diff --git a/README.md b/README.md index 55d09f33..d8c84a9e 100644 --- a/README.md +++ b/README.md @@ -16,6 +16,11 @@ to validate accounts by email, domain or group. ## Installation 1. Download [Prebuilt Binary](https://github.com/bitly/oauth2_proxy/releases) (current release is `v2.2`) or build with `$ go get github.com/bitly/oauth2_proxy` which will put the binary in `$GOROOT/bin` +Prebuilt binaries can be validated by extracting the file and verifying it against the `sha256sum.txt` checksum file provided for each release starting with version `v2.3`. +``` +sha256sum -c sha256sum.txt 2>&1 | grep OK +oauth2_proxy-2.3.linux-amd64: OK +``` 2. Select a Provider and Register an OAuth Application with a Provider 3. Configure OAuth2 Proxy using config file, command line options, or environment variables 4. Configure SSL or Deploy behind a SSL endpoint (example provided for Nginx) @@ -225,6 +230,7 @@ Usage of oauth2_proxy: -redeem-url string: Token redemption endpoint -redirect-url string: the OAuth Redirect URL. ie: "https://internalapp.yourcompany.com/oauth2/callback" -request-logging: Log requests to stdout (default true) + -request-logging-format: Template for request log lines (see "Logging Format" paragraph below) -resource string: The resource that is protected (Azure AD only) -scope string: OAuth scope specification -set-xauthrequest: set X-Auth-Request-User and X-Auth-Request-Email response headers (useful in Nginx auth_request mode) @@ -362,12 +368,21 @@ following: ## Logging Format -OAuth2 Proxy logs requests to stdout in a format similar to Apache Combined Log. +By default, OAuth2 Proxy logs requests to stdout in a format similar to Apache Combined Log. ``` - [19/Mar/2015:17:20:19 -0400] GET "/path/" HTTP/1.1 "" ``` +If you require a different format than that, you can configure it with the `-request-logging-format` flag. +The default format is configured as follows: + +``` +{{.Client}} - {{.Username}} [{{.Timestamp}}] {{.Host}} {{.RequestMethod}} {{.Upstream}} {{.RequestURI}} {{.Protocol}} {{.UserAgent}} {{.StatusCode}} {{.ResponseSize}} {{.RequestDuration}} +``` + +[See `logMessageData` in `logging_handler.go`](./logging_handler.go) for all available variables. + ## Adding a new Provider Follow the examples in the [`providers` package](providers/) to define a new diff --git a/api/api.go b/api/api.go index f5f6e4d4..e8378ff9 100644 --- a/api/api.go +++ b/api/api.go @@ -11,7 +11,6 @@ import ( ) func Request(req *http.Request) (*simplejson.Json, error) { - log.Printf("New request to: '%s'", req.URL) resp, err := http.DefaultClient.Do(req) if err != nil { log.Printf("%s %s %s", req.Method, req.URL, err) diff --git a/dist.sh b/dist.sh index 18c5d02e..a00318bb 100755 --- a/dist.sh +++ b/dist.sh @@ -5,14 +5,13 @@ set -e DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" echo "working dir $DIR" mkdir -p $DIR/dist -mkdir -p $DIR/.godeps -export GOPATH=$DIR/.godeps:$GOPATH -GOPATH=$DIR/.godeps gpm install +dep ensure || exit 1 os=$(go env GOOS) arch=$(go env GOARCH) version=$(cat $DIR/version.go | grep "const VERSION" | awk '{print $NF}' | sed 's/"//g') goversion=$(go version | awk '{print $3}') +sha256sum=() echo "... running tests" ./test.sh @@ -25,10 +24,22 @@ for os in windows linux darwin; do fi BUILD=$(mktemp -d ${TMPDIR:-/tmp}/oauth2_proxy.XXXXXX) TARGET="oauth2_proxy-$version.$os-$arch.$goversion" + FILENAME="oauth2_proxy-$version.$os-$arch$EXT" GOOS=$os GOARCH=$arch CGO_ENABLED=0 \ - go build -ldflags="-s -w" -o $BUILD/$TARGET/oauth2_proxy$EXT || exit 1 - pushd $BUILD - tar czvf $TARGET.tar.gz $TARGET + go build -ldflags="-s -w" -o $BUILD/$TARGET/$FILENAME || exit 1 + pushd $BUILD/$TARGET + sha256sum+=("$(shasum -a 256 $FILENAME || exit 1)") + cd .. && tar czvf $TARGET.tar.gz $TARGET mv $TARGET.tar.gz $DIR/dist popd done + +checksum_file="sha256sum.txt" +cd $DIR/dist +if [ -f $checksum_file ]; then + rm $checksum_file +fi +touch $checksum_file +for checksum in "${sha256sum[@]}"; do + echo "$checksum" >> $checksum_file +done diff --git a/logging_handler.go b/logging_handler.go index 17fca977..540b5409 100644 --- a/logging_handler.go +++ b/logging_handler.go @@ -9,9 +9,14 @@ import ( "net" "net/http" "net/url" + "text/template" "time" ) +const ( + defaultRequestLoggingFormat = "{{.Client}} - {{.Username}} [{{.Timestamp}}] {{.Host}} {{.RequestMethod}} {{.Upstream}} {{.RequestURI}} {{.Protocol}} {{.UserAgent}} {{.StatusCode}} {{.ResponseSize}} {{.RequestDuration}}" +) + // responseLogger is wrapper of http.ResponseWriter that keeps track of its HTTP status // code and body size type responseLogger struct { @@ -64,15 +69,38 @@ func (l *responseLogger) Size() int { return l.size } -// loggingHandler is the http.Handler implementation for LoggingHandlerTo and its friends -type loggingHandler struct { - writer io.Writer - handler http.Handler - enabled bool +// logMessageData is the container for all values that are available as variables in the request logging format. +// All values are pre-formatted strings so it is easy to use them in the format string. +type logMessageData struct { + Client, + Host, + Protocol, + RequestDuration, + RequestMethod, + RequestURI, + ResponseSize, + StatusCode, + Timestamp, + Upstream, + UserAgent, + Username string } -func LoggingHandler(out io.Writer, h http.Handler, v bool) http.Handler { - return loggingHandler{out, h, v} +// loggingHandler is the http.Handler implementation for LoggingHandlerTo and its friends +type loggingHandler struct { + writer io.Writer + handler http.Handler + enabled bool + logTemplate *template.Template +} + +func LoggingHandler(out io.Writer, h http.Handler, v bool, requestLoggingTpl string) http.Handler { + return loggingHandler{ + writer: out, + handler: h, + enabled: v, + logTemplate: template.Must(template.New("request-log").Parse(requestLoggingTpl)), + } } func (h loggingHandler) ServeHTTP(w http.ResponseWriter, req *http.Request) { @@ -83,14 +111,13 @@ func (h loggingHandler) ServeHTTP(w http.ResponseWriter, req *http.Request) { if !h.enabled { return } - logLine := buildLogLine(logger.authInfo, logger.upstream, req, url, t, logger.Status(), logger.Size()) - h.writer.Write(logLine) + h.writeLogLine(logger.authInfo, logger.upstream, req, url, t, logger.Status(), logger.Size()) } // Log entry for req similar to Apache Common Log Format. // ts is the timestamp with which the entry should be logged. // status, size are used to provide the response HTTP status and size. -func buildLogLine(username, upstream string, req *http.Request, url url.URL, ts time.Time, status int, size int) []byte { +func (h loggingHandler) writeLogLine(username, upstream string, req *http.Request, url url.URL, ts time.Time, status int, size int) { if username == "" { username = "-" } @@ -114,19 +141,20 @@ func buildLogLine(username, upstream string, req *http.Request, url url.URL, ts duration := float64(time.Now().Sub(ts)) / float64(time.Second) - logLine := fmt.Sprintf("%s - %s [%s] %s %s %s %q %s %q %d %d %0.3f\n", - client, - username, - ts.Format("02/Jan/2006:15:04:05 -0700"), - req.Host, - req.Method, - upstream, - url.RequestURI(), - req.Proto, - req.UserAgent(), - status, - size, - duration, - ) - return []byte(logLine) + h.logTemplate.Execute(h.writer, logMessageData{ + Client: client, + Host: req.Host, + Protocol: req.Proto, + RequestDuration: fmt.Sprintf("%0.3f", duration), + RequestMethod: req.Method, + RequestURI: fmt.Sprintf("%q", url.RequestURI()), + ResponseSize: fmt.Sprintf("%d", size), + StatusCode: fmt.Sprintf("%d", status), + Timestamp: ts.Format("02/Jan/2006:15:04:05 -0700"), + Upstream: upstream, + UserAgent: fmt.Sprintf("%q", req.UserAgent()), + Username: username, + }) + + h.writer.Write([]byte("\n")) } diff --git a/logging_handler_test.go b/logging_handler_test.go new file mode 100644 index 00000000..9717cd6e --- /dev/null +++ b/logging_handler_test.go @@ -0,0 +1,42 @@ +package main + +import ( + "bytes" + "fmt" + "net/http" + "net/http/httptest" + "testing" + "time" +) + +func TestLoggingHandler_ServeHTTP(t *testing.T) { + ts := time.Now() + + tests := []struct { + Format, + ExpectedLogMessage string + }{ + {defaultRequestLoggingFormat, fmt.Sprintf("127.0.0.1 - - [%s] test-server GET - \"/foo/bar\" HTTP/1.1 \"\" 200 4 0.000\n", ts.Format("02/Jan/2006:15:04:05 -0700"))}, + {"{{.RequestMethod}}", "GET\n"}, + } + + for _, test := range tests { + buf := bytes.NewBuffer(nil) + handler := func(w http.ResponseWriter, req *http.Request) { + w.Write([]byte("test")) + } + + h := LoggingHandler(buf, http.HandlerFunc(handler), true, test.Format) + + r, _ := http.NewRequest("GET", "/foo/bar", nil) + r.RemoteAddr = "127.0.0.1" + r.Host = "test-server" + + h.ServeHTTP(httptest.NewRecorder(), r) + + actual := buf.String() + if actual != test.ExpectedLogMessage { + t.Errorf("Log message was\n%s\ninstead of expected \n%s", actual, test.ExpectedLogMessage) + } + } +} diff --git a/main.go b/main.go index f39e62a9..5363b8d1 100644 --- a/main.go +++ b/main.go @@ -20,6 +20,7 @@ func main() { emailDomains := StringArray{} upstreams := StringArray{} skipAuthRegex := StringArray{} + googleGroups := StringArray{} permittedGroups := StringArray{} config := flagSet.String("config", "", "path to config file") @@ -50,6 +51,7 @@ func main() { flagSet.String("azure-tenant", "common", "go to a tenant-specific or common (tenant-independent) endpoint.") flagSet.String("github-org", "", "restrict logins to members of this organisation") flagSet.String("github-team", "", "restrict logins to members of this team") + flagSet.Var(&googleGroups, "google-group", "restrict logins to members of this google group (may be given multiple times).") flagSet.String("google-admin-email", "", "the google admin to impersonate for api calls") flagSet.String("google-service-account-json", "", "the path to the service account json credentials") flagSet.String("client-id", "", "the OAuth Client ID: ie: \"123456.apps.googleusercontent.com\"") @@ -70,6 +72,7 @@ func main() { flagSet.Bool("cookie-httponly", true, "set HttpOnly cookie flag") flagSet.Bool("request-logging", true, "Log requests to stdout") + flagSet.String("request-logging-format", defaultRequestLoggingFormat, "Template for log lines") flagSet.String("provider", "google", "OAuth provider") flagSet.String("oidc-issuer-url", "", "OpenID Connect issuer URL (ie: https://accounts.google.com)") @@ -128,7 +131,7 @@ func main() { } s := &Server{ - Handler: LoggingHandler(os.Stdout, oauthproxy, opts.RequestLogging), + Handler: LoggingHandler(os.Stdout, oauthproxy, opts.RequestLogging, opts.RequestLoggingFormat), Opts: opts, } s.ListenAndServe() diff --git a/oauthproxy.go b/oauthproxy.go index 83c6973e..81980d9e 100644 --- a/oauthproxy.go +++ b/oauthproxy.go @@ -525,14 +525,9 @@ func (p *OAuthProxy) OAuthStart(rw http.ResponseWriter, req *http.Request) { } func (p *OAuthProxy) OAuthCallback(rw http.ResponseWriter, req *http.Request) { - log.Printf("[OAuthCallback] Starting OAuthCallback") - remoteAddr := getRemoteAddr(req) - log.Printf("[OAuthCallback] remoteAddr = %s", remoteAddr) - // finish the oauth cycle - log.Printf("[OAuthCallback] req.ParseForm") err := req.ParseForm() if err != nil { p.ErrorPage(rw, 500, "Internal Error", err.Error()) @@ -541,8 +536,6 @@ func (p *OAuthProxy) OAuthCallback(rw http.ResponseWriter, req *http.Request) { errorString := req.Form.Get("error") if errorString != "" { - log.Printf("[OAuthCallback] error in parsed form (REQ.Form) : %s", req.Form) - log.Printf("[OAuthCallback] error in parsed form (REQ.error string) : %s", errorString) p.ErrorPage(rw, 403, "Permission Denied", errorString) return } diff --git a/options.go b/options.go index 19ac8c2a..bb07d80f 100644 --- a/options.go +++ b/options.go @@ -34,6 +34,7 @@ type Options struct { EmailDomains []string `flag:"email-domain" cfg:"email_domains"` GitHubOrg string `flag:"github-org" cfg:"github_org"` GitHubTeam string `flag:"github-team" cfg:"github_team"` + GoogleGroups []string `flag:"google-group" cfg:"google_group"` GoogleAdminEmail string `flag:"google-admin-email" cfg:"google_admin_email"` GoogleServiceAccountJSON string `flag:"google-service-account-json" cfg:"google_service_account_json"` HtpasswdFile string `flag:"htpasswd-file" cfg:"htpasswd_file"` @@ -77,7 +78,8 @@ type Options struct { Scope string `flag:"scope" cfg:"scope"` ApprovalPrompt string `flag:"approval-prompt" cfg:"approval_prompt"` - RequestLogging bool `flag:"request-logging" cfg:"request_logging"` + RequestLogging bool `flag:"request-logging" cfg:"request_logging"` + RequestLoggingFormat string `flag:"request-logging-format" cfg:"request_logging_format"` SignatureKey string `flag:"signature-key" cfg:"signature_key" env:"OAUTH2_PROXY_SIGNATURE_KEY"` @@ -97,27 +99,28 @@ type SignatureData struct { func NewOptions() *Options { return &Options{ - ProxyPrefix: "/oauth2", - HttpAddress: "127.0.0.1:4180", - HttpsAddress: ":443", - DisplayHtpasswdForm: true, - CookieName: "_oauth2_proxy", - CookieSecure: true, - CookieHttpOnly: true, - CookieExpire: time.Duration(168) * time.Hour, - CookieRefresh: time.Duration(0), - SetXAuthRequest: false, - SkipAuthPreflight: false, - PassBasicAuth: true, - PassUserHeaders: true, - PassGroups: false, - FilterGroups: "", - GroupsDelimiter: "|", - PassAccessToken: false, - PassHostHeader: true, - ApprovalPrompt: "", - RequestLogging: true, - Provider: "google", + ProxyPrefix: "/oauth2", + HttpAddress: "127.0.0.1:4180", + HttpsAddress: ":443", + Provider: "google", + DisplayHtpasswdForm: true, + CookieName: "_oauth2_proxy", + CookieSecure: true, + CookieHttpOnly: true, + CookieExpire: time.Duration(168) * time.Hour, + CookieRefresh: time.Duration(0), + SetXAuthRequest: false, + SkipAuthPreflight: false, + PassBasicAuth: true, + PassUserHeaders: true, + PassGroups: false, + FilterGroups: "", + GroupsDelimiter: "|", + PassAccessToken: false, + PassHostHeader: true, + ApprovalPrompt: "force", + RequestLogging: true, + RequestLoggingFormat: defaultRequestLoggingFormat, } } @@ -227,6 +230,18 @@ func (o *Options) Validate() error { o.CookieExpire.String())) } + // Backwards compatibility. We can still use `GoogleGroups` if google is used as provider + if len(o.GoogleGroups) > 0 { + if o.Provider != "google" { + msgs = append(msgs, "incorrect setting: 'google-group' parameter could be used within google provider only") + } + if len(o.PermitGroups) > 0 { + msgs = append(msgs, "incorrect setting: 'google-group' and 'permit-groups' can't be defined together") + } else { + o.PermitGroups = o.GoogleGroups + } + } + if o.Provider == "google" { if len(o.PermitGroups) > 0 || o.GoogleAdminEmail != "" || o.GoogleServiceAccountJSON != "" { if len(o.PermitGroups) < 1 { diff --git a/providers/github.go b/providers/github.go index f3af86fe..26526ce7 100644 --- a/providers/github.go +++ b/providers/github.go @@ -8,6 +8,7 @@ import ( "net/http" "net/url" "path" + "strconv" "strings" ) @@ -61,36 +62,51 @@ func (p *GitHubProvider) hasOrg(accessToken string) (bool, error) { Login string `json:"login"` } - params := url.Values{ - "limit": {"100"}, + type orgsPage []struct { + Login string `json:"login"` } - endpoint := &url.URL{ - Scheme: p.ValidateURL.Scheme, - Host: p.ValidateURL.Host, - Path: path.Join(p.ValidateURL.Path, "/user/orgs"), - RawQuery: params.Encode(), - } - req, _ := http.NewRequest("GET", endpoint.String(), nil) - req.Header.Set("Accept", "application/vnd.github.v3+json") - req.Header.Set("Authorization", fmt.Sprintf("token %s", accessToken)) - resp, err := http.DefaultClient.Do(req) - if err != nil { - return false, err - } + pn := 1 + for { + params := url.Values{ + "limit": {"200"}, + "page": {strconv.Itoa(pn)}, + } - body, err := ioutil.ReadAll(resp.Body) - resp.Body.Close() - if err != nil { - return false, err - } - if resp.StatusCode != 200 { - return false, fmt.Errorf( - "got %d from %q %s", resp.StatusCode, endpoint.String(), body) - } + endpoint := &url.URL{ + Scheme: p.ValidateURL.Scheme, + Host: p.ValidateURL.Host, + Path: path.Join(p.ValidateURL.Path, "/user/orgs"), + RawQuery: params.Encode(), + } + req, _ := http.NewRequest("GET", endpoint.String(), nil) + req.Header.Set("Accept", "application/vnd.github.v3+json") + req.Header.Set("Authorization", fmt.Sprintf("token %s", accessToken)) + resp, err := http.DefaultClient.Do(req) + if err != nil { + return false, err + } - if err := json.Unmarshal(body, &orgs); err != nil { - return false, err + body, err := ioutil.ReadAll(resp.Body) + resp.Body.Close() + if err != nil { + return false, err + } + if resp.StatusCode != 200 { + return false, fmt.Errorf( + "got %d from %q %s", resp.StatusCode, endpoint.String(), body) + } + + var op orgsPage + if err := json.Unmarshal(body, &op); err != nil { + return false, err + } + if len(op) == 0 { + break + } + + orgs = append(orgs, op...) + pn += 1 } var presentOrgs []string @@ -118,7 +134,7 @@ func (p *GitHubProvider) hasOrgAndTeam(accessToken string) (bool, error) { } params := url.Values{ - "limit": {"100"}, + "limit": {"200"}, } endpoint := &url.URL{ diff --git a/providers/github_test.go b/providers/github_test.go index 8080525b..48101825 100644 --- a/providers/github_test.go +++ b/providers/github_test.go @@ -27,23 +27,32 @@ func testGitHubProvider(hostname string) *GitHubProvider { return p } -func testGitHubBackend(payload string) *httptest.Server { - pathToQueryMap := map[string]string{ - "/user": "", - "/user/emails": "", +func testGitHubBackend(payload []string) *httptest.Server { + pathToQueryMap := map[string][]string{ + "/user": []string{""}, + "/user/emails": []string{""}, + "/user/orgs": []string{"limit=200&page=1", "limit=200&page=2", "limit=200&page=3"}, } return httptest.NewServer(http.HandlerFunc( func(w http.ResponseWriter, r *http.Request) { url := r.URL query, ok := pathToQueryMap[url.Path] + validQuery := false + index := 0 + for i, q := range query { + if q == url.RawQuery { + validQuery = true + index = i + } + } if !ok { w.WriteHeader(404) - } else if url.RawQuery != query { + } else if !validQuery { w.WriteHeader(404) } else { w.WriteHeader(200) - w.Write([]byte(payload)) + w.Write([]byte(payload[index])) } })) } @@ -89,7 +98,7 @@ func TestGitHubProviderOverrides(t *testing.T) { } func TestGitHubProviderGetEmailAddress(t *testing.T) { - b := testGitHubBackend(`[ {"email": "michael.bland@gsa.gov", "primary": true} ]`) + b := testGitHubBackend([]string{`[ {"email": "michael.bland@gsa.gov", "primary": true} ]`}) defer b.Close() bURL, _ := url.Parse(b.URL) @@ -101,10 +110,28 @@ func TestGitHubProviderGetEmailAddress(t *testing.T) { assert.Equal(t, "michael.bland@gsa.gov", email) } +func TestGitHubProviderGetEmailAddressWithOrg(t *testing.T) { + b := testGitHubBackend([]string{ + `[ {"email": "michael.bland@gsa.gov", "primary": true, "login":"testorg"} ]`, + `[ {"email": "michael.bland1@gsa.gov", "primary": true, "login":"testorg1"} ]`, + `[ ]`, + }) + defer b.Close() + + bURL, _ := url.Parse(b.URL) + p := testGitHubProvider(bURL.Host) + p.Org = "testorg1" + + session := &SessionState{AccessToken: "imaginary_access_token"} + email, err := p.GetEmailAddress(session) + assert.Equal(t, nil, err) + assert.Equal(t, "michael.bland@gsa.gov", email) +} + // Note that trying to trigger the "failed building request" case is not // practical, since the only way it can fail is if the URL fails to parse. func TestGitHubProviderGetEmailAddressFailedRequest(t *testing.T) { - b := testGitHubBackend("unused payload") + b := testGitHubBackend([]string{"unused payload"}) defer b.Close() bURL, _ := url.Parse(b.URL) @@ -120,7 +147,7 @@ func TestGitHubProviderGetEmailAddressFailedRequest(t *testing.T) { } func TestGitHubProviderGetEmailAddressEmailNotPresentInPayload(t *testing.T) { - b := testGitHubBackend("{\"foo\": \"bar\"}") + b := testGitHubBackend([]string{"{\"foo\": \"bar\"}"}) defer b.Close() bURL, _ := url.Parse(b.URL) @@ -133,7 +160,7 @@ func TestGitHubProviderGetEmailAddressEmailNotPresentInPayload(t *testing.T) { } func TestGitHubProviderGetUserName(t *testing.T) { - b := testGitHubBackend(`{"email": "michael.bland@gsa.gov", "login": "mbland"}`) + b := testGitHubBackend([]string{`{"email": "michael.bland@gsa.gov", "login": "mbland"}`}) defer b.Close() bURL, _ := url.Parse(b.URL)