German integration- Univention UCS@school - ID Broker Connector (Sysadmin)
TABLE OF CONTENTS
- 1 Overview
- 2 How synchronisation works
- 3 User management
- 4 Hierarchy management
- 5 Single sign-on
- 6 Known limitations
- 7 Support and contact points
Introduction
This article describes the Univention ID Broker integration with itslearning. It covers how synchronisation is triggered, what is synchronised for students and teachers, single sign-on, and the current limitations of the integration.
Important: This article covers the ID Broker connector only. If your school uses the Itswizard connector or the Dataduck connector for UCS@school, see the relevant article for that integration instead.
1 Overview
The Univention ID Broker provides user authentication and authorisation, single sign-on, user data management and synchronisation, and role-based access control between UCS@school and itslearning.
Unlike other Univention integrations, synchronisation with ID Broker does not run on a schedule or as a background task. Instead, it runs in the context of each user during their login process, and changes are processed immediately at that point.
2 How synchronisation works
2.1 Synchronisation scope by role
| Role | What is synchronised at login |
|---|---|
| Student | Only the student's own account and class memberships. |
| Teacher | The teacher's own account, and all of their classes, including student memberships in those classes |
Important: Students and teachers must have class memberships in order to be synchronised. Further, the user accounts are created when they log in for the first time.
2.2 Synchronising an entire school
Important: Because synchronisation is triggered by login and scoped by role, a complete synchronisation across an entire school requires a login from a dedicated account with access to all classes. Without this, some classes or accounts may not yet be reflected in itslearning.
3 User management
| Action | Behaviour |
|---|---|
| Creation | Users are automatically created in itslearning the first time their data is returned from ID Broker. |
| Updates | User data is synchronised during each login. |
| Deletion | Not currently handled, due to limitations in the source system. |
4 Hierarchy management
| Action | Behaviour |
|---|---|
| Creation | Hierarchies are automatically created in itslearning when classes and courses are received from ID Broker. |
| Updates | Synchronised during the login process, based on the user's role. A student login updates only their own class memberships. A teacher login updates all of their associated classes and courses. |
| Deletion | Not currently handled, due to limitations in the source API. |
5 Single sign-on
Single sign-on is handled through the EduSync middleware, which accesses the API from ID Broker and synchronises the data to itslearning.
6 Known limitations
Important:
- As a general rule, users are created when they log in the first time and only if they have one ore more class membership. A teacher login will also trigger creating students in the teachers class(es).
- User deletion is not currently handled. A user removed in UCS@school will not automatically be removed or deactivated in itslearning.
- Hierarchy deletion is not currently handled, for the same reason.
- A complete synchronisation for an entire school requires a login from an account with access to all classes.