From 357b7f927b78cf7bdcc08d1ad9b937a38fca7a96 Mon Sep 17 00:00:00 2001 From: donghyeon-ka Date: Sat, 25 Jul 2026 14:55:04 +0900 Subject: [PATCH] feat(ap4): integrate nginx auth_request --- README.md | 6 +- docker-compose.yml | 18 ++++-- docs/ap4-edge-forward-auth.md | 20 +++++++ e2e/pattern4.mjs | 35 ++++++++--- frontend/nginx.conf | 61 +++++++++++++++++--- keycloak/import/keycloak-patterns-realm.json | 2 +- scripts/verify-pattern4.sh | 7 ++- 7 files changed, 123 insertions(+), 26 deletions(-) diff --git a/README.md b/README.md index cf91526..dfc2351 100644 --- a/README.md +++ b/README.md @@ -107,8 +107,10 @@ gitignored `build/keycloak-export/`에 권한 `0600`으로만 저장됩니다. ``` 첫 feature에서는 oauth2-proxy를 `http://localhost:4180`에 직접 노출해 -OIDC redirect/PKCE/callback과 forwarded-user를 분리 확인합니다. 최종 -구성은 `http://localhost:8088` Nginx를 단일 진입점으로 사용합니다. +OIDC redirect/PKCE/callback과 forwarded-user를 분리 확인합니다. 두 번째 +feature부터 `http://localhost:8088` Nginx가 단일 진입점이며, 내부 +`auth_request`는 브라우저 요청을 login 302로, API 요청을 JSON 401로 +구분합니다. 최종 feature에서는 backend의 호스트 노출도 제거합니다. 자세한 내용은 [`docs/ap4-edge-forward-auth.md`](docs/ap4-edge-forward-auth.md)를 참고하세요. diff --git a/docker-compose.yml b/docker-compose.yml index edfe0c0..fc3c819 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -98,11 +98,13 @@ services: - --oidc-jwks-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/certs - --profile-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo - --validate-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo - - --redirect-url=http://localhost:4180/oauth2/callback + - --redirect-url=http://localhost:8088/oauth2/callback - --upstream=http://app:8081 - --email-domain=* - --scope=openid profile email - --code-challenge-method=S256 + - --reverse-proxy=true + - --trusted-proxy-ip=172.30.40.10/32 - --cookie-name=AP4_SESSION - --cookie-secure=false - --cookie-samesite=lax @@ -110,14 +112,14 @@ services: - --skip-provider-button=true - --set-xauthrequest=true - --pass-user-headers=true - - --whitelist-domain=localhost:4180 + - --whitelist-domain=localhost:8088 - --whitelist-domain=localhost:8080 environment: OAUTH2_PROXY_CLIENT_ID: edge-proxy OAUTH2_PROXY_CLIENT_SECRET: ${EDGE_PROXY_CLIENT_SECRET:?set EDGE_PROXY_CLIENT_SECRET in .env} OAUTH2_PROXY_COOKIE_SECRET: ${OAUTH2_PROXY_COOKIE_SECRET:?set OAUTH2_PROXY_COOKIE_SECRET in .env} - ports: - - "127.0.0.1:4180:4180" + expose: + - "4180" depends_on: keycloak: condition: service_healthy @@ -142,7 +144,7 @@ services: ports: - "127.0.0.1:${NGINX_PORT:-8088}:80" depends_on: - app: + oauth2-proxy: condition: service_healthy healthcheck: test: @@ -152,7 +154,8 @@ services: timeout: 5s retries: 12 networks: - - keycloak-net + keycloak-net: + ipv4_address: 172.30.40.10 restart: unless-stopped volumes: @@ -162,3 +165,6 @@ volumes: networks: keycloak-net: driver: bridge + ipam: + config: + - subnet: 172.30.40.0/24 diff --git a/docs/ap4-edge-forward-auth.md b/docs/ap4-edge-forward-auth.md index 4d34ab0..89b30cd 100644 --- a/docs/ap4-edge-forward-auth.md +++ b/docs/ap4-edge-forward-auth.md @@ -29,3 +29,23 @@ loopback에 publish되어 있습니다. 따라서 로컬에서 직접 `X-Forwarded-User: spoofed-admin`을 보내면 우회가 재현됩니다. 이후 Nginx `auth_request` 통합을 거쳐 최종 feature에서 backend no-publish와 내부 shared-secret 검증을 함께 적용합니다. + +## 두 번째 단계: Nginx `auth_request` + +`feature/keycloak-nginx-auth-request-integration`부터 외부 진입점은 +`http://localhost:8088` Nginx 하나입니다. oauth2-proxy의 4180 포트는 +Compose 네트워크에만 expose됩니다. + +- Nginx의 정확 일치 `location = /oauth2/auth`는 `internal`이라 외부에서 + 직접 호출할 수 없습니다. +- 인증 서브리퀘스트에는 본문을 보내지 않고 `Content-Length`도 + 비웁니다. +- 일반 브라우저 요청의 401은 `/oauth2/start` 302로 변환합니다. +- API 요청 `/api/edge`는 redirect하지 않고 JSON 401을 반환합니다. +- 인증 성공 시 oauth2-proxy의 `X-Auth-Request-User`와 email만 backend로 + 전달합니다. + +Nginx 컨테이너 IP를 전용 Compose subnet에서 고정하고 oauth2-proxy의 +trusted proxy를 그 단일 IP로 제한합니다. 다만 이 단계에서는 backend +8081이 로컬 호스트에 열려 있어 신뢰 헤더를 직접 위조할 수 있습니다. +그 재현 조건은 마지막 feature에서 제거합니다. diff --git a/e2e/pattern4.mjs b/e2e/pattern4.mjs index 0f314ef..b225586 100644 --- a/e2e/pattern4.mjs +++ b/e2e/pattern4.mjs @@ -4,6 +4,9 @@ import { chromium } from "playwright-core"; const password = process.env.E2E_PASSWORD; assert.ok(password, "E2E_PASSWORD must be set"); +const edgeBaseUrl = "http://localhost:8088"; +const edgeEntryUrl = `${edgeBaseUrl}/`; + async function completeKeycloakLogin(page) { for (let attempt = 1; attempt <= 2; attempt += 1) { await page.locator("#username").fill( @@ -13,11 +16,11 @@ async function completeKeycloakLogin(page) { await page.locator("#kc-login").click(); await page.waitForLoadState("domcontentloaded"); - if (page.url() === "http://localhost:4180/edge/me") { + if (page.url() === edgeEntryUrl) { return; } if (attempt === 1) { - await page.goto("http://localhost:4180/oauth2/start?rd=%2Fedge%2Fme"); + await page.goto(`${edgeBaseUrl}/oauth2/start?rd=${encodeURIComponent(edgeEntryUrl)}`); await page.waitForURL(/localhost:8080/u); } } @@ -40,7 +43,7 @@ try { const edgeResponsePromise = page.waitForResponse( (response) => - response.url() === "http://localhost:4180/edge/me" && + response.url() === edgeEntryUrl && response.status() === 302, ); const authorizationRequestPromise = page.waitForRequest((request) => @@ -48,7 +51,7 @@ try { "/protocol/openid-connect/auth?approval_prompt=", ), ); - await page.goto("http://localhost:4180/edge/me"); + await page.goto(edgeEntryUrl); const unauthenticatedEdgeResponse = await edgeResponsePromise; assert.equal(unauthenticatedEdgeResponse.status(), 302); @@ -63,10 +66,10 @@ try { const edgeIdentity = JSON.parse(await page.locator("body").innerText()); assert.equal(edgeIdentity.pattern, "AP4-edge-forward-auth"); assert.ok(edgeIdentity.user); - assert.equal(edgeIdentity.identityHeader, "X-Forwarded-User"); + assert.equal(edgeIdentity.identityHeader, "X-Auth-Request-User"); const callbackRequest = browserRequests.find(({ url }) => - url.startsWith("http://localhost:4180/oauth2/callback?"), + url.startsWith(`${edgeBaseUrl}/oauth2/callback?`), ); assert.ok(callbackRequest); assert.equal(callbackRequest.method, "GET"); @@ -78,7 +81,7 @@ try { "the confidential token exchange must be server-to-server", ); - const cookies = await context.cookies("http://localhost:4180/"); + const cookies = await context.cookies(edgeEntryUrl); const sessionCookie = cookies.find((cookie) => cookie.name === "AP4_SESSION"); assert.ok(sessionCookie); assert.equal(sessionCookie.httpOnly, true); @@ -94,17 +97,31 @@ try { assert.deepEqual(storage.sessionStorage, []); assert.equal(storage.readableCookies.includes("AP4_SESSION"), false); + const externalAuthSubrequest = await fetch(`${edgeBaseUrl}/oauth2/auth`); + assert.equal(externalAuthSubrequest.status, 404); + + const apiResponse = await fetch(`${edgeBaseUrl}/api/edge`, { + redirect: "manual", + }); + assert.equal(apiResponse.status, 401); + assert.equal(apiResponse.headers.get("location"), null); + + await assert.rejects( + fetch("http://localhost:4180/ping"), + "oauth2-proxy must not be published on the host", + ); + const missingHeader = await fetch("http://localhost:8081/edge/me"); assert.equal(missingHeader.status, 401); const directSpoof = await fetch("http://localhost:8081/edge/me", { - headers: { "X-Forwarded-User": "spoofed-admin" }, + headers: { "X-Auth-Request-User": "spoofed-admin" }, }); assert.equal(directSpoof.status, 200); const spoofedIdentity = await directSpoof.json(); assert.equal(spoofedIdentity.user, "spoofed-admin"); console.log( - "pattern4 oauth2-proxy verified: redirect, PKCE login, forwarded-user 200, direct spoof precondition", + "pattern4 nginx auth_request verified: internal subrequest, browser redirect, API 401, forwarded identity", ); } finally { await browser.close(); diff --git a/frontend/nginx.conf b/frontend/nginx.conf index 731d30e..3d6e5d4 100644 --- a/frontend/nginx.conf +++ b/frontend/nginx.conf @@ -2,8 +2,7 @@ server { listen 80; server_name _; - root /usr/share/nginx/html; - index index.html; + large_client_header_buffers 4 16k; location = /health { access_log off; @@ -11,16 +10,64 @@ server { return 200 "ok\n"; } - location /api/ { - proxy_pass http://app:8081; - proxy_http_version 1.1; - proxy_set_header Host $host; + location = /oauth2/auth { + internal; + proxy_pass http://oauth2-proxy:4180; + proxy_pass_request_body off; + proxy_set_header Content-Length ""; + proxy_set_header X-Original-URL $scheme://$http_host$request_uri; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Host $http_host; proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header X-Forwarded-Uri $request_uri; + } + + location /oauth2/ { + proxy_pass http://oauth2-proxy:4180; + proxy_http_version 1.1; + proxy_set_header Host $http_host; + proxy_set_header X-Real-IP $remote_addr; + proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; + proxy_set_header X-Forwarded-Host $http_host; + proxy_set_header X-Forwarded-Proto $scheme; + proxy_set_header X-Auth-Request-Redirect $scheme://$http_host$request_uri; + } + + location = /api/edge { + auth_request /oauth2/auth; + error_page 401 = @api_unauthorized; + + auth_request_set $auth_user $upstream_http_x_auth_request_user; + auth_request_set $auth_email $upstream_http_x_auth_request_email; + auth_request_set $auth_cookie $upstream_http_set_cookie; + add_header Set-Cookie $auth_cookie always; + + proxy_pass http://app:8081/edge/me; + proxy_set_header X-Auth-Request-User $auth_user; + proxy_set_header X-Auth-Request-Email $auth_email; } location / { - try_files $uri $uri/ /index.html; + auth_request /oauth2/auth; + error_page 401 = @oauth2_signin; + + auth_request_set $auth_user $upstream_http_x_auth_request_user; + auth_request_set $auth_email $upstream_http_x_auth_request_email; + auth_request_set $auth_cookie $upstream_http_set_cookie; + add_header Set-Cookie $auth_cookie always; + + proxy_pass http://app:8081/edge/me; + proxy_set_header X-Auth-Request-User $auth_user; + proxy_set_header X-Auth-Request-Email $auth_email; + } + + location @oauth2_signin { + return 302 $scheme://$http_host/oauth2/start?rd=$scheme://$http_host$request_uri; + } + + location @api_unauthorized { + default_type application/json; + return 401 '{"error":"authentication required"}'; } } diff --git a/keycloak/import/keycloak-patterns-realm.json b/keycloak/import/keycloak-patterns-realm.json index 0071289..50a5637 100644 --- a/keycloak/import/keycloak-patterns-realm.json +++ b/keycloak/import/keycloak-patterns-realm.json @@ -116,7 +116,7 @@ "serviceAccountsEnabled": false, "frontchannelLogout": true, "redirectUris": [ - "http://localhost:4180/oauth2/callback" + "http://localhost:8088/oauth2/callback" ], "webOrigins": [], "attributes": { diff --git a/scripts/verify-pattern4.sh b/scripts/verify-pattern4.sh index 2343dac..dbfef39 100755 --- a/scripts/verify-pattern4.sh +++ b/scripts/verify-pattern4.sh @@ -13,9 +13,14 @@ set +a docker compose down --volumes --remove-orphans docker compose up --build -d --wait +docker compose exec -T nginx nginx -V 2>&1 | + grep -q -- '--with-http_auth_request_module' +docker compose exec -T nginx nginx -T 2>&1 | + grep -q 'proxy_pass_request_body off' + npm --prefix e2e ci E2E_USERNAME=regular-user \ E2E_PASSWORD="$REGULAR_USER_PASSWORD" \ npm --prefix e2e run test:pattern4 -echo "AP4 oauth2-proxy edge flow verified" +echo "AP4 Nginx auth_request edge flow verified"