data:image/s3,"s3://crabby-images/f3fed/f3fed8b829facd1b2702c9586d75fff0923c9d2b" alt="Moodle 3.x Developer's Guide"
Authentication
Log in to your development Moodle as an administrator and, from the Site administration menu, slide down to Plugins, then Authentication, and then click on Manage authentication:
data:image/s3,"s3://crabby-images/7301e/7301edb37b9ba4cf072eb69c6a4f3dc3a8b75892" alt=""
The Manage authentication page lists the available authentication plugins (together with general configuration settings further down the page):
data:image/s3,"s3://crabby-images/ab127/ab1279e2d8c78ca0d290c458acf6597b533354b7" alt=""
Check out the Moodle docs for details of the authentication process at https://docs.moodle.org/dev/Authentication_plugins#Overview_of_Moodle_authentication_process. What is important to realize about the authentication process is that it isn't simply a question of either creating a new user account in Moodle or verifying user credentials against a third-party system.
Let's spend a little time studying the authentication process in detail. Open Eclipse and navigate to login/index.php:
data:image/s3,"s3://crabby-images/60e68/60e68773043e040ae38ca41a616a0c7bd4167a30" alt=""
Authentication begins and the Moodle login page is displayed. It requests the user's credentials:
data:image/s3,"s3://crabby-images/8a263/8a2632c638b44cc2de83cc2e882e77e5cdb8ec82" alt=""
When the login form is submitted, login/index.php loops through the enabled authentication plugins, in order, to fire the login event to each plugin's login hook:
data:image/s3,"s3://crabby-images/b451d/b451d859d74ad4416a5271c12d2fb0cb297ff27b" alt=""
An authentication plugin hook may return user details at this point--typically preventing the user logging in as part of a debugging process or because of a configuration error of some kind. The authentication plugins are called from the authenticate_user_login() function in lib/moodlelib.php. The auth_login() function is called on each authentication plugin:
data:image/s3,"s3://crabby-images/40200/40200f97140454eaf4ef45c91b86b2c2c8ed3712" alt=""
The authentication plugins themselves are to be found in the auth folder; for example, the default authentication method is manual accounts:
data:image/s3,"s3://crabby-images/b2842/b2842c4dd9c5b1cb2774b7117bfe80d2f6d8e2a8" alt=""
Feel free to take a look now at the structure of the manual authentication plugin. Authentication plugins have the same general structure:
data:image/s3,"s3://crabby-images/a4a9b/a4a9b0341e263ab456526ae4c8a62d4d4d782afd" alt=""
The script that actually authenticates, and each plugin contains one, is auth.php. The auth.php file contains a declaration of a class based on auth_plugin_base, the authentication base class declared in /lib/authlib.php. We will be studying the structure and operation of authentication plugins in general (as well as developing our own) in Chapter 6, Managing Users - Letting in the Crowds.