Files
proxy/nodejs/models/index.js
T
wmantly 87c0d024d5 Per-host SSO: Node auth endpoints + Redis session (#57)
Adds the /__proxy_auth OIDC flow served on every proxied host:
- routes/host_auth.js: /start (PKCE+state, per-host redirect_uri), /callback
  (exchange, enforce the host allow-list via utils/host_sso.identityAllowed,
  mint session + set __proxy_sso cookie), /logout.
- models/sso_session.js: SsoSession (Redis-backed, TTL'd; read directly by the
  Lua gate) and HostSsoState (in-flight auth request).
- utils/oidc.js: per-host redirect_uri override on buildAuthUrl/exchangeCode.
- conf.hostSso (reuses conf.oidc). Allow-list logic unit-tested.

Enforcement (Lua gate + nginx location) lands next.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-11 15:41:28 -04:00

18 lines
384 B
JavaScript

'use strict';
const conf = require('@simpleworkjs/conf');
const {setUpTable} = require('model-redis');
const Table = setUpTable(conf.redis);
module.exports = Table;
require('./dns_provider');
require('./dynamic_record');
require('./host');
require('./token');
require('./user');
require('./local_group');
require('./permission');
require('./oidc_state');
require('./sso_session');