Per-host SSO: Node auth endpoints + Redis session (#57)
Adds the /__proxy_auth OIDC flow served on every proxied host: - routes/host_auth.js: /start (PKCE+state, per-host redirect_uri), /callback (exchange, enforce the host allow-list via utils/host_sso.identityAllowed, mint session + set __proxy_sso cookie), /logout. - models/sso_session.js: SsoSession (Redis-backed, TTL'd; read directly by the Lua gate) and HostSsoState (in-flight auth request). - utils/oidc.js: per-host redirect_uri override on buildAuthUrl/exchangeCode. - conf.hostSso (reuses conf.oidc). Allow-list logic unit-tested. Enforcement (Lua gate + nginx location) lands next. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -77,4 +77,13 @@ module.exports = {
|
||||
'https://ifconfig.me/ip',
|
||||
],
|
||||
},
|
||||
|
||||
// Per-host SSO (#57). Reuses conf.oidc for the identity provider. Sessions
|
||||
// are Redis-backed and read directly by OpenResty; the cookie only carries a
|
||||
// random session id.
|
||||
hostSso:{
|
||||
enabled: true,
|
||||
sessionTtl: 28800, // 8 hours, in seconds
|
||||
cookieName: '__proxy_sso',
|
||||
},
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user