mirror of
https://github.com/NginxProxyManager/nginx-proxy-manager.git
synced 2025-05-03 04:22:28 +00:00
* add `oidc-config` setting allowing an admin user to configure parameters * modify login page to show another button when oidc is configured * add dependency `openid-client` `v5.4.0` * add backend route to process "OAuth2 Authorization Code" flow initialisation * add backend route to process callback of above flow * sign in the authenticated user with internal jwt token if internal user with email matching the one retrieved from oauth claims exists Note: Only Open ID Connect Discovery is supported which most modern Identity Providers offer. Tested with Authentik 2023.2.2 and Keycloak 18.0.2
57 lines
1.4 KiB
JavaScript
57 lines
1.4 KiB
JavaScript
const express = require('express');
|
|
const jwtdecode = require('../../lib/express/jwt-decode');
|
|
const internalToken = require('../../internal/token');
|
|
const apiValidator = require('../../lib/validator/api');
|
|
|
|
let router = express.Router({
|
|
caseSensitive: true,
|
|
strict: true,
|
|
mergeParams: true
|
|
});
|
|
|
|
router
|
|
.route('/')
|
|
.options((req, res) => {
|
|
res.sendStatus(204);
|
|
})
|
|
|
|
/**
|
|
* GET /tokens
|
|
*
|
|
* Get a new Token, given they already have a token they want to refresh
|
|
* We also piggy back on to this method, allowing admins to get tokens
|
|
* for services like Job board and Worker.
|
|
*/
|
|
.get(jwtdecode(), (req, res, next) => {
|
|
internalToken.getFreshToken(res.locals.access, {
|
|
expiry: (typeof req.query.expiry !== 'undefined' ? req.query.expiry : null),
|
|
scope: (typeof req.query.scope !== 'undefined' ? req.query.scope : null)
|
|
})
|
|
.then((data) => {
|
|
// clear this temporary cookie following a successful oidc authentication
|
|
res.clearCookie('npm_oidc');
|
|
res.status(200)
|
|
.send(data);
|
|
})
|
|
.catch(next);
|
|
})
|
|
|
|
/**
|
|
* POST /tokens
|
|
*
|
|
* Create a new Token
|
|
*/
|
|
.post((req, res, next) => {
|
|
apiValidator({$ref: 'endpoints/tokens#/links/0/schema'}, req.body)
|
|
.then((payload) => {
|
|
return internalToken.getTokenFromEmail(payload);
|
|
})
|
|
.then((data) => {
|
|
res.status(200)
|
|
.send(data);
|
|
})
|
|
.catch(next);
|
|
});
|
|
|
|
module.exports = router;
|