Compare commits

...
13 changed files with 253 additions and 74 deletions
+1
View File
@@ -11,6 +11,7 @@ TOKEN_MEDIATING_CLIENT_SECRET=change-me-token-mediating-client-secret
BFF_CLIENT_SECRET=change-me-bff-client-secret BFF_CLIENT_SECRET=change-me-bff-client-secret
EDGE_PROXY_CLIENT_SECRET=change-me-edge-proxy-client-secret EDGE_PROXY_CLIENT_SECRET=change-me-edge-proxy-client-secret
OAUTH2_PROXY_COOKIE_SECRET=generate-a-base64-encoded-32-byte-secret OAUTH2_PROXY_COOKIE_SECRET=generate-a-base64-encoded-32-byte-secret
INTERNAL_AUTH_TOKEN=generate-a-long-random-edge-to-backend-token
ADMIN_USER_PASSWORD=change-me-admin-user-password ADMIN_USER_PASSWORD=change-me-admin-user-password
REGULAR_USER_PASSWORD=change-me-regular-user-password REGULAR_USER_PASSWORD=change-me-regular-user-password
+5 -2
View File
@@ -107,8 +107,11 @@ gitignored `build/keycloak-export/`에 권한 `0600`으로만 저장됩니다.
``` ```
첫 feature에서는 oauth2-proxy를 `http://localhost:4180`에 직접 노출해 첫 feature에서는 oauth2-proxy를 `http://localhost:4180`에 직접 노출해
OIDC redirect/PKCE/callback과 forwarded-user를 분리 확인합니다. 최종 OIDC redirect/PKCE/callback과 forwarded-user를 분리 확인합니다. 두 번째
구성은 `http://localhost:8088` Nginx 단일 진입점으로 사용합니다. feature부터 `http://localhost:8088` Nginx 단일 진입점이며, 내부
`auth_request`는 브라우저 요청을 login 302로, API 요청을 JSON 401로
구분합니다. 최종 feature에서는 backend와 oauth2-proxy의 호스트 노출을
제거하고 Nginx 헤더 덮어쓰기와 내부 토큰 검증으로 spoofing을 막습니다.
자세한 내용은 자세한 내용은
[`docs/ap4-edge-forward-auth.md`](docs/ap4-edge-forward-auth.md)를 [`docs/ap4-edge-forward-auth.md`](docs/ap4-edge-forward-auth.md)를
참고하세요. 참고하세요.
@@ -1,44 +1,56 @@
package com.example.keycloakpattern; package com.example.keycloakpattern;
import java.nio.charset.StandardCharsets;
import java.security.MessageDigest;
import java.util.LinkedHashMap; import java.util.LinkedHashMap;
import java.util.Map; import java.util.Map;
import jakarta.servlet.http.HttpServletRequest; import jakarta.servlet.http.HttpServletRequest;
import org.springframework.http.ResponseEntity; import org.springframework.http.ResponseEntity;
import org.springframework.beans.factory.annotation.Value;
import org.springframework.web.bind.annotation.GetMapping; import org.springframework.web.bind.annotation.GetMapping;
import org.springframework.web.bind.annotation.RestController; import org.springframework.web.bind.annotation.RestController;
@RestController @RestController
public class EdgeIdentityController { public class EdgeIdentityController {
private final byte[] internalAuthToken;
EdgeIdentityController(@Value("${edge.internal-auth-token}") String internalAuthToken) {
if (!hasText(internalAuthToken)) {
throw new IllegalStateException("edge.internal-auth-token must be configured");
}
this.internalAuthToken = internalAuthToken.getBytes(StandardCharsets.UTF_8);
}
@GetMapping("/edge/me") @GetMapping("/edge/me")
ResponseEntity<Map<String, Object>> currentUser(HttpServletRequest request) { ResponseEntity<Map<String, Object>> currentUser(HttpServletRequest request) {
String authRequestUser = request.getHeader("X-Auth-Request-User"); String authRequestUser = request.getHeader("X-Auth-Request-User");
String forwardedUser = request.getHeader("X-Forwarded-User"); if (!hasText(authRequestUser) || !hasValidInternalToken(request)) {
String user = hasText(authRequestUser) ? authRequestUser : forwardedUser;
if (!hasText(user)) {
return ResponseEntity.status(401).body(Map.of( return ResponseEntity.status(401).body(Map.of(
"error", "error",
"trusted edge identity header is required" "trusted edge authentication is required"
)); ));
} }
Map<String, Object> response = new LinkedHashMap<>(); Map<String, Object> response = new LinkedHashMap<>();
response.put("pattern", "AP4-edge-forward-auth"); response.put("pattern", "AP4-edge-forward-auth");
response.put("user", user); response.put("user", authRequestUser);
response.put("email", firstNonBlank( response.put("email", request.getHeader("X-Auth-Request-Email"));
request.getHeader("X-Auth-Request-Email"), response.put("identityHeader", "X-Auth-Request-User");
request.getHeader("X-Forwarded-Email")
));
response.put("identityHeader", hasText(authRequestUser)
? "X-Auth-Request-User"
: "X-Forwarded-User");
return ResponseEntity.ok(response); return ResponseEntity.ok(response);
} }
private static String firstNonBlank(String first, String second) { private boolean hasValidInternalToken(HttpServletRequest request) {
return hasText(first) ? first : second; String suppliedToken = request.getHeader("X-Internal-Auth-Token");
if (!hasText(suppliedToken)) {
return false;
}
return MessageDigest.isEqual(
internalAuthToken,
suppliedToken.getBytes(StandardCharsets.UTF_8)
);
} }
private static boolean hasText(String value) { private static boolean hasText(String value) {
@@ -1,6 +1,9 @@
server: server:
port: ${SERVER_PORT:8081} port: ${SERVER_PORT:8081}
edge:
internal-auth-token: ${EDGE_INTERNAL_AUTH_TOKEN:}
spring: spring:
application: application:
name: keycloak-pattern-api name: keycloak-pattern-api
@@ -11,7 +11,7 @@ import org.springframework.boot.test.autoconfigure.web.servlet.AutoConfigureMock
import org.springframework.boot.test.context.SpringBootTest; import org.springframework.boot.test.context.SpringBootTest;
import org.springframework.test.web.servlet.MockMvc; import org.springframework.test.web.servlet.MockMvc;
@SpringBootTest @SpringBootTest(properties = "edge.internal-auth-token=test-internal-edge-token")
@AutoConfigureMockMvc @AutoConfigureMockMvc
class ApiSecurityTest { class ApiSecurityTest {
@@ -42,18 +42,34 @@ class ApiSecurityTest {
} }
@Test @Test
void edgeEndpointRejectsMissingIdentityHeader() throws Exception { void edgeEndpointRejectsMissingTrustedHeaders() throws Exception {
mockMvc.perform(get("/edge/me")) mockMvc.perform(get("/edge/me"))
.andExpect(status().isUnauthorized()); .andExpect(status().isUnauthorized());
} }
@Test @Test
void edgeEndpointCurrentlyTrustsForwardedUserHeader() throws Exception { void edgeEndpointRejectsForgedIdentityWithoutInternalToken() throws Exception {
mockMvc.perform(get("/edge/me") mockMvc.perform(get("/edge/me")
.header("X-Forwarded-User", "regular-user") .header("X-Auth-Request-User", "spoofed-admin"))
.header("X-Forwarded-Email", "regular-user@example.test")) .andExpect(status().isUnauthorized());
}
@Test
void edgeEndpointRejectsWrongInternalToken() throws Exception {
mockMvc.perform(get("/edge/me")
.header("X-Auth-Request-User", "spoofed-admin")
.header("X-Internal-Auth-Token", "wrong-token"))
.andExpect(status().isUnauthorized());
}
@Test
void edgeEndpointAcceptsIdentityFromTrustedEdge() throws Exception {
mockMvc.perform(get("/edge/me")
.header("X-Auth-Request-User", "regular-user")
.header("X-Auth-Request-Email", "regular-user@example.test")
.header("X-Internal-Auth-Token", "test-internal-edge-token"))
.andExpect(status().isOk()) .andExpect(status().isOk())
.andExpect(jsonPath("$.user").value("regular-user")) .andExpect(jsonPath("$.user").value("regular-user"))
.andExpect(jsonPath("$.identityHeader").value("X-Forwarded-User")); .andExpect(jsonPath("$.identityHeader").value("X-Auth-Request-User"));
} }
} }
+17 -8
View File
@@ -69,8 +69,9 @@ services:
SERVER_PORT: "8081" SERVER_PORT: "8081"
SPRING_SECURITY_OAUTH2_RESOURCESERVER_JWT_ISSUER_URI: http://localhost:8080/realms/keycloak-patterns SPRING_SECURITY_OAUTH2_RESOURCESERVER_JWT_ISSUER_URI: http://localhost:8080/realms/keycloak-patterns
SPRING_SECURITY_OAUTH2_RESOURCESERVER_JWT_JWK_SET_URI: http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/certs SPRING_SECURITY_OAUTH2_RESOURCESERVER_JWT_JWK_SET_URI: http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/certs
ports: EDGE_INTERNAL_AUTH_TOKEN: ${INTERNAL_AUTH_TOKEN:?set INTERNAL_AUTH_TOKEN in .env}
- "127.0.0.1:8081:8081" expose:
- "8081"
depends_on: depends_on:
keycloak: keycloak:
condition: service_healthy condition: service_healthy
@@ -98,11 +99,13 @@ services:
- --oidc-jwks-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/certs - --oidc-jwks-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/certs
- --profile-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo - --profile-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo
- --validate-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo - --validate-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo
- --redirect-url=http://localhost:4180/oauth2/callback - --redirect-url=http://localhost:8088/oauth2/callback
- --upstream=http://app:8081 - --upstream=http://app:8081
- --email-domain=* - --email-domain=*
- --scope=openid profile email - --scope=openid profile email
- --code-challenge-method=S256 - --code-challenge-method=S256
- --reverse-proxy=true
- --trusted-proxy-ip=172.30.40.10/32
- --cookie-name=AP4_SESSION - --cookie-name=AP4_SESSION
- --cookie-secure=false - --cookie-secure=false
- --cookie-samesite=lax - --cookie-samesite=lax
@@ -110,14 +113,14 @@ services:
- --skip-provider-button=true - --skip-provider-button=true
- --set-xauthrequest=true - --set-xauthrequest=true
- --pass-user-headers=true - --pass-user-headers=true
- --whitelist-domain=localhost:4180 - --whitelist-domain=localhost:8088
- --whitelist-domain=localhost:8080 - --whitelist-domain=localhost:8080
environment: environment:
OAUTH2_PROXY_CLIENT_ID: edge-proxy OAUTH2_PROXY_CLIENT_ID: edge-proxy
OAUTH2_PROXY_CLIENT_SECRET: ${EDGE_PROXY_CLIENT_SECRET:?set EDGE_PROXY_CLIENT_SECRET in .env} OAUTH2_PROXY_CLIENT_SECRET: ${EDGE_PROXY_CLIENT_SECRET:?set EDGE_PROXY_CLIENT_SECRET in .env}
OAUTH2_PROXY_COOKIE_SECRET: ${OAUTH2_PROXY_COOKIE_SECRET:?set OAUTH2_PROXY_COOKIE_SECRET in .env} OAUTH2_PROXY_COOKIE_SECRET: ${OAUTH2_PROXY_COOKIE_SECRET:?set OAUTH2_PROXY_COOKIE_SECRET in .env}
ports: expose:
- "127.0.0.1:4180:4180" - "4180"
depends_on: depends_on:
keycloak: keycloak:
condition: service_healthy condition: service_healthy
@@ -139,10 +142,12 @@ services:
nginx: nginx:
build: build:
context: ./frontend context: ./frontend
environment:
INTERNAL_AUTH_TOKEN: ${INTERNAL_AUTH_TOKEN:?set INTERNAL_AUTH_TOKEN in .env}
ports: ports:
- "127.0.0.1:${NGINX_PORT:-8088}:80" - "127.0.0.1:${NGINX_PORT:-8088}:80"
depends_on: depends_on:
app: oauth2-proxy:
condition: service_healthy condition: service_healthy
healthcheck: healthcheck:
test: test:
@@ -152,7 +157,8 @@ services:
timeout: 5s timeout: 5s
retries: 12 retries: 12
networks: networks:
- keycloak-net keycloak-net:
ipv4_address: 172.30.40.10
restart: unless-stopped restart: unless-stopped
volumes: volumes:
@@ -162,3 +168,6 @@ volumes:
networks: networks:
keycloak-net: keycloak-net:
driver: bridge driver: bridge
ipam:
config:
- subnet: 172.30.40.0/24
+39
View File
@@ -29,3 +29,42 @@ loopback에 publish되어 있습니다. 따라서 로컬에서 직접
`X-Forwarded-User: spoofed-admin`을 보내면 우회가 재현됩니다. 이후 `X-Forwarded-User: spoofed-admin`을 보내면 우회가 재현됩니다. 이후
Nginx `auth_request` 통합을 거쳐 최종 feature에서 backend no-publish와 Nginx `auth_request` 통합을 거쳐 최종 feature에서 backend no-publish와
내부 shared-secret 검증을 함께 적용합니다. 내부 shared-secret 검증을 함께 적용합니다.
## 두 번째 단계: Nginx `auth_request`
`feature/keycloak-nginx-auth-request-integration`부터 외부 진입점은
`http://localhost:8088` Nginx 하나입니다. oauth2-proxy의 4180 포트는
Compose 네트워크에만 expose됩니다.
- Nginx의 정확 일치 `location = /oauth2/auth``internal`이라 외부에서
직접 호출할 수 없습니다.
- 인증 서브리퀘스트에는 본문을 보내지 않고 `Content-Length`
비웁니다.
- 일반 브라우저 요청의 401은 `/oauth2/start` 302로 변환합니다.
- API 요청 `/api/edge`는 redirect하지 않고 JSON 401을 반환합니다.
- 인증 성공 시 oauth2-proxy의 `X-Auth-Request-User`와 email만 backend로
전달합니다.
Nginx 컨테이너 IP를 전용 Compose subnet에서 고정하고 oauth2-proxy의
trusted proxy를 그 단일 IP로 제한합니다. 다만 이 단계에서는 backend
8081이 로컬 호스트에 열려 있어 신뢰 헤더를 직접 위조할 수 있습니다.
그 재현 조건은 마지막 feature에서 제거합니다.
## 마지막 단계: 신뢰 경계와 헤더 스푸핑 방어
`feature/keycloak-header-spoofing-defense`에서는 신뢰 경계를 실제
네트워크와 application 양쪽에서 강제합니다.
1. backend 8081과 oauth2-proxy 4180은 host에 publish하지 않습니다.
브라우저가 접근 가능한 application 포트는 Nginx 8088뿐입니다.
2. Nginx는 client가 보낸 `X-Auth-Request-User`, email, 내부 토큰을
그대로 전달하지 않고 oauth2-proxy 결과와 server-side 토큰으로
항상 덮어씁니다.
3. backend는 `X-Auth-Request-User``X-Internal-Auth-Token`이 모두
유효할 때만 edge identity를 받아들이며 token은 constant-time으로
비교합니다.
shared token은 방어 심층화 수단입니다. 운영에서는 Secret Manager나
orchestrator secret으로 주입하고 주기적으로 교체해야 합니다. 서비스
간 mTLS 또는 service mesh identity를 사용할 수 있다면 단순 shared
token보다 강한 workload identity로 대체하는 편이 좋습니다.
+42 -15
View File
@@ -4,6 +4,9 @@ import { chromium } from "playwright-core";
const password = process.env.E2E_PASSWORD; const password = process.env.E2E_PASSWORD;
assert.ok(password, "E2E_PASSWORD must be set"); assert.ok(password, "E2E_PASSWORD must be set");
const edgeBaseUrl = "http://localhost:8088";
const edgeEntryUrl = `${edgeBaseUrl}/`;
async function completeKeycloakLogin(page) { async function completeKeycloakLogin(page) {
for (let attempt = 1; attempt <= 2; attempt += 1) { for (let attempt = 1; attempt <= 2; attempt += 1) {
await page.locator("#username").fill( await page.locator("#username").fill(
@@ -13,11 +16,11 @@ async function completeKeycloakLogin(page) {
await page.locator("#kc-login").click(); await page.locator("#kc-login").click();
await page.waitForLoadState("domcontentloaded"); await page.waitForLoadState("domcontentloaded");
if (page.url() === "http://localhost:4180/edge/me") { if (page.url() === edgeEntryUrl) {
return; return;
} }
if (attempt === 1) { if (attempt === 1) {
await page.goto("http://localhost:4180/oauth2/start?rd=%2Fedge%2Fme"); await page.goto(`${edgeBaseUrl}/oauth2/start?rd=${encodeURIComponent(edgeEntryUrl)}`);
await page.waitForURL(/localhost:8080/u); await page.waitForURL(/localhost:8080/u);
} }
} }
@@ -40,7 +43,7 @@ try {
const edgeResponsePromise = page.waitForResponse( const edgeResponsePromise = page.waitForResponse(
(response) => (response) =>
response.url() === "http://localhost:4180/edge/me" && response.url() === edgeEntryUrl &&
response.status() === 302, response.status() === 302,
); );
const authorizationRequestPromise = page.waitForRequest((request) => const authorizationRequestPromise = page.waitForRequest((request) =>
@@ -48,7 +51,7 @@ try {
"/protocol/openid-connect/auth?approval_prompt=", "/protocol/openid-connect/auth?approval_prompt=",
), ),
); );
await page.goto("http://localhost:4180/edge/me"); await page.goto(edgeEntryUrl);
const unauthenticatedEdgeResponse = await edgeResponsePromise; const unauthenticatedEdgeResponse = await edgeResponsePromise;
assert.equal(unauthenticatedEdgeResponse.status(), 302); assert.equal(unauthenticatedEdgeResponse.status(), 302);
@@ -63,10 +66,10 @@ try {
const edgeIdentity = JSON.parse(await page.locator("body").innerText()); const edgeIdentity = JSON.parse(await page.locator("body").innerText());
assert.equal(edgeIdentity.pattern, "AP4-edge-forward-auth"); assert.equal(edgeIdentity.pattern, "AP4-edge-forward-auth");
assert.ok(edgeIdentity.user); assert.ok(edgeIdentity.user);
assert.equal(edgeIdentity.identityHeader, "X-Forwarded-User"); assert.equal(edgeIdentity.identityHeader, "X-Auth-Request-User");
const callbackRequest = browserRequests.find(({ url }) => const callbackRequest = browserRequests.find(({ url }) =>
url.startsWith("http://localhost:4180/oauth2/callback?"), url.startsWith(`${edgeBaseUrl}/oauth2/callback?`),
); );
assert.ok(callbackRequest); assert.ok(callbackRequest);
assert.equal(callbackRequest.method, "GET"); assert.equal(callbackRequest.method, "GET");
@@ -78,7 +81,7 @@ try {
"the confidential token exchange must be server-to-server", "the confidential token exchange must be server-to-server",
); );
const cookies = await context.cookies("http://localhost:4180/"); const cookies = await context.cookies(edgeEntryUrl);
const sessionCookie = cookies.find((cookie) => cookie.name === "AP4_SESSION"); const sessionCookie = cookies.find((cookie) => cookie.name === "AP4_SESSION");
assert.ok(sessionCookie); assert.ok(sessionCookie);
assert.equal(sessionCookie.httpOnly, true); assert.equal(sessionCookie.httpOnly, true);
@@ -94,17 +97,41 @@ try {
assert.deepEqual(storage.sessionStorage, []); assert.deepEqual(storage.sessionStorage, []);
assert.equal(storage.readableCookies.includes("AP4_SESSION"), false); assert.equal(storage.readableCookies.includes("AP4_SESSION"), false);
const missingHeader = await fetch("http://localhost:8081/edge/me"); const spoofAttempt = await page.evaluate(async () => {
assert.equal(missingHeader.status, 401); const response = await fetch("/", {
const directSpoof = await fetch("http://localhost:8081/edge/me", { headers: {
headers: { "X-Forwarded-User": "spoofed-admin" }, "X-Auth-Request-User": "spoofed-admin",
"X-Auth-Request-Email": "spoofed-admin@example.test",
"X-Internal-Auth-Token": "attacker-controlled-token",
},
}); });
assert.equal(directSpoof.status, 200); return { status: response.status, body: await response.json() };
const spoofedIdentity = await directSpoof.json(); });
assert.equal(spoofedIdentity.user, "spoofed-admin"); assert.equal(spoofAttempt.status, 200);
assert.equal(spoofAttempt.body.user, edgeIdentity.user);
assert.notEqual(spoofAttempt.body.user, "spoofed-admin");
const externalAuthSubrequest = await fetch(`${edgeBaseUrl}/oauth2/auth`);
assert.equal(externalAuthSubrequest.status, 404);
const apiResponse = await fetch(`${edgeBaseUrl}/api/edge`, {
redirect: "manual",
});
assert.equal(apiResponse.status, 401);
assert.equal(apiResponse.headers.get("location"), null);
await assert.rejects(
fetch("http://localhost:4180/ping"),
"oauth2-proxy must not be published on the host",
);
await assert.rejects(
fetch("http://localhost:8081/edge/me"),
"backend must not be published on the host",
);
console.log( console.log(
"pattern4 oauth2-proxy verified: redirect, PKCE login, forwarded-user 200, direct spoof precondition", "pattern4 hardened edge verified: auth_request, no backend publish, spoofed headers overwritten",
); );
} finally { } finally {
await browser.close(); await browser.close();
+1 -1
View File
@@ -1,4 +1,4 @@
FROM nginx:1.29-alpine FROM nginx:1.29-alpine
COPY nginx.conf /etc/nginx/conf.d/default.conf COPY default.conf.template /etc/nginx/templates/default.conf.template
COPY index.html /usr/share/nginx/html/index.html COPY index.html /usr/share/nginx/html/index.html
+75
View File
@@ -0,0 +1,75 @@
server {
listen 80;
server_name _;
large_client_header_buffers 4 16k;
location = /health {
access_log off;
default_type text/plain;
return 200 "ok\n";
}
location = /oauth2/auth {
internal;
proxy_pass http://oauth2-proxy:4180;
proxy_pass_request_body off;
proxy_set_header Content-Length "";
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Uri $request_uri;
}
location /oauth2/ {
proxy_pass http://oauth2-proxy:4180;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Auth-Request-Redirect $scheme://$http_host$request_uri;
}
location = /api/edge {
auth_request /oauth2/auth;
error_page 401 = @api_unauthorized;
auth_request_set $auth_user $upstream_http_x_auth_request_user;
auth_request_set $auth_email $upstream_http_x_auth_request_email;
auth_request_set $auth_cookie $upstream_http_set_cookie;
add_header Set-Cookie $auth_cookie always;
proxy_pass http://app:8081/edge/me;
proxy_set_header X-Auth-Request-User $auth_user;
proxy_set_header X-Auth-Request-Email $auth_email;
proxy_set_header X-Internal-Auth-Token "${INTERNAL_AUTH_TOKEN}";
}
location / {
auth_request /oauth2/auth;
error_page 401 = @oauth2_signin;
auth_request_set $auth_user $upstream_http_x_auth_request_user;
auth_request_set $auth_email $upstream_http_x_auth_request_email;
auth_request_set $auth_cookie $upstream_http_set_cookie;
add_header Set-Cookie $auth_cookie always;
proxy_pass http://app:8081/edge/me;
proxy_set_header X-Auth-Request-User $auth_user;
proxy_set_header X-Auth-Request-Email $auth_email;
proxy_set_header X-Internal-Auth-Token "${INTERNAL_AUTH_TOKEN}";
}
location @oauth2_signin {
return 302 $scheme://$http_host/oauth2/start?rd=$scheme://$http_host$request_uri;
}
location @api_unauthorized {
default_type application/json;
return 401 '{"error":"authentication required"}';
}
}
-26
View File
@@ -1,26 +0,0 @@
server {
listen 80;
server_name _;
root /usr/share/nginx/html;
index index.html;
location = /health {
access_log off;
default_type text/plain;
return 200 "ok\n";
}
location /api/ {
proxy_pass http://app:8081;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
location / {
try_files $uri $uri/ /index.html;
}
}
+1 -1
View File
@@ -116,7 +116,7 @@
"serviceAccountsEnabled": false, "serviceAccountsEnabled": false,
"frontchannelLogout": true, "frontchannelLogout": true,
"redirectUris": [ "redirectUris": [
"http://localhost:4180/oauth2/callback" "http://localhost:8088/oauth2/callback"
], ],
"webOrigins": [], "webOrigins": [],
"attributes": { "attributes": {
+21 -1
View File
@@ -13,9 +13,29 @@ set +a
docker compose down --volumes --remove-orphans docker compose down --volumes --remove-orphans
docker compose up --build -d --wait docker compose up --build -d --wait
docker compose exec -T nginx nginx -V 2>&1 |
grep -q -- '--with-http_auth_request_module'
docker compose exec -T nginx nginx -T 2>&1 |
grep -q 'proxy_pass_request_body off'
app_container_id="$(docker compose ps -q app)"
published_app_port="$(docker inspect "$app_container_id" \
--format '{{with (index .NetworkSettings.Ports "8081/tcp")}}{{json .}}{{end}}')"
if [ -n "$published_app_port" ]; then
echo "backend port 8081 must not be published on the host" >&2
exit 1
fi
if docker compose exec -T nginx wget -q -O /dev/null \
--header 'X-Auth-Request-User: spoofed-admin' \
http://app:8081/edge/me 2>/dev/null; then
echo "backend accepted a forged identity without the internal token" >&2
exit 1
fi
npm --prefix e2e ci npm --prefix e2e ci
E2E_USERNAME=regular-user \ E2E_USERNAME=regular-user \
E2E_PASSWORD="$REGULAR_USER_PASSWORD" \ E2E_PASSWORD="$REGULAR_USER_PASSWORD" \
npm --prefix e2e run test:pattern4 npm --prefix e2e run test:pattern4
echo "AP4 oauth2-proxy edge flow verified" echo "AP4 hardened Nginx auth_request edge flow verified"