docs: define exact Google redirect URI policy
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
# Google redirect URI policy
|
||||
|
||||
Google에 등록하는 redirect URI는 애플리케이션 SPA callback이 아니라 Keycloak
|
||||
broker endpoint다.
|
||||
|
||||
```text
|
||||
https://auth.example.test/realms/keycloak-patterns/broker/google/endpoint
|
||||
```
|
||||
|
||||
규칙:
|
||||
|
||||
- production URI는 HTTPS와 고정된 public Keycloak origin을 사용한다.
|
||||
- wildcard, path prefix, 임시 tunnel hostname을 production OAuth client에
|
||||
등록하지 않는다.
|
||||
- 개발·스테이징·운영은 Google OAuth client를 분리한다.
|
||||
- reverse proxy가 있더라도 Google이 보는 URI와 Keycloak이 생성하는 URI가
|
||||
byte-for-byte 같아야 한다.
|
||||
- `configure-google-idp.sh`가 출력하는 URI를 Google Console의 Authorized
|
||||
redirect URI와 대조한다.
|
||||
|
||||
```sh
|
||||
PUBLIC_KEYCLOAK_URL=https://auth.example.test \
|
||||
./scripts/verify-google-redirect-uri-policy.sh
|
||||
```
|
||||
Executable
+24
@@ -0,0 +1,24 @@
|
||||
#!/usr/bin/env sh
|
||||
set -eu
|
||||
|
||||
realm="${KEYCLOAK_REALM:-keycloak-patterns}"
|
||||
public_keycloak_url="${PUBLIC_KEYCLOAK_URL:-https://auth.example.test}"
|
||||
expected="$public_keycloak_url/realms/$realm/broker/google/endpoint"
|
||||
|
||||
case "$public_keycloak_url" in
|
||||
https://*) ;;
|
||||
*)
|
||||
echo "PUBLIC_KEYCLOAK_URL must use https outside the local mock environment" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
case "$public_keycloak_url" in
|
||||
*\** | */)
|
||||
echo "PUBLIC_KEYCLOAK_URL must be an exact origin without wildcard/trailing slash" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
|
||||
test "$expected" = "https://auth.example.test/realms/keycloak-patterns/broker/google/endpoint"
|
||||
echo "Google redirect URI policy verified: $expected"
|
||||
Reference in New Issue
Block a user