<!--- Provide a general summary of your changes in the Title above --> ## Description Users with different tabs, applications etc will now have their cookie refreshed so when they open other tabs that have other applications, these applications will now be authenticated. Example: I'm doing logging for 1 hour, when I open reporting, hsp reporting will ask for login due to expired cookie. Now this is no longer happer https://www.hsdp.io/documentation/identity-and-access-management-iam/api-documents/resource-reference-api/oauth2-api#/Session%20Refresh/refreshSessionUsingGET New settings introduced: `OAUTH2_PROXY_OIDC_ENABLE_COOKIE_REFRESH` default false `OAUTH2_PROXY_OIDC_COOKIE_REFRESH_NAME` default 'hsdpamcookie' ## Motivation and Context <!--- Why is this change required? What problem does it solve? --> <!--- If it fixes an open issue, please link to the issue here. --> ## How Has This Been Tested? <!--- Please describe in detail how you tested your changes. --> <!--- Include details of your testing environment, and the tests you ran to --> <!--- see how your change affects other areas of the code, etc. --> Tested locally ## Checklist: <!--- Go over all the following points, and put an `x` in all the boxes that apply. --> <!--- If you're unsure about any of these, don't hesitate to ask. We're here to help! --> - [ ] My change requires a change to the documentation or CHANGELOG. - [ ] I have updated the documentation/CHANGELOG accordingly. - [ ] I have created a feature (non-master) branch for my PR. |
||
|---|---|---|
| .github | ||
| build | ||
| contrib | ||
| deploy | ||
| docs | ||
| helm/hsd-oauth-proxy | ||
| pkg | ||
| providers | ||
| testdata | ||
| tools | ||
| .bumpversion.cfg | ||
| .dockerignore | ||
| .editorconfig | ||
| .gitignore | ||
| .golangci.yml | ||
| CHANGELOG.md | ||
| CONTRIBUTING.md | ||
| Directory.Build.props | ||
| Dockerfile | ||
| LICENSE | ||
| MAINTAINERS | ||
| Makefile | ||
| README.md | ||
| RELEASE.md | ||
| SECURITY.md | ||
| VERSION | ||
| dist.sh | ||
| go.mod | ||
| go.sum | ||
| main.go | ||
| main_suite_test.go | ||
| main_test.go | ||
| nsswitch.conf | ||
| oauthproxy.go | ||
| oauthproxy_test.go | ||
| sonar-project.properties | ||
| validator.go | ||
| validator_test.go | ||
| version.go | ||
README.md
A reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain or group.
Note: This repository was forked from bitly/OAuth2_Proxy on 27/11/2018. Versions v3.0.0 and up are from this fork and will have diverged from any changes in the original fork. A list of changes can be seen in the CHANGELOG.
Note: This project was formerly hosted as pusher/oauth2_proxy but has been renamed as of 29/03/2020 to oauth2-proxy/oauth2-proxy.
Going forward, all images shall be available at quay.io/oauth2-proxy/oauth2-proxy and binaries will be named oauth2-proxy.
Installation
-
Choose how to deploy:
a. Download Prebuilt Binary (current release is
v7.4.0)b. Build with
$ go get github.com/oauth2-proxy/oauth2-proxy/v7which will put the binary in$GOROOT/binc. Using the prebuilt docker image quay.io/oauth2-proxy/oauth2-proxy (AMD64, PPC64LE, ARMv6, ARMv8 and ARM64 available)
Prebuilt binaries can be validated by extracting the file and verifying it against the
sha256sum.txtchecksum file provided for each release starting with versionv3.0.0.sha256sum -c sha256sum.txt 2>&1 | grep OK oauth2-proxy-x.y.z.linux-amd64: OK -
Select a Provider and Register an OAuth Application with a Provider
-
Configure OAuth2 Proxy using config file, command line options, or environment variables
-
Configure SSL or Deploy behind a SSL endpoint (example provided for Nginx)
Security
If you are running a version older than v6.0.0 we strongly recommend you please update to a current version. See open redirect vulnerability for details.
Docs
Read the docs on our Docs site.
Configure OAuth Proxy Cookie as Session Cookie
OAuth Proxy Cookie can be configured as session cookie by setting cookie expire time (--cookie-expire) as 0.
This can also be set via environment variable:
- OAUTH2_PROXY_COOKIE_EXPIRE = 0
Getting Involved
If you would like to reach out to the maintainers, come talk to us in the #oauth2-proxy channel in the Gophers slack.
Contributing
Please see our Contributing guidelines. For releasing see our release creation guide.

