Compare commits

..
Author SHA1 Message Date
donghyeon-ka 357b7f927b feat(ap4): integrate nginx auth_request 2026-07-25 14:55:04 +09:00
donghyeon-ka 5ce47689a9 merge: oauth2-proxy OIDC flow 2026-07-25 14:50:00 +09:00
donghyeon-ka 4ac0133586 feat(ap4): add oauth2-proxy OIDC flow 2026-07-25 14:50:00 +09:00
26 changed files with 430 additions and 820 deletions
+1 -7
View File
@@ -10,15 +10,9 @@ POSTGRES_PASSWORD=change-me-postgres-password
TOKEN_MEDIATING_CLIENT_SECRET=change-me-token-mediating-client-secret
BFF_CLIENT_SECRET=change-me-bff-client-secret
EDGE_PROXY_CLIENT_SECRET=change-me-edge-proxy-client-secret
MOCK_GOOGLE_BROKER_CLIENT_SECRET=change-me-mock-google-broker-client-secret
OAUTH2_PROXY_COOKIE_SECRET=generate-a-base64-encoded-32-byte-secret
ADMIN_USER_PASSWORD=change-me-admin-user-password
REGULAR_USER_PASSWORD=change-me-regular-user-password
MOCK_GOOGLE_USER_PASSWORD=change-me-mock-google-user-password
# Optional real-Google profile. These are consumed only by
# scripts/configure-google-idp.sh and must never be committed with real values.
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
# Port 80 is the single-EC2 target. 8088 avoids common local port conflicts.
NGINX_PORT=8088
+2 -4
View File
@@ -4,8 +4,6 @@
*.iml
backend/target/
build/
e2e/node_modules/
google-e2e/node_modules/
frontend/node_modules/
**/node_modules/
frontend/dist/
build/
+18 -7
View File
@@ -1,12 +1,5 @@
# Keycloak Authentication Patterns
The 39-branch implementation registry is documented in
[`docs/keycloak-branch-index.md`](docs/keycloak-branch-index.md).
Google brokering has a credential-free local OIDC harness and an opt-in
real-Google profile described in
[`docs/google-idp-brokering.md`](docs/google-idp-brokering.md).
Keycloak을 중심으로 네 가지 브라우저 인증 통합 패턴을 같은 로컬
인프라에서 비교하는 학습 프로젝트입니다.
@@ -103,3 +96,21 @@ Keycloak을 잠시 중지하고 export한 뒤 자동으로 다시 올립니다.
runtime export에는 실제 client secret과 credential hash가 포함될 수 있어
gitignored `build/keycloak-export/`에 권한 `0600`으로만 저장됩니다.
## AP4: oauth2-proxy Edge Forward Auth
`develop-keycloak-pattern4`는 oauth2-proxy와 Nginx `auth_request`
인증을 edge에서 강제하는 패턴입니다.
```bash
./scripts/verify-pattern4.sh
```
첫 feature에서는 oauth2-proxy를 `http://localhost:4180`에 직접 노출해
OIDC redirect/PKCE/callback과 forwarded-user를 분리 확인합니다. 두 번째
feature부터 `http://localhost:8088` Nginx가 단일 진입점이며, 내부
`auth_request`는 브라우저 요청을 login 302로, API 요청을 JSON 401로
구분합니다. 최종 feature에서는 backend의 호스트 노출도 제거합니다.
자세한 내용은
[`docs/ap4-edge-forward-auth.md`](docs/ap4-edge-forward-auth.md)를
참고하세요.
@@ -0,0 +1,47 @@
package com.example.keycloakpattern;
import java.util.LinkedHashMap;
import java.util.Map;
import jakarta.servlet.http.HttpServletRequest;
import org.springframework.http.ResponseEntity;
import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController;
@RestController
public class EdgeIdentityController {
@GetMapping("/edge/me")
ResponseEntity<Map<String, Object>> currentUser(HttpServletRequest request) {
String authRequestUser = request.getHeader("X-Auth-Request-User");
String forwardedUser = request.getHeader("X-Forwarded-User");
String user = hasText(authRequestUser) ? authRequestUser : forwardedUser;
if (!hasText(user)) {
return ResponseEntity.status(401).body(Map.of(
"error",
"trusted edge identity header is required"
));
}
Map<String, Object> response = new LinkedHashMap<>();
response.put("pattern", "AP4-edge-forward-auth");
response.put("user", user);
response.put("email", firstNonBlank(
request.getHeader("X-Auth-Request-Email"),
request.getHeader("X-Forwarded-Email")
));
response.put("identityHeader", hasText(authRequestUser)
? "X-Auth-Request-User"
: "X-Forwarded-User");
return ResponseEntity.ok(response);
}
private static String firstNonBlank(String first, String second) {
return hasText(first) ? first : second;
}
private static boolean hasText(String value) {
return value != null && !value.isBlank();
}
}
@@ -17,7 +17,12 @@ public class SecurityConfig {
.sessionManagement(session ->
session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
.authorizeHttpRequests(authorize -> authorize
.requestMatchers("/actuator/health", "/actuator/health/**", "/api/public")
.requestMatchers(
"/actuator/health",
"/actuator/health/**",
"/api/public",
"/edge/**"
)
.permitAll()
.anyRequest()
.authenticated())
@@ -40,4 +40,20 @@ class ApiSecurityTest {
.andExpect(jsonPath("$.subject").value("test-subject"))
.andExpect(jsonPath("$.username").value("regular-user"));
}
@Test
void edgeEndpointRejectsMissingIdentityHeader() throws Exception {
mockMvc.perform(get("/edge/me"))
.andExpect(status().isUnauthorized());
}
@Test
void edgeEndpointCurrentlyTrustsForwardedUserHeader() throws Exception {
mockMvc.perform(get("/edge/me")
.header("X-Forwarded-User", "regular-user")
.header("X-Forwarded-Email", "regular-user@example.test"))
.andExpect(status().isOk())
.andExpect(jsonPath("$.user").value("regular-user"))
.andExpect(jsonPath("$.identityHeader").value("X-Forwarded-User"));
}
}
+58 -4
View File
@@ -38,10 +38,8 @@ services:
TOKEN_MEDIATING_CLIENT_SECRET: ${TOKEN_MEDIATING_CLIENT_SECRET:?set TOKEN_MEDIATING_CLIENT_SECRET in .env}
BFF_CLIENT_SECRET: ${BFF_CLIENT_SECRET:?set BFF_CLIENT_SECRET in .env}
EDGE_PROXY_CLIENT_SECRET: ${EDGE_PROXY_CLIENT_SECRET:?set EDGE_PROXY_CLIENT_SECRET in .env}
MOCK_GOOGLE_BROKER_CLIENT_SECRET: ${MOCK_GOOGLE_BROKER_CLIENT_SECRET:?set MOCK_GOOGLE_BROKER_CLIENT_SECRET in .env}
ADMIN_USER_PASSWORD: ${ADMIN_USER_PASSWORD:?set ADMIN_USER_PASSWORD in .env}
REGULAR_USER_PASSWORD: ${REGULAR_USER_PASSWORD:?set REGULAR_USER_PASSWORD in .env}
MOCK_GOOGLE_USER_PASSWORD: ${MOCK_GOOGLE_USER_PASSWORD:?set MOCK_GOOGLE_USER_PASSWORD in .env}
ports:
- "127.0.0.1:8080:8080"
volumes:
@@ -88,13 +86,65 @@ services:
- keycloak-net
restart: unless-stopped
oauth2-proxy:
image: quay.io/oauth2-proxy/oauth2-proxy:v7.15.2
command:
- --http-address=0.0.0.0:4180
- --provider=keycloak-oidc
- --oidc-issuer-url=http://localhost:8080/realms/keycloak-patterns
- --skip-oidc-discovery=true
- --login-url=http://localhost:8080/realms/keycloak-patterns/protocol/openid-connect/auth
- --redeem-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/token
- --oidc-jwks-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/certs
- --profile-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo
- --validate-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo
- --redirect-url=http://localhost:8088/oauth2/callback
- --upstream=http://app:8081
- --email-domain=*
- --scope=openid profile email
- --code-challenge-method=S256
- --reverse-proxy=true
- --trusted-proxy-ip=172.30.40.10/32
- --cookie-name=AP4_SESSION
- --cookie-secure=false
- --cookie-samesite=lax
- --cookie-expire=1h
- --skip-provider-button=true
- --set-xauthrequest=true
- --pass-user-headers=true
- --whitelist-domain=localhost:8088
- --whitelist-domain=localhost:8080
environment:
OAUTH2_PROXY_CLIENT_ID: edge-proxy
OAUTH2_PROXY_CLIENT_SECRET: ${EDGE_PROXY_CLIENT_SECRET:?set EDGE_PROXY_CLIENT_SECRET in .env}
OAUTH2_PROXY_COOKIE_SECRET: ${OAUTH2_PROXY_COOKIE_SECRET:?set OAUTH2_PROXY_COOKIE_SECRET in .env}
expose:
- "4180"
depends_on:
keycloak:
condition: service_healthy
app:
condition: service_healthy
healthcheck:
test:
- CMD
- /bin/oauth2-proxy
- --version
interval: 10s
timeout: 5s
retries: 3
start_period: 5s
networks:
- keycloak-net
restart: unless-stopped
nginx:
build:
context: ./frontend
ports:
- "127.0.0.1:${NGINX_PORT:-8088}:80"
depends_on:
app:
oauth2-proxy:
condition: service_healthy
healthcheck:
test:
@@ -104,7 +154,8 @@ services:
timeout: 5s
retries: 12
networks:
- keycloak-net
keycloak-net:
ipv4_address: 172.30.40.10
restart: unless-stopped
volumes:
@@ -114,3 +165,6 @@ volumes:
networks:
keycloak-net:
driver: bridge
ipam:
config:
- subnet: 172.30.40.0/24
+51
View File
@@ -0,0 +1,51 @@
# AP4 · oauth2-proxy Edge Forward Auth
## 첫 단계: oauth2-proxy 자체 OIDC 흐름
`feature/keycloak-oauth2-proxy-oidc-flow`에서는 oauth2-proxy를
`http://localhost:4180`에 직접 노출해 구성 요소를 분리해서 확인합니다.
1. `/edge/me` 미인증 요청이 Keycloak로 redirect됩니다.
2. oauth2-proxy는 confidential `edge-proxy` client와 PKCE S256을 사용합니다.
3. callback에서 code/token 교환과 ID/access token 검증은 서버끼리
수행합니다.
4. 브라우저에는 HttpOnly `AP4_SESSION` cookie만 남습니다.
5. oauth2-proxy가 backend 요청에 `X-Forwarded-User`를 붙여 200을 받습니다.
Keycloak이 발급하는 issuer는 브라우저 기준
`http://localhost:8080/realms/keycloak-patterns`입니다. 컨테이너 내부의
`localhost`는 oauth2-proxy 자신이므로 discovery endpoint에 도달할 수
없습니다. 그래서 이 로컬 Compose 구성은 issuer 검증값은 외부 URL로
유지하되, login URL은 브라우저용 외부 주소, token/JWKS/userinfo는
`http://keycloak:8080` 내부 주소로 각각 명시합니다.
HTTP 로컬 시연이라 `cookie-secure=false`를 사용합니다. 운영 HTTPS에서는
반드시 secure cookie로 되돌려야 합니다.
## 다음 단계의 보안 전제
이 첫 feature의 backend는 전달된 사용자 헤더를 신뢰하며 8081도
loopback에 publish되어 있습니다. 따라서 로컬에서 직접
`X-Forwarded-User: spoofed-admin`을 보내면 우회가 재현됩니다. 이후
Nginx `auth_request` 통합을 거쳐 최종 feature에서 backend no-publish와
내부 shared-secret 검증을 함께 적용합니다.
## 두 번째 단계: Nginx `auth_request`
`feature/keycloak-nginx-auth-request-integration`부터 외부 진입점은
`http://localhost:8088` Nginx 하나입니다. oauth2-proxy의 4180 포트는
Compose 네트워크에만 expose됩니다.
- Nginx의 정확 일치 `location = /oauth2/auth``internal`이라 외부에서
직접 호출할 수 없습니다.
- 인증 서브리퀘스트에는 본문을 보내지 않고 `Content-Length`
비웁니다.
- 일반 브라우저 요청의 401은 `/oauth2/start` 302로 변환합니다.
- API 요청 `/api/edge`는 redirect하지 않고 JSON 401을 반환합니다.
- 인증 성공 시 oauth2-proxy의 `X-Auth-Request-User`와 email만 backend로
전달합니다.
Nginx 컨테이너 IP를 전용 Compose subnet에서 고정하고 oauth2-proxy의
trusted proxy를 그 단일 IP로 제한합니다. 다만 이 단계에서는 backend
8081이 로컬 호스트에 열려 있어 신뢰 헤더를 직접 위조할 수 있습니다.
그 재현 조건은 마지막 feature에서 제거합니다.
-27
View File
@@ -1,27 +0,0 @@
# First Broker Login security
Keycloak 26.7.0's built-in `first broker login` flow does **not** silently
auto-link by email. It contains:
- `Create User If Unique`
- `Handle Existing Account`
- `Confirm link existing account`
- email verification or re-authentication ownership proof
`Automatically set existing user` is an explicit, dangerous opt-in. The local
acceptance harness copies the built-in flow, enables AutoLink, disables the
ownership-proof branch, and signs in through a controllable OIDC account whose
email collides with `regular-user`. It verifies that the external identity is
attached without proof. The harness then assigns the original built-in flow,
repeats the login, observes the existing-account confirmation page, and verifies
that no federated identity was attached.
Run after the stack is healthy:
```bash
./scripts/verify-first-broker-login.sh
```
The vulnerable flow remains only as a disabled learning artifact. The
`mock-google` provider is always returned to the secure built-in flow at the end
of the verification.
-28
View File
@@ -1,28 +0,0 @@
# Google IdP brokering
Keycloak is the only issuer trusted by AP1AP4. Google is an upstream Identity
Provider; applications do not receive or validate a Google token.
## Two verification profiles
The default local profile imports a second Keycloak realm named `mock-google`.
It acts as a controllable OIDC provider and allows tests to choose claims such
as a duplicate email, `email_verified=false`, `hd`, and `picture`. This is the
safe way to reproduce an unsafe email auto-link without impersonating a real
Google account.
The real-Google profile is configured explicitly:
1. Create a Google OAuth **Web application**.
2. Register the exact redirect URI printed by
`./scripts/configure-google-idp.sh`.
3. Put `GOOGLE_CLIENT_ID` and `GOOGLE_CLIENT_SECRET` in ignored `.env`.
4. Start the stack and run the configuration script.
The script writes `providerId=google`, `trustEmail=false`, minimal
`openid profile email` scopes, and `syncMode=IMPORT` through the Keycloak Admin
API. Credentials are never written to the realm export or repository.
Google requires a public HTTPS redirect for non-local deployments. Local mock
verification proves the Keycloak brokering boundary; a real Google login is a
separate credentialed acceptance profile.
-29
View File
@@ -1,29 +0,0 @@
# Keycloak branch implementation index
The source inventory contains 39 `feature-keycloak-*.md` branch notes. This
repository preserves one local Git feature branch for every note and merges it
with `--no-ff` into either the common `develop` baseline or one of the four
authentication-pattern branches.
| Target | Meaning |
|---|---|
| `common` | Shared realm, federation, deployment, or governance contract. Merge into `develop`, then propagate to AP1AP4. |
| `ap1` | Browser-based OAuth client: vanilla SPA, Authorization Code + PKCE, Resource Server. |
| `ap2` | Token-mediating confidential backend: browser receives access token only. |
| `ap3` | BFF: backend owns every OAuth token and browser owns only a session cookie. |
| `ap4` | Edge forward-auth: oauth2-proxy/Nginx owns login and backend trusts an isolated identity header. |
The machine-readable registry is
[`keycloak-branch-manifest.tsv`](keycloak-branch-manifest.tsv). Run:
```bash
./scripts/audit-keycloak-branches.sh
```
The audit succeeds only when all 39 note names have matching local feature
branches and each feature tip is reachable from its declared target branch.
Google credentials are never committed. The default local acceptance harness
uses a second Keycloak realm as a controllable OIDC provider so claim mapping
and unsafe-linking failure paths can be reproduced. A real Google login remains
an explicit credentialed/public-HTTPS verification profile.
-40
View File
@@ -1,40 +0,0 @@
branch target delivery
feature/keycloak-account-linking-spa-ux ap1 documented-and-contract-tested
feature/keycloak-account-linking-sub-vs-email common documented-and-contract-tested
feature/keycloak-bff-csrf-samesite-defense ap3 locally-verified
feature/keycloak-bff-oauth2login-session ap3 locally-verified
feature/keycloak-bff-vs-spa-direct ap3 documented
feature/keycloak-docker-compose-stack common locally-verified
feature/keycloak-edge-forwardauth-google-federation ap4 documented-and-config-tested
feature/keycloak-edge-forwardauth-no-google ap4 documented-and-config-tested
feature/keycloak-federation-spa-zero-change ap1 contract-tested
feature/keycloak-first-broker-login-flow common locally-verified-with-mock-idp
feature/keycloak-four-pattern-tradeoff-matrix common documented-and-evidence-linked
feature/keycloak-google-claim-attribute-mapping common locally-verified-with-mock-idp
feature/keycloak-google-redirect-uri-policy common config-tested
feature/keycloak-header-spoofing-defense ap4 locally-verified
feature/keycloak-https-termination-caddy-nginx common config-tested
feature/keycloak-idp-brokering-google-client common locally-verified-with-mock-idp
feature/keycloak-idp-mappers-claim-to-role common locally-verified-with-mock-idp
feature/keycloak-internal-spa-direct-google-federation ap1 documented-and-contract-tested
feature/keycloak-internal-spa-direct-no-google ap1 documented-and-contract-tested
feature/keycloak-iss-claim-hostname-mismatch ap1 locally-verified
feature/keycloak-nginx-auth-request-integration ap4 locally-verified
feature/keycloak-oauth2-proxy-oidc-flow ap4 locally-verified
feature/keycloak-patterns common governance
feature/keycloak-pkce-flow-stages ap1 contract-tested
feature/keycloak-public-domain-tunneling common config-tested
feature/keycloak-realm-client-export common locally-verified
feature/keycloak-refresh-rotation-and-logout ap1 locally-verified
feature/keycloak-refresh-token-rotation ap1 contract-tested
feature/keycloak-reverse-proxy-headers common config-tested
feature/keycloak-single-ec2-google-federation ap1 documented-and-config-tested
feature/keycloak-single-ec2-no-google ap1 documented-and-contract-tested
feature/keycloak-spa-token-storage-tradeoff ap1 locally-verified
feature/keycloak-spring-rs-audience-validator ap1 locally-verified
feature/keycloak-spring-rs-role-mapping ap1 locally-verified
feature/keycloak-three-leg-trust-chain ap1 documented-and-contract-tested
feature/keycloak-token-mediating-access-handoff ap2 locally-verified
feature/keycloak-token-mediating-confidential-client ap2 locally-verified
feature/keycloak-traefik-forwardauth-alternative ap4 config-tested
feature/keycloak-vanilla-js-spa-pkce ap1 locally-verified
1 branch target delivery
2 feature/keycloak-account-linking-spa-ux ap1 documented-and-contract-tested
3 feature/keycloak-account-linking-sub-vs-email common documented-and-contract-tested
4 feature/keycloak-bff-csrf-samesite-defense ap3 locally-verified
5 feature/keycloak-bff-oauth2login-session ap3 locally-verified
6 feature/keycloak-bff-vs-spa-direct ap3 documented
7 feature/keycloak-docker-compose-stack common locally-verified
8 feature/keycloak-edge-forwardauth-google-federation ap4 documented-and-config-tested
9 feature/keycloak-edge-forwardauth-no-google ap4 documented-and-config-tested
10 feature/keycloak-federation-spa-zero-change ap1 contract-tested
11 feature/keycloak-first-broker-login-flow common locally-verified-with-mock-idp
12 feature/keycloak-four-pattern-tradeoff-matrix common documented-and-evidence-linked
13 feature/keycloak-google-claim-attribute-mapping common locally-verified-with-mock-idp
14 feature/keycloak-google-redirect-uri-policy common config-tested
15 feature/keycloak-header-spoofing-defense ap4 locally-verified
16 feature/keycloak-https-termination-caddy-nginx common config-tested
17 feature/keycloak-idp-brokering-google-client common locally-verified-with-mock-idp
18 feature/keycloak-idp-mappers-claim-to-role common locally-verified-with-mock-idp
19 feature/keycloak-internal-spa-direct-google-federation ap1 documented-and-contract-tested
20 feature/keycloak-internal-spa-direct-no-google ap1 documented-and-contract-tested
21 feature/keycloak-iss-claim-hostname-mismatch ap1 locally-verified
22 feature/keycloak-nginx-auth-request-integration ap4 locally-verified
23 feature/keycloak-oauth2-proxy-oidc-flow ap4 locally-verified
24 feature/keycloak-patterns common governance
25 feature/keycloak-pkce-flow-stages ap1 contract-tested
26 feature/keycloak-public-domain-tunneling common config-tested
27 feature/keycloak-realm-client-export common locally-verified
28 feature/keycloak-refresh-rotation-and-logout ap1 locally-verified
29 feature/keycloak-refresh-token-rotation ap1 contract-tested
30 feature/keycloak-reverse-proxy-headers common config-tested
31 feature/keycloak-single-ec2-google-federation ap1 documented-and-config-tested
32 feature/keycloak-single-ec2-no-google ap1 documented-and-contract-tested
33 feature/keycloak-spa-token-storage-tradeoff ap1 locally-verified
34 feature/keycloak-spring-rs-audience-validator ap1 locally-verified
35 feature/keycloak-spring-rs-role-mapping ap1 locally-verified
36 feature/keycloak-three-leg-trust-chain ap1 documented-and-contract-tested
37 feature/keycloak-token-mediating-access-handoff ap2 locally-verified
38 feature/keycloak-token-mediating-confidential-client ap2 locally-verified
39 feature/keycloak-traefik-forwardauth-alternative ap4 config-tested
40 feature/keycloak-vanilla-js-spa-pkce ap1 locally-verified
+9 -8
View File
@@ -1,26 +1,27 @@
{
"name": "keycloak-google-broker-e2e",
"name": "keycloak-pattern-e2e",
"version": "1.0.0",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "keycloak-google-broker-e2e",
"name": "keycloak-pattern-e2e",
"version": "1.0.0",
"dependencies": {
"playwright-core": "1.55.1"
"devDependencies": {
"playwright-core": "1.62.0"
}
},
"node_modules/playwright-core": {
"version": "1.55.1",
"resolved": "https://registry.npmjs.org/playwright-core/-/playwright-core-1.55.1.tgz",
"integrity": "sha512-Z6Mh9mkwX+zxSlHqdr5AOcJnfp+xUWLCt9uKV18fhzA8eyxUd8NUWzAjxUh55RZKSYwDGX0cfaySdhZJGMoJ+w==",
"version": "1.62.0",
"resolved": "https://registry.npmjs.org/playwright-core/-/playwright-core-1.62.0.tgz",
"integrity": "sha512-nsNRyq0r2zsG8AcRHWknc9QRA5XCueC7gWMrs+Gx2tlZn9hcl8zudfh00lhJPY1DE7NmZ6bDsT9g2yey8mXljA==",
"dev": true,
"license": "Apache-2.0",
"bin": {
"playwright-core": "cli.js"
},
"engines": {
"node": ">=18"
"node": ">=20"
}
}
}
+12
View File
@@ -0,0 +1,12 @@
{
"name": "keycloak-pattern-e2e",
"private": true,
"version": "1.0.0",
"type": "module",
"scripts": {
"test:pattern4": "node pattern4.mjs"
},
"devDependencies": {
"playwright-core": "1.62.0"
}
}
+128
View File
@@ -0,0 +1,128 @@
import assert from "node:assert/strict";
import { chromium } from "playwright-core";
const password = process.env.E2E_PASSWORD;
assert.ok(password, "E2E_PASSWORD must be set");
const edgeBaseUrl = "http://localhost:8088";
const edgeEntryUrl = `${edgeBaseUrl}/`;
async function completeKeycloakLogin(page) {
for (let attempt = 1; attempt <= 2; attempt += 1) {
await page.locator("#username").fill(
process.env.E2E_USERNAME ?? "regular-user",
);
await page.locator("#password").fill(password);
await page.locator("#kc-login").click();
await page.waitForLoadState("domcontentloaded");
if (page.url() === edgeEntryUrl) {
return;
}
if (attempt === 1) {
await page.goto(`${edgeBaseUrl}/oauth2/start?rd=${encodeURIComponent(edgeEntryUrl)}`);
await page.waitForURL(/localhost:8080/u);
}
}
throw new Error(`Keycloak login did not return to AP4: ${page.url()}`);
}
const browser = await chromium.launch({
executablePath: process.env.CHROME_BIN ?? "/usr/bin/google-chrome",
headless: true,
args: ["--no-sandbox"],
});
try {
const context = await browser.newContext();
const page = await context.newPage();
const browserRequests = [];
page.on("request", (request) =>
browserRequests.push({ method: request.method(), url: request.url() }),
);
const edgeResponsePromise = page.waitForResponse(
(response) =>
response.url() === edgeEntryUrl &&
response.status() === 302,
);
const authorizationRequestPromise = page.waitForRequest((request) =>
request.url().includes(
"/protocol/openid-connect/auth?approval_prompt=",
),
);
await page.goto(edgeEntryUrl);
const unauthenticatedEdgeResponse = await edgeResponsePromise;
assert.equal(unauthenticatedEdgeResponse.status(), 302);
const authorizationRequest = await authorizationRequestPromise;
const authorizationUrl = new URL(authorizationRequest.url());
assert.equal(authorizationUrl.searchParams.get("client_id"), "edge-proxy");
assert.equal(authorizationUrl.searchParams.get("code_challenge_method"), "S256");
assert.ok(authorizationUrl.searchParams.get("code_challenge"));
await page.waitForURL(/localhost:8080/u);
await completeKeycloakLogin(page);
const edgeIdentity = JSON.parse(await page.locator("body").innerText());
assert.equal(edgeIdentity.pattern, "AP4-edge-forward-auth");
assert.ok(edgeIdentity.user);
assert.equal(edgeIdentity.identityHeader, "X-Auth-Request-User");
const callbackRequest = browserRequests.find(({ url }) =>
url.startsWith(`${edgeBaseUrl}/oauth2/callback?`),
);
assert.ok(callbackRequest);
assert.equal(callbackRequest.method, "GET");
assert.equal(
browserRequests.some(({ url }) =>
url.includes("/protocol/openid-connect/token"),
),
false,
"the confidential token exchange must be server-to-server",
);
const cookies = await context.cookies(edgeEntryUrl);
const sessionCookie = cookies.find((cookie) => cookie.name === "AP4_SESSION");
assert.ok(sessionCookie);
assert.equal(sessionCookie.httpOnly, true);
assert.equal(sessionCookie.sameSite, "Lax");
assert.equal(sessionCookie.secure, false);
const storage = await page.evaluate(() => ({
localStorage: Object.values(localStorage),
sessionStorage: Object.values(sessionStorage),
readableCookies: document.cookie,
}));
assert.deepEqual(storage.localStorage, []);
assert.deepEqual(storage.sessionStorage, []);
assert.equal(storage.readableCookies.includes("AP4_SESSION"), false);
const externalAuthSubrequest = await fetch(`${edgeBaseUrl}/oauth2/auth`);
assert.equal(externalAuthSubrequest.status, 404);
const apiResponse = await fetch(`${edgeBaseUrl}/api/edge`, {
redirect: "manual",
});
assert.equal(apiResponse.status, 401);
assert.equal(apiResponse.headers.get("location"), null);
await assert.rejects(
fetch("http://localhost:4180/ping"),
"oauth2-proxy must not be published on the host",
);
const missingHeader = await fetch("http://localhost:8081/edge/me");
assert.equal(missingHeader.status, 401);
const directSpoof = await fetch("http://localhost:8081/edge/me", {
headers: { "X-Auth-Request-User": "spoofed-admin" },
});
assert.equal(directSpoof.status, 200);
const spoofedIdentity = await directSpoof.json();
assert.equal(spoofedIdentity.user, "spoofed-admin");
console.log(
"pattern4 nginx auth_request verified: internal subrequest, browser redirect, API 401, forwarded identity",
);
} finally {
await browser.close();
}
+54 -7
View File
@@ -2,8 +2,7 @@ server {
listen 80;
server_name _;
root /usr/share/nginx/html;
index index.html;
large_client_header_buffers 4 16k;
location = /health {
access_log off;
@@ -11,16 +10,64 @@ server {
return 200 "ok\n";
}
location /api/ {
proxy_pass http://app:8081;
proxy_http_version 1.1;
proxy_set_header Host $host;
location = /oauth2/auth {
internal;
proxy_pass http://oauth2-proxy:4180;
proxy_pass_request_body off;
proxy_set_header Content-Length "";
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Uri $request_uri;
}
location /oauth2/ {
proxy_pass http://oauth2-proxy:4180;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Auth-Request-Redirect $scheme://$http_host$request_uri;
}
location = /api/edge {
auth_request /oauth2/auth;
error_page 401 = @api_unauthorized;
auth_request_set $auth_user $upstream_http_x_auth_request_user;
auth_request_set $auth_email $upstream_http_x_auth_request_email;
auth_request_set $auth_cookie $upstream_http_set_cookie;
add_header Set-Cookie $auth_cookie always;
proxy_pass http://app:8081/edge/me;
proxy_set_header X-Auth-Request-User $auth_user;
proxy_set_header X-Auth-Request-Email $auth_email;
}
location / {
try_files $uri $uri/ /index.html;
auth_request /oauth2/auth;
error_page 401 = @oauth2_signin;
auth_request_set $auth_user $upstream_http_x_auth_request_user;
auth_request_set $auth_email $upstream_http_x_auth_request_email;
auth_request_set $auth_cookie $upstream_http_set_cookie;
add_header Set-Cookie $auth_cookie always;
proxy_pass http://app:8081/edge/me;
proxy_set_header X-Auth-Request-User $auth_user;
proxy_set_header X-Auth-Request-Email $auth_email;
}
location @oauth2_signin {
return 302 $scheme://$http_host/oauth2/start?rd=$scheme://$http_host$request_uri;
}
location @api_unauthorized {
default_type application/json;
return 401 '{"error":"authentication required"}';
}
}
-124
View File
@@ -1,124 +0,0 @@
import assert from "node:assert/strict";
import { chromium } from "playwright-core";
const expectation = process.env.FIRST_BROKER_EXPECTATION;
assert.ok(
expectation === "vulnerable" || expectation === "secure",
"FIRST_BROKER_EXPECTATION must be vulnerable or secure",
);
const keycloakUrl = process.env.KEYCLOAK_URL ?? "http://localhost:8080";
const adminUsername = process.env.KC_BOOTSTRAP_ADMIN_USERNAME;
const adminPassword = process.env.KC_BOOTSTRAP_ADMIN_PASSWORD;
const mockPassword = process.env.MOCK_GOOGLE_USER_PASSWORD;
assert.ok(adminUsername && adminPassword && mockPassword);
async function adminToken() {
const body = new URLSearchParams({
client_id: "admin-cli",
grant_type: "password",
username: adminUsername,
password: adminPassword,
});
const response = await fetch(
`${keycloakUrl}/realms/master/protocol/openid-connect/token`,
{ method: "POST", body },
);
assert.equal(response.status, 200);
return (await response.json()).access_token;
}
async function regularUser(token) {
const response = await fetch(
`${keycloakUrl}/admin/realms/keycloak-patterns/users?username=regular-user&exact=true`,
{ headers: { Authorization: `Bearer ${token}` } },
);
assert.equal(response.status, 200);
const users = await response.json();
assert.equal(users.length, 1);
return users[0];
}
async function federatedIdentities(token, userId) {
const response = await fetch(
`${keycloakUrl}/admin/realms/keycloak-patterns/users/${userId}/federated-identity`,
{ headers: { Authorization: `Bearer ${token}` } },
);
assert.equal(response.status, 200);
return response.json();
}
async function removeMockLink(token, userId) {
const identities = await federatedIdentities(token, userId);
if (identities.some(({ identityProvider }) => identityProvider === "mock-google")) {
const response = await fetch(
`${keycloakUrl}/admin/realms/keycloak-patterns/users/${userId}/federated-identity/mock-google`,
{
method: "DELETE",
headers: { Authorization: `Bearer ${token}` },
},
);
assert.equal(response.status, 204);
}
}
const token = await adminToken();
const user = await regularUser(token);
await removeMockLink(token, user.id);
const browser = await chromium.launch({
executablePath: process.env.CHROME_BIN ?? "/usr/bin/google-chrome",
headless: true,
args: ["--no-sandbox"],
});
try {
const context = await browser.newContext();
const page = await context.newPage();
const authorizationUrl = new URL(
`${keycloakUrl}/realms/keycloak-patterns/protocol/openid-connect/auth`,
);
authorizationUrl.search = new URLSearchParams({
client_id: "spa-public",
redirect_uri: "http://localhost:8088/",
response_type: "code",
scope: "openid profile email",
state: `first-broker-${expectation}`,
nonce: `nonce-${expectation}`,
code_challenge: "K2qUEfBl-nQvF2gB4dNxC2zYVwZc1CVnZb5CsX2L7fI",
code_challenge_method: "S256",
kc_idp_hint: "mock-google",
});
await page.goto(authorizationUrl.toString());
await page.waitForURL(/\/realms\/mock-google\//u);
await page.locator("#username").fill("mock-collision-user");
await page.locator("#password").fill(mockPassword);
await page.locator("#kc-login").click();
await page.waitForLoadState("domcontentloaded");
if (expectation === "vulnerable") {
await page.waitForURL(/localhost:8088\/\?.*code=/u);
const identities = await federatedIdentities(token, user.id);
assert.equal(
identities.some(({ identityProvider }) => identityProvider === "mock-google"),
true,
"unsafe AutoLink should attach the attacker-controlled identity",
);
await removeMockLink(token, user.id);
} else {
assert.match(page.url(), /\/realms\/keycloak-patterns\//u);
const body = (await page.locator("body").innerText()).toLowerCase();
assert.match(body, /account already exists|link existing account|existing account/u);
const identities = await federatedIdentities(token, user.id);
assert.equal(
identities.some(({ identityProvider }) => identityProvider === "mock-google"),
false,
"Confirm Link must not attach the identity without ownership proof",
);
}
console.log(`first broker login ${expectation} case verified`);
} finally {
await browser.close();
}
-12
View File
@@ -1,12 +0,0 @@
{
"name": "keycloak-google-broker-e2e",
"version": "1.0.0",
"private": true,
"type": "module",
"scripts": {
"test:first-broker": "node first-broker-login.mjs"
},
"dependencies": {
"playwright-core": "1.55.1"
}
}
+2 -31
View File
@@ -116,44 +116,15 @@
"serviceAccountsEnabled": false,
"frontchannelLogout": true,
"redirectUris": [
"http://localhost:4180/oauth2/callback"
"http://localhost:8088/oauth2/callback"
],
"webOrigins": [],
"attributes": {
"pkce.code.challenge.method": "S256",
"post.logout.redirect.uris": "http://localhost:8088/*"
}
}
],
"identityProviders": [
{
"alias": "mock-google",
"displayName": "Mock Google (local verification)",
"providerId": "oidc",
"enabled": true,
"updateProfileFirstLoginMode": "off",
"trustEmail": false,
"storeToken": false,
"addReadTokenRoleOnCreate": false,
"authenticateByDefault": false,
"linkOnly": false,
"firstBrokerLoginFlowAlias": "first broker login",
"config": {
"clientId": "mock-google-broker",
"clientSecret": "${MOCK_GOOGLE_BROKER_CLIENT_SECRET}",
"authorizationUrl": "http://localhost:8080/realms/mock-google/protocol/openid-connect/auth",
"tokenUrl": "http://keycloak:8080/realms/mock-google/protocol/openid-connect/token",
"userInfoUrl": "http://keycloak:8080/realms/mock-google/protocol/openid-connect/userinfo",
"issuer": "http://localhost:8080/realms/mock-google",
"jwksUrl": "http://keycloak:8080/realms/mock-google/protocol/openid-connect/certs",
"useJwksUrl": "true",
"validateSignature": "true",
"defaultScope": "openid profile email",
"syncMode": "IMPORT",
"pkceEnabled": "true",
"pkceMethod": "S256"
}
}
],
"users": [
{
"username": "admin-user",
-71
View File
@@ -1,71 +0,0 @@
{
"realm": "mock-google",
"displayName": "Controllable Google OIDC Test Provider",
"enabled": true,
"sslRequired": "external",
"registrationAllowed": false,
"resetPasswordAllowed": false,
"editUsernameAllowed": false,
"loginWithEmailAllowed": true,
"duplicateEmailsAllowed": false,
"bruteForceProtected": true,
"clients": [
{
"clientId": "mock-google-broker",
"name": "Main Realm Identity Broker",
"enabled": true,
"protocol": "openid-connect",
"publicClient": false,
"clientAuthenticatorType": "client-secret",
"secret": "${MOCK_GOOGLE_BROKER_CLIENT_SECRET}",
"standardFlowEnabled": true,
"implicitFlowEnabled": false,
"directAccessGrantsEnabled": false,
"serviceAccountsEnabled": false,
"redirectUris": [
"http://localhost:8080/realms/keycloak-patterns/broker/mock-google/endpoint"
],
"webOrigins": []
}
],
"users": [
{
"username": "mock-new-user",
"enabled": true,
"email": "broker-new-user@example.test",
"emailVerified": true,
"firstName": "Broker",
"lastName": "New",
"credentials": [
{
"type": "password",
"value": "${MOCK_GOOGLE_USER_PASSWORD}",
"temporary": false
}
]
},
{
"username": "mock-collision-user",
"enabled": true,
"email": "regular-user@example.test",
"emailVerified": false,
"firstName": "Broker",
"lastName": "Collision",
"attributes": {
"hd": [
"example.test"
],
"picture": [
"https://images.example.test/mock-collision-user.png"
]
},
"credentials": [
{
"type": "password",
"value": "${MOCK_GOOGLE_USER_PASSWORD}",
"temporary": false
}
]
}
]
}
-62
View File
@@ -1,62 +0,0 @@
#!/usr/bin/env sh
set -eu
manifest="${1:-docs/keycloak-branch-manifest.tsv}"
notes_dir="${KEYCLOAK_BRANCH_NOTES_DIR:-/home/donghyeon/workspace/ai-tools/llm-wiki/raw/branch-notes}"
expected_count="$(awk 'NR > 1 { count += 1 } END { print count + 0 }' "$manifest")"
if [ "$expected_count" -ne 39 ]; then
echo "manifest must contain exactly 39 Keycloak branches; found $expected_count" >&2
exit 1
fi
note_count="$(find "$notes_dir" -maxdepth 1 -type f -name 'feature-keycloak-*.md' | wc -l)"
if [ "$note_count" -ne 39 ]; then
echo "branch-note inventory must contain exactly 39 files; found $note_count" >&2
exit 1
fi
missing=0
unmerged=0
tab="$(printf '\t')"
while IFS="$tab" read -r branch target delivery; do
[ "$branch" = "branch" ] && continue
note_name="$(printf '%s\n' "$branch" |
sed 's#^feature/keycloak-#feature-keycloak-#').md"
if [ ! -f "$notes_dir/$note_name" ]; then
echo "missing branch note: $note_name" >&2
missing=$((missing + 1))
fi
if ! git show-ref --verify --quiet "refs/heads/$branch"; then
echo "missing local branch: $branch" >&2
missing=$((missing + 1))
continue
fi
case "$target" in
common) target_branch="develop" ;;
ap1) target_branch="develop-keycloak-pattern1" ;;
ap2) target_branch="develop-keycloak-pattern2" ;;
ap3) target_branch="develop-keycloak-pattern3" ;;
ap4) target_branch="develop-keycloak-pattern4" ;;
*)
echo "unknown target '$target' for $branch ($delivery)" >&2
exit 1
;;
esac
if ! git merge-base --is-ancestor "$branch" "$target_branch"; then
echo "feature tip is not merged: $branch -> $target_branch" >&2
unmerged=$((unmerged + 1))
fi
done < "$manifest"
if [ "$missing" -ne 0 ] || [ "$unmerged" -ne 0 ]; then
echo "Keycloak branch audit failed: missing=$missing unmerged=$unmerged" >&2
exit 1
fi
echo "Keycloak branch audit passed: 39/39 branches exist and are merged"
-81
View File
@@ -1,81 +0,0 @@
#!/usr/bin/env sh
set -eu
if [ ! -f .env ]; then
echo "missing .env" >&2
exit 1
fi
set -a
. ./.env
set +a
: "${KC_BOOTSTRAP_ADMIN_USERNAME:?set KC_BOOTSTRAP_ADMIN_USERNAME in .env}"
: "${KC_BOOTSTRAP_ADMIN_PASSWORD:?set KC_BOOTSTRAP_ADMIN_PASSWORD in .env}"
: "${GOOGLE_CLIENT_ID:?set GOOGLE_CLIENT_ID in .env}"
: "${GOOGLE_CLIENT_SECRET:?set GOOGLE_CLIENT_SECRET in .env}"
keycloak_url="${KEYCLOAK_URL:-http://localhost:8080}"
realm="${KEYCLOAK_REALM:-keycloak-patterns}"
admin_token="$(
curl -fsS \
-d client_id=admin-cli \
-d grant_type=password \
-d "username=$KC_BOOTSTRAP_ADMIN_USERNAME" \
-d "password=$KC_BOOTSTRAP_ADMIN_PASSWORD" \
"$keycloak_url/realms/master/protocol/openid-connect/token" |
jq -er .access_token
)"
payload="$(
jq -n \
--arg client_id "$GOOGLE_CLIENT_ID" \
--arg client_secret "$GOOGLE_CLIENT_SECRET" \
'{
alias: "google",
displayName: "Sign in with Google",
providerId: "google",
enabled: true,
updateProfileFirstLoginMode: "off",
trustEmail: false,
storeToken: false,
addReadTokenRoleOnCreate: false,
authenticateByDefault: false,
linkOnly: false,
firstBrokerLoginFlowAlias: "first broker login",
config: {
clientId: $client_id,
clientSecret: $client_secret,
defaultScope: "openid profile email",
syncMode: "IMPORT"
}
}'
)"
endpoint="$keycloak_url/admin/realms/$realm/identity-provider/instances"
status="$(
curl -sS -o /dev/null -w '%{http_code}' \
-H "Authorization: Bearer $admin_token" \
"$endpoint/google"
)"
if [ "$status" = "200" ]; then
curl -fsS -X PUT \
-H "Authorization: Bearer $admin_token" \
-H "Content-Type: application/json" \
--data "$payload" \
"$endpoint/google"
action="updated"
else
curl -fsS -X POST \
-H "Authorization: Bearer $admin_token" \
-H "Content-Type: application/json" \
--data "$payload" \
"$endpoint"
action="created"
fi
echo "Google Identity Provider $action for realm '$realm'"
echo "Register this exact Google redirect URI:"
echo "$keycloak_url/realms/$realm/broker/google/endpoint"
-178
View File
@@ -1,178 +0,0 @@
#!/usr/bin/env sh
set -eu
mode="${1:-}"
case "$mode" in
vulnerable|secure) ;;
*)
echo "usage: $0 vulnerable|secure" >&2
exit 1
;;
esac
if [ ! -f .env ]; then
echo "missing .env" >&2
exit 1
fi
set -a
. ./.env
set +a
keycloak_url="${KEYCLOAK_URL:-http://localhost:8080}"
realm="${KEYCLOAK_REALM:-keycloak-patterns}"
admin_base="$keycloak_url/admin/realms/$realm"
vulnerable_flow="vulnerable first broker login"
idp_url="$admin_base/identity-provider/instances/mock-google"
admin_token="$(
curl -fsS \
-d client_id=admin-cli \
-d grant_type=password \
-d "username=$KC_BOOTSTRAP_ADMIN_USERNAME" \
-d "password=$KC_BOOTSTRAP_ADMIN_PASSWORD" \
"$keycloak_url/realms/master/protocol/openid-connect/token" |
jq -er .access_token
)"
auth_header="Authorization: Bearer $admin_token"
encode() {
jq -rn --arg value "$1" '$value | @uri'
}
flows="$(curl -fsS -H "$auth_header" "$admin_base/authentication/flows")"
flow_id="$(
printf '%s' "$flows" |
jq -r --arg alias "$vulnerable_flow" '
.[] | select(.alias == $alias) | .id
' |
head -1
)"
if [ -n "$flow_id" ]; then
existing_executions="$(
curl -fsS -H "$auth_header" \
"$admin_base/authentication/flows/$(encode "$vulnerable_flow")/executions"
)"
if printf '%s' "$existing_executions" | jq -e '
any(.[]; .authenticationFlow == true)
' >/dev/null; then
idp_before_delete="$(curl -fsS -H "$auth_header" "$idp_url")"
printf '%s' "$idp_before_delete" |
jq '.firstBrokerLoginFlowAlias = "first broker login"' |
curl -fsS -X PUT \
-H "$auth_header" \
-H "Content-Type: application/json" \
--data @- \
"$idp_url"
curl -fsS -X DELETE \
-H "$auth_header" \
"$admin_base/authentication/flows/$flow_id"
flow_id=""
fi
fi
if [ -z "$flow_id" ]; then
curl -fsS -X POST \
-H "$auth_header" \
-H "Content-Type: application/json" \
--data "$(
jq -n --arg alias "$vulnerable_flow" '{
alias: $alias,
description: "INSECURE LEARNING FLOW - automatic email linking",
providerId: "basic-flow",
topLevel: true,
builtIn: false
}'
)" \
"$admin_base/authentication/flows"
fi
executions_url="$admin_base/authentication/flows/$(encode "$vulnerable_flow")/executions"
executions="$(curl -fsS -H "$auth_header" "$executions_url")"
create_user_id="$(
printf '%s' "$executions" |
jq -r '.[] | select(.providerId == "idp-create-user-if-unique") | .id' |
head -1
)"
if [ -z "$create_user_id" ]; then
curl -fsS -X POST \
-H "$auth_header" \
-H "Content-Type: application/json" \
--data '{"provider":"idp-create-user-if-unique"}' \
"$admin_base/authentication/flows/$(encode "$vulnerable_flow")/executions/execution"
executions="$(curl -fsS -H "$auth_header" "$executions_url")"
create_user_id="$(
printf '%s' "$executions" |
jq -r '.[] | select(.providerId == "idp-create-user-if-unique") | .id' |
head -1
)"
fi
auto_link_id="$(
printf '%s' "$executions" |
jq -r '.[] | select(.providerId == "idp-auto-link") | .id' |
head -1
)"
if [ -z "$auto_link_id" ]; then
curl -fsS -X POST \
-H "$auth_header" \
-H "Content-Type: application/json" \
--data '{"provider":"idp-auto-link"}' \
"$admin_base/authentication/flows/$(encode "$vulnerable_flow")/executions/execution"
executions="$(curl -fsS -H "$auth_header" "$executions_url")"
auto_link_id="$(
printf '%s' "$executions" |
jq -r '.[] | select(.providerId == "idp-auto-link") | .id' |
head -1
)"
fi
if [ "$mode" = "vulnerable" ]; then
curl -fsS -X PUT \
-H "$auth_header" \
-H "Content-Type: application/json" \
--data "$(jq -n --arg id "$create_user_id" '{id: $id, requirement: "ALTERNATIVE"}')" \
"$executions_url"
curl -fsS -X PUT \
-H "$auth_header" \
-H "Content-Type: application/json" \
--data "$(jq -n --arg id "$auto_link_id" '{id: $id, requirement: "ALTERNATIVE"}')" \
"$executions_url"
selected_flow="$vulnerable_flow"
else
selected_flow="first broker login"
fi
idp="$(curl -fsS -H "$auth_header" "$idp_url")"
printf '%s' "$idp" |
jq --arg flow "$selected_flow" '.firstBrokerLoginFlowAlias = $flow' |
curl -fsS -X PUT \
-H "$auth_header" \
-H "Content-Type: application/json" \
--data @- \
"$idp_url"
assigned="$(
curl -fsS -H "$auth_header" "$idp_url" |
jq -r .firstBrokerLoginFlowAlias
)"
test "$assigned" = "$selected_flow"
if [ "$mode" = "secure" ]; then
secure_executions="$(
curl -fsS -H "$auth_header" \
"$admin_base/authentication/flows/$(encode "first broker login")/executions"
)"
printf '%s' "$secure_executions" | jq -e '
any(.[];
.providerId == "idp-confirm-link" and .requirement == "REQUIRED"
) and
(any(.[];
.providerId == "idp-auto-link" and .requirement != "DISABLED"
) | not)
' >/dev/null
fi
echo "mock-google First Broker Login mode: $mode ($selected_flow)"
-29
View File
@@ -1,29 +0,0 @@
#!/usr/bin/env sh
set -eu
if [ ! -f .env ]; then
echo "missing .env" >&2
exit 1
fi
set -a
. ./.env
set +a
restore_secure_flow() {
./scripts/set-first-broker-login-mode.sh secure >/dev/null 2>&1 || true
}
trap restore_secure_flow 0 1 2 15
npm --prefix google-e2e ci
./scripts/set-first-broker-login-mode.sh vulnerable
FIRST_BROKER_EXPECTATION=vulnerable \
npm --prefix google-e2e run test:first-broker
./scripts/set-first-broker-login-mode.sh secure
FIRST_BROKER_EXPECTATION=secure \
npm --prefix google-e2e run test:first-broker
trap - 0 1 2 15
echo "First Broker Login verified: unsafe AutoLink reproduced, Confirm Link restored"
-70
View File
@@ -1,70 +0,0 @@
#!/usr/bin/env sh
set -eu
if [ ! -f .env ]; then
echo "missing .env" >&2
exit 1
fi
set -a
. ./.env
set +a
keycloak_url="${KEYCLOAK_URL:-http://localhost:8080}"
admin_token="$(
curl -fsS \
-d client_id=admin-cli \
-d grant_type=password \
-d "username=$KC_BOOTSTRAP_ADMIN_USERNAME" \
-d "password=$KC_BOOTSTRAP_ADMIN_PASSWORD" \
"$keycloak_url/realms/master/protocol/openid-connect/token" |
jq -er .access_token
)"
idp="$(
curl -fsS \
-H "Authorization: Bearer $admin_token" \
"$keycloak_url/admin/realms/keycloak-patterns/identity-provider/instances/mock-google"
)"
printf '%s' "$idp" | jq -e '
.providerId == "oidc" and
.enabled == true and
.trustEmail == false and
.config.clientId == "mock-google-broker" and
.config.defaultScope == "openid profile email" and
.config.syncMode == "IMPORT" and
.config.validateSignature == "true"
' >/dev/null
client="$(
curl -fsS \
-H "Authorization: Bearer $admin_token" \
"$keycloak_url/admin/realms/mock-google/clients?clientId=mock-google-broker"
)"
printf '%s' "$client" | jq -e '
length == 1 and
.[0].publicClient == false and
(.[0].redirectUris | index(
"http://localhost:8080/realms/keycloak-patterns/broker/mock-google/endpoint"
)) != null
' >/dev/null
location="$(
curl -sS -D - -o /dev/null \
"$keycloak_url/realms/keycloak-patterns/protocol/openid-connect/auth?client_id=spa-public&redirect_uri=http%3A%2F%2Flocalhost%3A8088%2F&response_type=code&scope=openid&code_challenge=K2qUEfBl-nQvF2gB4dNxC2zYVwZc1CVnZb5CsX2L7fI&code_challenge_method=S256&kc_idp_hint=mock-google" |
awk 'BEGIN { IGNORECASE=1 } /^Location:/ { print $2 }' |
tr -d '\r'
)"
case "$location" in
"$keycloak_url/realms/keycloak-patterns/broker/mock-google/login"*) ;;
*)
echo "broker did not redirect to the controllable OIDC provider: $location" >&2
exit 1
;;
esac
echo "Google broker contract verified with the local mock OIDC realm"
+26
View File
@@ -0,0 +1,26 @@
#!/usr/bin/env sh
set -eu
if [ ! -f .env ]; then
echo "missing .env; copy .env.example and set development values" >&2
exit 1
fi
set -a
. ./.env
set +a
docker compose down --volumes --remove-orphans
docker compose up --build -d --wait
docker compose exec -T nginx nginx -V 2>&1 |
grep -q -- '--with-http_auth_request_module'
docker compose exec -T nginx nginx -T 2>&1 |
grep -q 'proxy_pass_request_body off'
npm --prefix e2e ci
E2E_USERNAME=regular-user \
E2E_PASSWORD="$REGULAR_USER_PASSWORD" \
npm --prefix e2e run test:pattern4
echo "AP4 Nginx auth_request edge flow verified"