feat(ap4): integrate nginx auth_request

This commit is contained in:
donghyeon-ka
2026-07-25 14:55:04 +09:00
parent 5ce47689a9
commit 357b7f927b
7 changed files with 123 additions and 26 deletions
+4 -2
View File
@@ -107,8 +107,10 @@ gitignored `build/keycloak-export/`에 권한 `0600`으로만 저장됩니다.
``` ```
첫 feature에서는 oauth2-proxy를 `http://localhost:4180`에 직접 노출해 첫 feature에서는 oauth2-proxy를 `http://localhost:4180`에 직접 노출해
OIDC redirect/PKCE/callback과 forwarded-user를 분리 확인합니다. 최종 OIDC redirect/PKCE/callback과 forwarded-user를 분리 확인합니다. 두 번째
구성은 `http://localhost:8088` Nginx 단일 진입점으로 사용합니다. feature부터 `http://localhost:8088` Nginx 단일 진입점이며, 내부
`auth_request`는 브라우저 요청을 login 302로, API 요청을 JSON 401로
구분합니다. 최종 feature에서는 backend의 호스트 노출도 제거합니다.
자세한 내용은 자세한 내용은
[`docs/ap4-edge-forward-auth.md`](docs/ap4-edge-forward-auth.md)를 [`docs/ap4-edge-forward-auth.md`](docs/ap4-edge-forward-auth.md)를
참고하세요. 참고하세요.
+12 -6
View File
@@ -98,11 +98,13 @@ services:
- --oidc-jwks-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/certs - --oidc-jwks-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/certs
- --profile-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo - --profile-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo
- --validate-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo - --validate-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo
- --redirect-url=http://localhost:4180/oauth2/callback - --redirect-url=http://localhost:8088/oauth2/callback
- --upstream=http://app:8081 - --upstream=http://app:8081
- --email-domain=* - --email-domain=*
- --scope=openid profile email - --scope=openid profile email
- --code-challenge-method=S256 - --code-challenge-method=S256
- --reverse-proxy=true
- --trusted-proxy-ip=172.30.40.10/32
- --cookie-name=AP4_SESSION - --cookie-name=AP4_SESSION
- --cookie-secure=false - --cookie-secure=false
- --cookie-samesite=lax - --cookie-samesite=lax
@@ -110,14 +112,14 @@ services:
- --skip-provider-button=true - --skip-provider-button=true
- --set-xauthrequest=true - --set-xauthrequest=true
- --pass-user-headers=true - --pass-user-headers=true
- --whitelist-domain=localhost:4180 - --whitelist-domain=localhost:8088
- --whitelist-domain=localhost:8080 - --whitelist-domain=localhost:8080
environment: environment:
OAUTH2_PROXY_CLIENT_ID: edge-proxy OAUTH2_PROXY_CLIENT_ID: edge-proxy
OAUTH2_PROXY_CLIENT_SECRET: ${EDGE_PROXY_CLIENT_SECRET:?set EDGE_PROXY_CLIENT_SECRET in .env} OAUTH2_PROXY_CLIENT_SECRET: ${EDGE_PROXY_CLIENT_SECRET:?set EDGE_PROXY_CLIENT_SECRET in .env}
OAUTH2_PROXY_COOKIE_SECRET: ${OAUTH2_PROXY_COOKIE_SECRET:?set OAUTH2_PROXY_COOKIE_SECRET in .env} OAUTH2_PROXY_COOKIE_SECRET: ${OAUTH2_PROXY_COOKIE_SECRET:?set OAUTH2_PROXY_COOKIE_SECRET in .env}
ports: expose:
- "127.0.0.1:4180:4180" - "4180"
depends_on: depends_on:
keycloak: keycloak:
condition: service_healthy condition: service_healthy
@@ -142,7 +144,7 @@ services:
ports: ports:
- "127.0.0.1:${NGINX_PORT:-8088}:80" - "127.0.0.1:${NGINX_PORT:-8088}:80"
depends_on: depends_on:
app: oauth2-proxy:
condition: service_healthy condition: service_healthy
healthcheck: healthcheck:
test: test:
@@ -152,7 +154,8 @@ services:
timeout: 5s timeout: 5s
retries: 12 retries: 12
networks: networks:
- keycloak-net keycloak-net:
ipv4_address: 172.30.40.10
restart: unless-stopped restart: unless-stopped
volumes: volumes:
@@ -162,3 +165,6 @@ volumes:
networks: networks:
keycloak-net: keycloak-net:
driver: bridge driver: bridge
ipam:
config:
- subnet: 172.30.40.0/24
+20
View File
@@ -29,3 +29,23 @@ loopback에 publish되어 있습니다. 따라서 로컬에서 직접
`X-Forwarded-User: spoofed-admin`을 보내면 우회가 재현됩니다. 이후 `X-Forwarded-User: spoofed-admin`을 보내면 우회가 재현됩니다. 이후
Nginx `auth_request` 통합을 거쳐 최종 feature에서 backend no-publish와 Nginx `auth_request` 통합을 거쳐 최종 feature에서 backend no-publish와
내부 shared-secret 검증을 함께 적용합니다. 내부 shared-secret 검증을 함께 적용합니다.
## 두 번째 단계: Nginx `auth_request`
`feature/keycloak-nginx-auth-request-integration`부터 외부 진입점은
`http://localhost:8088` Nginx 하나입니다. oauth2-proxy의 4180 포트는
Compose 네트워크에만 expose됩니다.
- Nginx의 정확 일치 `location = /oauth2/auth``internal`이라 외부에서
직접 호출할 수 없습니다.
- 인증 서브리퀘스트에는 본문을 보내지 않고 `Content-Length`
비웁니다.
- 일반 브라우저 요청의 401은 `/oauth2/start` 302로 변환합니다.
- API 요청 `/api/edge`는 redirect하지 않고 JSON 401을 반환합니다.
- 인증 성공 시 oauth2-proxy의 `X-Auth-Request-User`와 email만 backend로
전달합니다.
Nginx 컨테이너 IP를 전용 Compose subnet에서 고정하고 oauth2-proxy의
trusted proxy를 그 단일 IP로 제한합니다. 다만 이 단계에서는 backend
8081이 로컬 호스트에 열려 있어 신뢰 헤더를 직접 위조할 수 있습니다.
그 재현 조건은 마지막 feature에서 제거합니다.
+26 -9
View File
@@ -4,6 +4,9 @@ import { chromium } from "playwright-core";
const password = process.env.E2E_PASSWORD; const password = process.env.E2E_PASSWORD;
assert.ok(password, "E2E_PASSWORD must be set"); assert.ok(password, "E2E_PASSWORD must be set");
const edgeBaseUrl = "http://localhost:8088";
const edgeEntryUrl = `${edgeBaseUrl}/`;
async function completeKeycloakLogin(page) { async function completeKeycloakLogin(page) {
for (let attempt = 1; attempt <= 2; attempt += 1) { for (let attempt = 1; attempt <= 2; attempt += 1) {
await page.locator("#username").fill( await page.locator("#username").fill(
@@ -13,11 +16,11 @@ async function completeKeycloakLogin(page) {
await page.locator("#kc-login").click(); await page.locator("#kc-login").click();
await page.waitForLoadState("domcontentloaded"); await page.waitForLoadState("domcontentloaded");
if (page.url() === "http://localhost:4180/edge/me") { if (page.url() === edgeEntryUrl) {
return; return;
} }
if (attempt === 1) { if (attempt === 1) {
await page.goto("http://localhost:4180/oauth2/start?rd=%2Fedge%2Fme"); await page.goto(`${edgeBaseUrl}/oauth2/start?rd=${encodeURIComponent(edgeEntryUrl)}`);
await page.waitForURL(/localhost:8080/u); await page.waitForURL(/localhost:8080/u);
} }
} }
@@ -40,7 +43,7 @@ try {
const edgeResponsePromise = page.waitForResponse( const edgeResponsePromise = page.waitForResponse(
(response) => (response) =>
response.url() === "http://localhost:4180/edge/me" && response.url() === edgeEntryUrl &&
response.status() === 302, response.status() === 302,
); );
const authorizationRequestPromise = page.waitForRequest((request) => const authorizationRequestPromise = page.waitForRequest((request) =>
@@ -48,7 +51,7 @@ try {
"/protocol/openid-connect/auth?approval_prompt=", "/protocol/openid-connect/auth?approval_prompt=",
), ),
); );
await page.goto("http://localhost:4180/edge/me"); await page.goto(edgeEntryUrl);
const unauthenticatedEdgeResponse = await edgeResponsePromise; const unauthenticatedEdgeResponse = await edgeResponsePromise;
assert.equal(unauthenticatedEdgeResponse.status(), 302); assert.equal(unauthenticatedEdgeResponse.status(), 302);
@@ -63,10 +66,10 @@ try {
const edgeIdentity = JSON.parse(await page.locator("body").innerText()); const edgeIdentity = JSON.parse(await page.locator("body").innerText());
assert.equal(edgeIdentity.pattern, "AP4-edge-forward-auth"); assert.equal(edgeIdentity.pattern, "AP4-edge-forward-auth");
assert.ok(edgeIdentity.user); assert.ok(edgeIdentity.user);
assert.equal(edgeIdentity.identityHeader, "X-Forwarded-User"); assert.equal(edgeIdentity.identityHeader, "X-Auth-Request-User");
const callbackRequest = browserRequests.find(({ url }) => const callbackRequest = browserRequests.find(({ url }) =>
url.startsWith("http://localhost:4180/oauth2/callback?"), url.startsWith(`${edgeBaseUrl}/oauth2/callback?`),
); );
assert.ok(callbackRequest); assert.ok(callbackRequest);
assert.equal(callbackRequest.method, "GET"); assert.equal(callbackRequest.method, "GET");
@@ -78,7 +81,7 @@ try {
"the confidential token exchange must be server-to-server", "the confidential token exchange must be server-to-server",
); );
const cookies = await context.cookies("http://localhost:4180/"); const cookies = await context.cookies(edgeEntryUrl);
const sessionCookie = cookies.find((cookie) => cookie.name === "AP4_SESSION"); const sessionCookie = cookies.find((cookie) => cookie.name === "AP4_SESSION");
assert.ok(sessionCookie); assert.ok(sessionCookie);
assert.equal(sessionCookie.httpOnly, true); assert.equal(sessionCookie.httpOnly, true);
@@ -94,17 +97,31 @@ try {
assert.deepEqual(storage.sessionStorage, []); assert.deepEqual(storage.sessionStorage, []);
assert.equal(storage.readableCookies.includes("AP4_SESSION"), false); assert.equal(storage.readableCookies.includes("AP4_SESSION"), false);
const externalAuthSubrequest = await fetch(`${edgeBaseUrl}/oauth2/auth`);
assert.equal(externalAuthSubrequest.status, 404);
const apiResponse = await fetch(`${edgeBaseUrl}/api/edge`, {
redirect: "manual",
});
assert.equal(apiResponse.status, 401);
assert.equal(apiResponse.headers.get("location"), null);
await assert.rejects(
fetch("http://localhost:4180/ping"),
"oauth2-proxy must not be published on the host",
);
const missingHeader = await fetch("http://localhost:8081/edge/me"); const missingHeader = await fetch("http://localhost:8081/edge/me");
assert.equal(missingHeader.status, 401); assert.equal(missingHeader.status, 401);
const directSpoof = await fetch("http://localhost:8081/edge/me", { const directSpoof = await fetch("http://localhost:8081/edge/me", {
headers: { "X-Forwarded-User": "spoofed-admin" }, headers: { "X-Auth-Request-User": "spoofed-admin" },
}); });
assert.equal(directSpoof.status, 200); assert.equal(directSpoof.status, 200);
const spoofedIdentity = await directSpoof.json(); const spoofedIdentity = await directSpoof.json();
assert.equal(spoofedIdentity.user, "spoofed-admin"); assert.equal(spoofedIdentity.user, "spoofed-admin");
console.log( console.log(
"pattern4 oauth2-proxy verified: redirect, PKCE login, forwarded-user 200, direct spoof precondition", "pattern4 nginx auth_request verified: internal subrequest, browser redirect, API 401, forwarded identity",
); );
} finally { } finally {
await browser.close(); await browser.close();
+54 -7
View File
@@ -2,8 +2,7 @@ server {
listen 80; listen 80;
server_name _; server_name _;
root /usr/share/nginx/html; large_client_header_buffers 4 16k;
index index.html;
location = /health { location = /health {
access_log off; access_log off;
@@ -11,16 +10,64 @@ server {
return 200 "ok\n"; return 200 "ok\n";
} }
location /api/ { location = /oauth2/auth {
proxy_pass http://app:8081; internal;
proxy_http_version 1.1; proxy_pass http://oauth2-proxy:4180;
proxy_set_header Host $host; proxy_pass_request_body off;
proxy_set_header Content-Length "";
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Uri $request_uri;
}
location /oauth2/ {
proxy_pass http://oauth2-proxy:4180;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Auth-Request-Redirect $scheme://$http_host$request_uri;
}
location = /api/edge {
auth_request /oauth2/auth;
error_page 401 = @api_unauthorized;
auth_request_set $auth_user $upstream_http_x_auth_request_user;
auth_request_set $auth_email $upstream_http_x_auth_request_email;
auth_request_set $auth_cookie $upstream_http_set_cookie;
add_header Set-Cookie $auth_cookie always;
proxy_pass http://app:8081/edge/me;
proxy_set_header X-Auth-Request-User $auth_user;
proxy_set_header X-Auth-Request-Email $auth_email;
} }
location / { location / {
try_files $uri $uri/ /index.html; auth_request /oauth2/auth;
error_page 401 = @oauth2_signin;
auth_request_set $auth_user $upstream_http_x_auth_request_user;
auth_request_set $auth_email $upstream_http_x_auth_request_email;
auth_request_set $auth_cookie $upstream_http_set_cookie;
add_header Set-Cookie $auth_cookie always;
proxy_pass http://app:8081/edge/me;
proxy_set_header X-Auth-Request-User $auth_user;
proxy_set_header X-Auth-Request-Email $auth_email;
}
location @oauth2_signin {
return 302 $scheme://$http_host/oauth2/start?rd=$scheme://$http_host$request_uri;
}
location @api_unauthorized {
default_type application/json;
return 401 '{"error":"authentication required"}';
} }
} }
+1 -1
View File
@@ -116,7 +116,7 @@
"serviceAccountsEnabled": false, "serviceAccountsEnabled": false,
"frontchannelLogout": true, "frontchannelLogout": true,
"redirectUris": [ "redirectUris": [
"http://localhost:4180/oauth2/callback" "http://localhost:8088/oauth2/callback"
], ],
"webOrigins": [], "webOrigins": [],
"attributes": { "attributes": {
+6 -1
View File
@@ -13,9 +13,14 @@ set +a
docker compose down --volumes --remove-orphans docker compose down --volumes --remove-orphans
docker compose up --build -d --wait docker compose up --build -d --wait
docker compose exec -T nginx nginx -V 2>&1 |
grep -q -- '--with-http_auth_request_module'
docker compose exec -T nginx nginx -T 2>&1 |
grep -q 'proxy_pass_request_body off'
npm --prefix e2e ci npm --prefix e2e ci
E2E_USERNAME=regular-user \ E2E_USERNAME=regular-user \
E2E_PASSWORD="$REGULAR_USER_PASSWORD" \ E2E_PASSWORD="$REGULAR_USER_PASSWORD" \
npm --prefix e2e run test:pattern4 npm --prefix e2e run test:pattern4
echo "AP4 oauth2-proxy edge flow verified" echo "AP4 Nginx auth_request edge flow verified"