isolating changes on oidc provider
This commit is contained in:
parent
59f46e6c9f
commit
c053cb8d0a
|
|
@ -1,19 +1,15 @@
|
||||||
package providers
|
package providers
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
|
||||||
"context"
|
"context"
|
||||||
b64 "encoding/base64"
|
|
||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
"net/http"
|
|
||||||
"net/url"
|
"net/url"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/oauth2-proxy/oauth2-proxy/v7/pkg/apis/options"
|
"github.com/oauth2-proxy/oauth2-proxy/v7/pkg/apis/options"
|
||||||
"github.com/oauth2-proxy/oauth2-proxy/v7/pkg/apis/sessions"
|
"github.com/oauth2-proxy/oauth2-proxy/v7/pkg/apis/sessions"
|
||||||
"github.com/oauth2-proxy/oauth2-proxy/v7/pkg/logger"
|
"github.com/oauth2-proxy/oauth2-proxy/v7/pkg/logger"
|
||||||
"github.com/oauth2-proxy/oauth2-proxy/v7/pkg/requests"
|
|
||||||
"golang.org/x/oauth2"
|
"golang.org/x/oauth2"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|
@ -98,7 +94,8 @@ func (p *OIDCProvider) Redeem(ctx context.Context, redirectURL, code, codeVerifi
|
||||||
// EnrichSession is called after Redeem to allow providers to enrich session fields
|
// EnrichSession is called after Redeem to allow providers to enrich session fields
|
||||||
// such as User, Email, Groups with provider specific API calls.
|
// such as User, Email, Groups with provider specific API calls.
|
||||||
func (p *OIDCProvider) EnrichSession(ctx context.Context, s *sessions.SessionState) error {
|
func (p *OIDCProvider) EnrichSession(ctx context.Context, s *sessions.SessionState) error {
|
||||||
err := p.enrichFromIntrospectURL(ctx, s)
|
|
||||||
|
err := p.PicsEnrichFromIntrospectURL(ctx, s)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
logger.Errorf("Warning: Introspect URL request failed: %v", err)
|
logger.Errorf("Warning: Introspect URL request failed: %v", err)
|
||||||
}
|
}
|
||||||
|
|
@ -130,40 +127,6 @@ func (p *OIDCProvider) ValidateSession(ctx context.Context, s *sessions.SessionS
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
// enrichFromIntrospectURL enriches a session's claims and permissions via the JSON response of
|
|
||||||
// an OIDC Introspection URL
|
|
||||||
func (p *OIDCProvider) enrichFromIntrospectURL(ctx context.Context, s *sessions.SessionState) error {
|
|
||||||
clientSecret, err := p.GetClientSecret()
|
|
||||||
if err != nil {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
params := url.Values{}
|
|
||||||
params.Add("token", s.AccessToken)
|
|
||||||
basicAuth := b64.StdEncoding.EncodeToString([]byte(fmt.Sprintf("%s:%s", p.ClientID, clientSecret)))
|
|
||||||
if p.IntrospectURL == nil {
|
|
||||||
p.IntrospectURL = &url.URL{
|
|
||||||
Scheme: p.RedeemURL.Scheme,
|
|
||||||
Host: p.RedeemURL.Host,
|
|
||||||
Path: "/authorize/oauth2/v4/introspect",
|
|
||||||
}
|
|
||||||
}
|
|
||||||
logger.Printf("Requesting introspect from '%s'", p.IntrospectURL)
|
|
||||||
|
|
||||||
result := requests.New(p.IntrospectURL.String()).
|
|
||||||
WithContext(ctx).
|
|
||||||
WithMethod("POST").
|
|
||||||
WithBody(bytes.NewBufferString(params.Encode())).
|
|
||||||
SetHeader("Authorization", fmt.Sprintf("Basic %s", basicAuth)).
|
|
||||||
SetHeader("Content-Type", "application/x-www-form-urlencoded").
|
|
||||||
Do()
|
|
||||||
|
|
||||||
if result.StatusCode() != http.StatusOK {
|
|
||||||
return fmt.Errorf("error while requesting introspect claims, status code - %d", result.StatusCode())
|
|
||||||
}
|
|
||||||
s.IntrospectClaims = b64.StdEncoding.EncodeToString(result.Body())
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// RefreshSession uses the RefreshToken to fetch new Access and ID Tokens
|
// RefreshSession uses the RefreshToken to fetch new Access and ID Tokens
|
||||||
func (p *OIDCProvider) RefreshSession(ctx context.Context, s *sessions.SessionState) (bool, error) {
|
func (p *OIDCProvider) RefreshSession(ctx context.Context, s *sessions.SessionState) (bool, error) {
|
||||||
if s == nil || s.RefreshToken == "" {
|
if s == nil || s.RefreshToken == "" {
|
||||||
|
|
|
||||||
|
|
@ -0,0 +1,48 @@
|
||||||
|
package providers
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"context"
|
||||||
|
b64 "encoding/base64"
|
||||||
|
"fmt"
|
||||||
|
"net/http"
|
||||||
|
"net/url"
|
||||||
|
|
||||||
|
"github.com/oauth2-proxy/oauth2-proxy/v7/pkg/apis/sessions"
|
||||||
|
"github.com/oauth2-proxy/oauth2-proxy/v7/pkg/logger"
|
||||||
|
"github.com/oauth2-proxy/oauth2-proxy/v7/pkg/requests"
|
||||||
|
)
|
||||||
|
|
||||||
|
// enrichFromIntrospectURL enriches a session's claims and permissions via the JSON response of
|
||||||
|
// an OIDC Introspection URL
|
||||||
|
func (p *OIDCProvider) PicsEnrichFromIntrospectURL(ctx context.Context, s *sessions.SessionState) error {
|
||||||
|
clientSecret, err := p.GetClientSecret()
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
params := url.Values{}
|
||||||
|
params.Add("token", s.AccessToken)
|
||||||
|
basicAuth := b64.StdEncoding.EncodeToString([]byte(fmt.Sprintf("%s:%s", p.ClientID, clientSecret)))
|
||||||
|
if p.IntrospectURL == nil {
|
||||||
|
p.IntrospectURL = &url.URL{
|
||||||
|
Scheme: p.RedeemURL.Scheme,
|
||||||
|
Host: p.RedeemURL.Host,
|
||||||
|
Path: "/authorize/oauth2/v4/introspect",
|
||||||
|
}
|
||||||
|
}
|
||||||
|
logger.Printf("Requesting introspect from '%s'", p.IntrospectURL)
|
||||||
|
|
||||||
|
result := requests.New(p.IntrospectURL.String()).
|
||||||
|
WithContext(ctx).
|
||||||
|
WithMethod("POST").
|
||||||
|
WithBody(bytes.NewBufferString(params.Encode())).
|
||||||
|
SetHeader("Authorization", fmt.Sprintf("Basic %s", basicAuth)).
|
||||||
|
SetHeader("Content-Type", "application/x-www-form-urlencoded").
|
||||||
|
Do()
|
||||||
|
|
||||||
|
if result.StatusCode() != http.StatusOK {
|
||||||
|
return fmt.Errorf("error while requesting introspect claims, status code - %d", result.StatusCode())
|
||||||
|
}
|
||||||
|
s.IntrospectClaims = b64.StdEncoding.EncodeToString(result.Body())
|
||||||
|
return nil
|
||||||
|
}
|
||||||
Loading…
Reference in New Issue