feat(ap4): add oauth2-proxy OIDC flow
This commit is contained in:
@@ -0,0 +1,47 @@
|
||||
package com.example.keycloakpattern;
|
||||
|
||||
import java.util.LinkedHashMap;
|
||||
import java.util.Map;
|
||||
|
||||
import jakarta.servlet.http.HttpServletRequest;
|
||||
|
||||
import org.springframework.http.ResponseEntity;
|
||||
import org.springframework.web.bind.annotation.GetMapping;
|
||||
import org.springframework.web.bind.annotation.RestController;
|
||||
|
||||
@RestController
|
||||
public class EdgeIdentityController {
|
||||
|
||||
@GetMapping("/edge/me")
|
||||
ResponseEntity<Map<String, Object>> currentUser(HttpServletRequest request) {
|
||||
String authRequestUser = request.getHeader("X-Auth-Request-User");
|
||||
String forwardedUser = request.getHeader("X-Forwarded-User");
|
||||
String user = hasText(authRequestUser) ? authRequestUser : forwardedUser;
|
||||
if (!hasText(user)) {
|
||||
return ResponseEntity.status(401).body(Map.of(
|
||||
"error",
|
||||
"trusted edge identity header is required"
|
||||
));
|
||||
}
|
||||
|
||||
Map<String, Object> response = new LinkedHashMap<>();
|
||||
response.put("pattern", "AP4-edge-forward-auth");
|
||||
response.put("user", user);
|
||||
response.put("email", firstNonBlank(
|
||||
request.getHeader("X-Auth-Request-Email"),
|
||||
request.getHeader("X-Forwarded-Email")
|
||||
));
|
||||
response.put("identityHeader", hasText(authRequestUser)
|
||||
? "X-Auth-Request-User"
|
||||
: "X-Forwarded-User");
|
||||
return ResponseEntity.ok(response);
|
||||
}
|
||||
|
||||
private static String firstNonBlank(String first, String second) {
|
||||
return hasText(first) ? first : second;
|
||||
}
|
||||
|
||||
private static boolean hasText(String value) {
|
||||
return value != null && !value.isBlank();
|
||||
}
|
||||
}
|
||||
@@ -17,7 +17,12 @@ public class SecurityConfig {
|
||||
.sessionManagement(session ->
|
||||
session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
|
||||
.authorizeHttpRequests(authorize -> authorize
|
||||
.requestMatchers("/actuator/health", "/actuator/health/**", "/api/public")
|
||||
.requestMatchers(
|
||||
"/actuator/health",
|
||||
"/actuator/health/**",
|
||||
"/api/public",
|
||||
"/edge/**"
|
||||
)
|
||||
.permitAll()
|
||||
.anyRequest()
|
||||
.authenticated())
|
||||
|
||||
Reference in New Issue
Block a user