<a id="discourse"></a>

# Discourse

<a id="backend-class"></a>

## Backend class

For Django, add this class path to `AUTHENTICATION_BACKENDS`. For other
integrations, use the same class path in the framework-specific backend
setting.

| Backend name   | Class path                                     |
|----------------|------------------------------------------------|
| `discourse`    | `social_core.backends.discourse.DiscourseAuth` |

Discourse can serve as a Single Sign On provider for Authentication.

The backend binds the local association to Discourse’s `external_id`. Email
addresses remain profile data and are not account identifiers because they can
change or later belong to another user.

- Deploy a Discourse application and configure
  <https://meta.discourse.org/t/using-discourse-as-a-sso-provider/32974> the
  application to enable Discourse as an SSO provider.
- Fill in the shared secret and url of the Discourse server in the settings:
  ```default
  SOCIAL_AUTH_DISCOURSE_SECRET = "myDiscourseSecret"
  SOCIAL_AUTH_DISCOURSE_SERVER_URL = "https://my-discourse-site.com"
  ```

<a id="using-multiple-discourse-instances"></a>

## Using multiple Discourse instances

Since Discourse is a distributed application, multiple Discourse instances can
be used as SSO providers. If this is the case, the DiscourseAuth class can be
extended and configured as follows:

```default
from social_core.backends.discourse import DiscourseAuth

class DiscourseAuthFoo(DiscourseAuth):
    name = 'discourse-foo'

class DiscourseAuthBar(DiscourseAuth):
    name = 'discourse-bar'
```

Fill in the settings like so:

```default
SOCIAL_AUTH_DISCOURSE_FOO_SECRET = "myDiscourseFooSecret"
SOCIAL_AUTH_DISCOURSE_FOO_SERVER_URL = "https://my-discourse-foo-site.com"
SOCIAL_AUTH_DISCOURSE_BAR_SECRET = "myDiscourseBarSecret"
SOCIAL_AUTH_DISCOURSE_BAR_SERVER_URL = "https://my-discourse-bar-site.com"
```

<a id="external-memberships"></a>

## External memberships

See [External groups](../groups.html.md) for opt-in extraction, group-based login restrictions, and
local group synchronization. No separate extraction pipeline step is needed.
