mirror of
https://github.com/oauth2-proxy/oauth2-proxy.git
synced 2026-10-09 16:05:33 +02:00
feat(entra): add Workload Identity support for Entra ID (#2902)
This commit is contained in:
+59
-12
@@ -46,20 +46,47 @@ func validateProvider(provider options.Provider, providerIDs map[string]struct{}
|
||||
msgs = append(msgs, "provider missing setting: client-id")
|
||||
}
|
||||
|
||||
// login.gov uses a signed JWT to authenticate, not a client-secret
|
||||
if provider.Type != "login.gov" {
|
||||
if provider.ClientSecret == "" && provider.ClientSecretFile == "" {
|
||||
msgs = append(msgs, "missing setting: client-secret or client-secret-file")
|
||||
}
|
||||
if provider.ClientSecret == "" && provider.ClientSecretFile != "" {
|
||||
_, err := os.ReadFile(provider.ClientSecretFile)
|
||||
if err != nil {
|
||||
msgs = append(msgs, "could not read client secret file: "+provider.ClientSecretFile)
|
||||
}
|
||||
}
|
||||
if providerRequiresClientSecret(provider) {
|
||||
msgs = append(msgs, validateClientSecret(provider)...)
|
||||
}
|
||||
|
||||
msgs = append(msgs, validateGoogleConfig(provider)...)
|
||||
if provider.Type == "google" {
|
||||
msgs = append(msgs, validateGoogleConfig(provider)...)
|
||||
}
|
||||
|
||||
if provider.Type == "entra-id" {
|
||||
msgs = append(msgs, validateEntraConfig(provider)...)
|
||||
}
|
||||
|
||||
return msgs
|
||||
}
|
||||
|
||||
// providerRequiresClientSecret checks if provider requires client secret to be set
|
||||
// or it can be omitted in favor of JWT token to authenticate oAuth client
|
||||
func providerRequiresClientSecret(provider options.Provider) bool {
|
||||
if provider.Type == "entra-id" && provider.MicrosoftEntraIDConfig.FederatedTokenAuth {
|
||||
return false
|
||||
}
|
||||
|
||||
if provider.Type == "login.gov" {
|
||||
return false
|
||||
}
|
||||
|
||||
return true
|
||||
}
|
||||
|
||||
func validateClientSecret(provider options.Provider) []string {
|
||||
msgs := []string{}
|
||||
|
||||
if provider.ClientSecret == "" && provider.ClientSecretFile == "" {
|
||||
msgs = append(msgs, "missing setting: client-secret or client-secret-file")
|
||||
}
|
||||
if provider.ClientSecret == "" && provider.ClientSecretFile != "" {
|
||||
_, err := os.ReadFile(provider.ClientSecretFile)
|
||||
if err != nil {
|
||||
msgs = append(msgs, "could not read client secret file: "+provider.ClientSecretFile)
|
||||
}
|
||||
}
|
||||
|
||||
return msgs
|
||||
}
|
||||
@@ -96,3 +123,23 @@ func validateGoogleConfig(provider options.Provider) []string {
|
||||
|
||||
return msgs
|
||||
}
|
||||
|
||||
func validateEntraConfig(provider options.Provider) []string {
|
||||
msgs := []string{}
|
||||
|
||||
if provider.MicrosoftEntraIDConfig.FederatedTokenAuth {
|
||||
federatedTokenPath := os.Getenv("AZURE_FEDERATED_TOKEN_FILE")
|
||||
|
||||
if federatedTokenPath == "" {
|
||||
msgs = append(msgs, "entra federated token authentication is enabled, but AZURE_FEDERATED_TOKEN_FILE variable is not set, check your workload identity configuration.")
|
||||
return msgs
|
||||
}
|
||||
|
||||
_, err := os.ReadFile(federatedTokenPath)
|
||||
if err != nil {
|
||||
msgs = append(msgs, "could not read entra federated token file")
|
||||
}
|
||||
}
|
||||
|
||||
return msgs
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user