
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
ui5-middleware-onelogin
Advanced tools
:wave: This is an open‑source, community‑driven project, developed and actively monitored by members of the UI5 community. You are welcome to use it, report issues, contribute enhancements, and support others in the community.
Middleware for ui5-server, enabling a generic login support.
The middleware will on first request try to login with the provided credentials and save the cookie for further requests. This uses playwright in a headless mode to run the login process. The first request will take longer.
This has been tested with Azure AD, Google, OpenAM and the SAP Gateway login pages.
Merge requests with other login handlers are more than welcome via pull request.
@ui5/cli@3.0.0 (to support specVersion: "3.0"):warning: UI5 CLI Compatibility All releases of this UI5 CLI extension using the major version
3require UI5 CLI V3. Any previous releases below major version3(if available) also support older versions of the UI5 CLI. But the usage of the latest UI5 CLI is strongly recommended!
npm install ui5-middleware-onelogin --save-dev
$yourapp/ui5.yaml)Currently you can define the properties in the configuration (see below) or the following environment variables are used.
string either the url or the hostname and port of the SAP system(optional): string the subdirectory that is appended to the path, defaults to the fiori launchpad at /sap/bc/ui2/flp(optional): string Username to be used to login to the launchpad(optional): stringPassword used to login(optional): boolean use a certificate to login instead of username and password(optional): boolean true will open up the playwright browser so you can see what's going onNB1: If you choose to use the certificate login then check the property AutoSelectCertificateForUrls in chrome://policy if it holds the url pattern for your system. Playwright has an issue to handle the certificate prompt. Another workaround is to set debug and useCertificate to true in the configuration and press ok when the prompt opens
NB2: If your system does not host a fiori launchpad, you will have to adjust the subdirectory to point to a different login protected page. In the case of a MII java stack that hosts an OData service, try setting subdirectory to XMII/PropertyAccessServlet?Mode=List
You can either add the following properties to your .env file, remember to add that to your .gitignore
Use of environment variables or values set in a .env file will be used.
Other options is to either set it in the yaml file or if left blank it will prompt you for the details.
You can choose to just add the url and let the rest be prompted in the terminal

$yourapp/package.json:"devDependencies": {
// ...
"ui5-middleware-onelogin": "*"
// ...
}
$yourapp/ui5.yaml:server:
customMiddleware:
- name: ui5-middleware-onelogin
afterMiddleware: compression
configuration:
path: <Login URL>
username: <Login User>
password: <Login Password>
useCertificate: true / false (use a certificate to login instead of username and password)
debug: true / false (true will open up the playwright browser so you can see what's going on)
query:
sap-client: "206"
This work is dual-licensed under Apache 2.0 and the Derived Beer-ware License. The official license will be Apache 2.0 but finally you can choose between one of them if you use this work.
FAQs
A universal login provider for UI5 CLI
We found that ui5-middleware-onelogin demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.