the admin I talk before this is the admin for everyone you can under your service provider just for

22:02.040 --> 22:14.680
service provider in just unbox so so application is designed to be easy to install it

22:14.680 --> 22:22.040
is used to compose an all-ducary image we use admin published so it's public there is

22:22.040 --> 22:26.280
the extension percentage is intended to be very simple but there is slightly

22:26.280 --> 22:32.360
then deduce initial steps when you need to add a few environment variables to your shell

22:32.360 --> 22:38.360
this part is not the best part but we will correct it soon I hope after that if you have not

22:38.360 --> 22:42.920
just yarn, ducary and ducary composing style the setup is very fast and set up it's more

22:42.920 --> 22:47.400
the installation because you have nothing to do except to learn just comment and you will have to wait

22:47.400 --> 22:55.960
a little time the image works we we try it mainly on Ubuntu and MacOS so I don't know

22:55.960 --> 23:00.760
for Windows but tell us if you have issue it's supposed to be not difficult to install

23:02.120 --> 23:10.920
I will finish if we open the hood we have just to show you the code everything is on the

23:10.920 --> 23:17.960
repo we have if we take a quick look at the code base we can see the following main folder

23:17.960 --> 23:23.880
and main back ducary pcdb api and quality I want just to focus on the main part

23:23.880 --> 23:31.400
next is the back folder first it's the core of the project so back is what we see before

23:31.400 --> 23:37.080
as a core is the core is the next is the application in a monorepomeride it's in TypeScript

23:40.840 --> 23:46.440
it contains all the logic and the max the unminful there is for the unmin the ducary folder is for

23:46.440 --> 23:52.120
all the local stack and the quality we have not time today to talk but it's a lot of

23:53.080 --> 23:59.800
end-to-end tests that first connect as initiated and where thanks send full to them because

23:59.800 --> 24:05.800
this part is our back bone test part is very useful and it's also test on cucumber so

24:05.800 --> 24:09.640
we use it as documentation to know what project is supposed to be able to do

24:16.760 --> 24:21.480
we try to do a friendly open source release it's probably not perfect but we make effort to

24:21.480 --> 24:26.920
share the code first we try to open and share the most resource possible the code of almost all

24:26.920 --> 24:36.360
repo know in the project can be found in the git repo we try to add clear explanation of

24:36.360 --> 24:41.720
all the pull requests we do and the regular lines are coming to it's important to us to deliver

24:41.720 --> 24:47.560
a git log that can be read and understand we use English in the commentary and best code

24:47.560 --> 24:53.800
can be in the stumble and an eventual external community we hope installation will be for you as

24:53.800 --> 24:59.560
easy as well as I think I am not too little time after so I would have been happy to talk about

24:59.560 --> 25:06.840
accessibility I just like and be fine again I have a subject about the test so just to finish I

25:06.840 --> 25:13.640
would say my presentation was very imperfect and I didn't talk a lot about a lot of things

25:13.720 --> 25:19.000
there just for the main part there is a pro connect identity provider that's very interesting it's

25:19.000 --> 25:25.000
another GitHub repository we have something I didn't talk about about some private network or

25:25.000 --> 25:31.400
area and we have a lot of bridge and it's very fascinating it's very interesting or maybe not

25:31.400 --> 25:36.920
and after we have the hyper tool system it's a custom tool for support to Microsoft is sorry

25:37.080 --> 25:42.760
we have some actually we have a migration for the infrastructure that it's not enough

25:42.760 --> 25:49.400
says but we didn't have for no and we aggregate with our servers too and we have a

25:51.160 --> 25:59.720
very we have some useful option parameters I think it's finished thank you thank you everyone

26:07.880 --> 26:27.800
if I say yes is it okay for an answer oh yes very good no problem with the package on the

26:28.360 --> 26:36.440
I'm sorry the question was isn't it just a problem for security and of course you have seen

26:36.440 --> 26:41.640
the I don't know the name for the package the corruption recently or we have some things like that

26:41.640 --> 26:48.600
we have it's not just security sometimes it's so for the package managing we have a difficulty

26:48.600 --> 26:55.960
to upgrade or we disappointed I don't know if you have that so we tried to live with it and to be

26:56.040 --> 27:03.080
professional we have a pen test we have for pro connect that help us to be more to feel more

27:03.080 --> 27:08.760
confident so thank you

