Compare commits

...
Author SHA1 Message Date
donghyeon-ka 357b7f927b feat(ap4): integrate nginx auth_request 2026-07-25 14:55:04 +09:00
donghyeon-ka 5ce47689a9 merge: oauth2-proxy OIDC flow 2026-07-25 14:50:00 +09:00
7 changed files with 123 additions and 26 deletions
+4 -2
View File
@@ -107,8 +107,10 @@ gitignored `build/keycloak-export/`에 권한 `0600`으로만 저장됩니다.
```
첫 feature에서는 oauth2-proxy를 `http://localhost:4180`에 직접 노출해
OIDC redirect/PKCE/callback과 forwarded-user를 분리 확인합니다. 최종
구성은 `http://localhost:8088` Nginx 단일 진입점으로 사용합니다.
OIDC redirect/PKCE/callback과 forwarded-user를 분리 확인합니다. 두 번째
feature부터 `http://localhost:8088` Nginx 단일 진입점이며, 내부
`auth_request`는 브라우저 요청을 login 302로, API 요청을 JSON 401로
구분합니다. 최종 feature에서는 backend의 호스트 노출도 제거합니다.
자세한 내용은
[`docs/ap4-edge-forward-auth.md`](docs/ap4-edge-forward-auth.md)를
참고하세요.
+12 -6
View File
@@ -98,11 +98,13 @@ services:
- --oidc-jwks-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/certs
- --profile-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo
- --validate-url=http://keycloak:8080/realms/keycloak-patterns/protocol/openid-connect/userinfo
- --redirect-url=http://localhost:4180/oauth2/callback
- --redirect-url=http://localhost:8088/oauth2/callback
- --upstream=http://app:8081
- --email-domain=*
- --scope=openid profile email
- --code-challenge-method=S256
- --reverse-proxy=true
- --trusted-proxy-ip=172.30.40.10/32
- --cookie-name=AP4_SESSION
- --cookie-secure=false
- --cookie-samesite=lax
@@ -110,14 +112,14 @@ services:
- --skip-provider-button=true
- --set-xauthrequest=true
- --pass-user-headers=true
- --whitelist-domain=localhost:4180
- --whitelist-domain=localhost:8088
- --whitelist-domain=localhost:8080
environment:
OAUTH2_PROXY_CLIENT_ID: edge-proxy
OAUTH2_PROXY_CLIENT_SECRET: ${EDGE_PROXY_CLIENT_SECRET:?set EDGE_PROXY_CLIENT_SECRET in .env}
OAUTH2_PROXY_COOKIE_SECRET: ${OAUTH2_PROXY_COOKIE_SECRET:?set OAUTH2_PROXY_COOKIE_SECRET in .env}
ports:
- "127.0.0.1:4180:4180"
expose:
- "4180"
depends_on:
keycloak:
condition: service_healthy
@@ -142,7 +144,7 @@ services:
ports:
- "127.0.0.1:${NGINX_PORT:-8088}:80"
depends_on:
app:
oauth2-proxy:
condition: service_healthy
healthcheck:
test:
@@ -152,7 +154,8 @@ services:
timeout: 5s
retries: 12
networks:
- keycloak-net
keycloak-net:
ipv4_address: 172.30.40.10
restart: unless-stopped
volumes:
@@ -162,3 +165,6 @@ volumes:
networks:
keycloak-net:
driver: bridge
ipam:
config:
- subnet: 172.30.40.0/24
+20
View File
@@ -29,3 +29,23 @@ loopback에 publish되어 있습니다. 따라서 로컬에서 직접
`X-Forwarded-User: spoofed-admin`을 보내면 우회가 재현됩니다. 이후
Nginx `auth_request` 통합을 거쳐 최종 feature에서 backend no-publish와
내부 shared-secret 검증을 함께 적용합니다.
## 두 번째 단계: Nginx `auth_request`
`feature/keycloak-nginx-auth-request-integration`부터 외부 진입점은
`http://localhost:8088` Nginx 하나입니다. oauth2-proxy의 4180 포트는
Compose 네트워크에만 expose됩니다.
- Nginx의 정확 일치 `location = /oauth2/auth``internal`이라 외부에서
직접 호출할 수 없습니다.
- 인증 서브리퀘스트에는 본문을 보내지 않고 `Content-Length`
비웁니다.
- 일반 브라우저 요청의 401은 `/oauth2/start` 302로 변환합니다.
- API 요청 `/api/edge`는 redirect하지 않고 JSON 401을 반환합니다.
- 인증 성공 시 oauth2-proxy의 `X-Auth-Request-User`와 email만 backend로
전달합니다.
Nginx 컨테이너 IP를 전용 Compose subnet에서 고정하고 oauth2-proxy의
trusted proxy를 그 단일 IP로 제한합니다. 다만 이 단계에서는 backend
8081이 로컬 호스트에 열려 있어 신뢰 헤더를 직접 위조할 수 있습니다.
그 재현 조건은 마지막 feature에서 제거합니다.
+26 -9
View File
@@ -4,6 +4,9 @@ import { chromium } from "playwright-core";
const password = process.env.E2E_PASSWORD;
assert.ok(password, "E2E_PASSWORD must be set");
const edgeBaseUrl = "http://localhost:8088";
const edgeEntryUrl = `${edgeBaseUrl}/`;
async function completeKeycloakLogin(page) {
for (let attempt = 1; attempt <= 2; attempt += 1) {
await page.locator("#username").fill(
@@ -13,11 +16,11 @@ async function completeKeycloakLogin(page) {
await page.locator("#kc-login").click();
await page.waitForLoadState("domcontentloaded");
if (page.url() === "http://localhost:4180/edge/me") {
if (page.url() === edgeEntryUrl) {
return;
}
if (attempt === 1) {
await page.goto("http://localhost:4180/oauth2/start?rd=%2Fedge%2Fme");
await page.goto(`${edgeBaseUrl}/oauth2/start?rd=${encodeURIComponent(edgeEntryUrl)}`);
await page.waitForURL(/localhost:8080/u);
}
}
@@ -40,7 +43,7 @@ try {
const edgeResponsePromise = page.waitForResponse(
(response) =>
response.url() === "http://localhost:4180/edge/me" &&
response.url() === edgeEntryUrl &&
response.status() === 302,
);
const authorizationRequestPromise = page.waitForRequest((request) =>
@@ -48,7 +51,7 @@ try {
"/protocol/openid-connect/auth?approval_prompt=",
),
);
await page.goto("http://localhost:4180/edge/me");
await page.goto(edgeEntryUrl);
const unauthenticatedEdgeResponse = await edgeResponsePromise;
assert.equal(unauthenticatedEdgeResponse.status(), 302);
@@ -63,10 +66,10 @@ try {
const edgeIdentity = JSON.parse(await page.locator("body").innerText());
assert.equal(edgeIdentity.pattern, "AP4-edge-forward-auth");
assert.ok(edgeIdentity.user);
assert.equal(edgeIdentity.identityHeader, "X-Forwarded-User");
assert.equal(edgeIdentity.identityHeader, "X-Auth-Request-User");
const callbackRequest = browserRequests.find(({ url }) =>
url.startsWith("http://localhost:4180/oauth2/callback?"),
url.startsWith(`${edgeBaseUrl}/oauth2/callback?`),
);
assert.ok(callbackRequest);
assert.equal(callbackRequest.method, "GET");
@@ -78,7 +81,7 @@ try {
"the confidential token exchange must be server-to-server",
);
const cookies = await context.cookies("http://localhost:4180/");
const cookies = await context.cookies(edgeEntryUrl);
const sessionCookie = cookies.find((cookie) => cookie.name === "AP4_SESSION");
assert.ok(sessionCookie);
assert.equal(sessionCookie.httpOnly, true);
@@ -94,17 +97,31 @@ try {
assert.deepEqual(storage.sessionStorage, []);
assert.equal(storage.readableCookies.includes("AP4_SESSION"), false);
const externalAuthSubrequest = await fetch(`${edgeBaseUrl}/oauth2/auth`);
assert.equal(externalAuthSubrequest.status, 404);
const apiResponse = await fetch(`${edgeBaseUrl}/api/edge`, {
redirect: "manual",
});
assert.equal(apiResponse.status, 401);
assert.equal(apiResponse.headers.get("location"), null);
await assert.rejects(
fetch("http://localhost:4180/ping"),
"oauth2-proxy must not be published on the host",
);
const missingHeader = await fetch("http://localhost:8081/edge/me");
assert.equal(missingHeader.status, 401);
const directSpoof = await fetch("http://localhost:8081/edge/me", {
headers: { "X-Forwarded-User": "spoofed-admin" },
headers: { "X-Auth-Request-User": "spoofed-admin" },
});
assert.equal(directSpoof.status, 200);
const spoofedIdentity = await directSpoof.json();
assert.equal(spoofedIdentity.user, "spoofed-admin");
console.log(
"pattern4 oauth2-proxy verified: redirect, PKCE login, forwarded-user 200, direct spoof precondition",
"pattern4 nginx auth_request verified: internal subrequest, browser redirect, API 401, forwarded identity",
);
} finally {
await browser.close();
+54 -7
View File
@@ -2,8 +2,7 @@ server {
listen 80;
server_name _;
root /usr/share/nginx/html;
index index.html;
large_client_header_buffers 4 16k;
location = /health {
access_log off;
@@ -11,16 +10,64 @@ server {
return 200 "ok\n";
}
location /api/ {
proxy_pass http://app:8081;
proxy_http_version 1.1;
proxy_set_header Host $host;
location = /oauth2/auth {
internal;
proxy_pass http://oauth2-proxy:4180;
proxy_pass_request_body off;
proxy_set_header Content-Length "";
proxy_set_header X-Original-URL $scheme://$http_host$request_uri;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Uri $request_uri;
}
location /oauth2/ {
proxy_pass http://oauth2-proxy:4180;
proxy_http_version 1.1;
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $http_host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Auth-Request-Redirect $scheme://$http_host$request_uri;
}
location = /api/edge {
auth_request /oauth2/auth;
error_page 401 = @api_unauthorized;
auth_request_set $auth_user $upstream_http_x_auth_request_user;
auth_request_set $auth_email $upstream_http_x_auth_request_email;
auth_request_set $auth_cookie $upstream_http_set_cookie;
add_header Set-Cookie $auth_cookie always;
proxy_pass http://app:8081/edge/me;
proxy_set_header X-Auth-Request-User $auth_user;
proxy_set_header X-Auth-Request-Email $auth_email;
}
location / {
try_files $uri $uri/ /index.html;
auth_request /oauth2/auth;
error_page 401 = @oauth2_signin;
auth_request_set $auth_user $upstream_http_x_auth_request_user;
auth_request_set $auth_email $upstream_http_x_auth_request_email;
auth_request_set $auth_cookie $upstream_http_set_cookie;
add_header Set-Cookie $auth_cookie always;
proxy_pass http://app:8081/edge/me;
proxy_set_header X-Auth-Request-User $auth_user;
proxy_set_header X-Auth-Request-Email $auth_email;
}
location @oauth2_signin {
return 302 $scheme://$http_host/oauth2/start?rd=$scheme://$http_host$request_uri;
}
location @api_unauthorized {
default_type application/json;
return 401 '{"error":"authentication required"}';
}
}
+1 -1
View File
@@ -116,7 +116,7 @@
"serviceAccountsEnabled": false,
"frontchannelLogout": true,
"redirectUris": [
"http://localhost:4180/oauth2/callback"
"http://localhost:8088/oauth2/callback"
],
"webOrigins": [],
"attributes": {
+6 -1
View File
@@ -13,9 +13,14 @@ set +a
docker compose down --volumes --remove-orphans
docker compose up --build -d --wait
docker compose exec -T nginx nginx -V 2>&1 |
grep -q -- '--with-http_auth_request_module'
docker compose exec -T nginx nginx -T 2>&1 |
grep -q 'proxy_pass_request_body off'
npm --prefix e2e ci
E2E_USERNAME=regular-user \
E2E_PASSWORD="$REGULAR_USER_PASSWORD" \
npm --prefix e2e run test:pattern4
echo "AP4 oauth2-proxy edge flow verified"
echo "AP4 Nginx auth_request edge flow verified"