Auth separate client if token not set
This commit is contained in:
parent
d17861bf84
commit
db281d3219
@ -75,30 +75,36 @@ http {
|
|||||||
location /pacs-admin/ {
|
location /pacs-admin/ {
|
||||||
access_by_lua_block {
|
access_by_lua_block {
|
||||||
local opts = {
|
local opts = {
|
||||||
redirect_uri = "http://127.0.0.1/callback",
|
redirect_uri = "http://127.0.0.1/pacs-admin/admin",
|
||||||
discovery = "http://127.0.0.1/auth/realms/master/.well-known/openid-configuration",
|
discovery = "http://127.0.0.1/auth/realms/master/.well-known/openid-configuration",
|
||||||
|
token_endpoint_auth_method = "client_secret_basic",
|
||||||
client_id = "pacs",
|
client_id = "pacs",
|
||||||
client_secret = "a726f5b1-5abd-42c9-b7b1-53a1a17d2ad2",
|
client_secret = "a726f5b1-5abd-42c9-b7b1-53a1a17d2ad2",
|
||||||
|
client_jwt_assertion_expires_in = 60 * 60,
|
||||||
ssl_verify = "no",
|
ssl_verify = "no",
|
||||||
redirect_uri_scheme = "http"
|
scope = "openid email profile",
|
||||||
|
refresh_session_interval = 900,
|
||||||
|
redirect_uri_scheme = "http",
|
||||||
|
redirect_after_logout_uri = "/",
|
||||||
|
session_contents = {id_token=true}
|
||||||
}
|
}
|
||||||
|
|
||||||
-- call authenticate for OpenID Connect user authentication
|
-- call authenticate for OpenID Connect user authentication
|
||||||
local res, err = require("resty.openidc").authenticate(opts)
|
local res, err = require("resty.openidc").authenticate(opts)
|
||||||
|
|
||||||
-- check session, but do not redirect to auth if not already logged in
|
if err or not res then
|
||||||
-- local res, err = require("resty.openidc").authenticate(opts, nil, "pass")
|
|
||||||
|
|
||||||
if err then
|
|
||||||
ngx.print(err)
|
ngx.print(err)
|
||||||
ngx.status = 200
|
ngx.status = 200
|
||||||
ngx.say(err)
|
ngx.say(err and err or "no access_token provided")
|
||||||
ngx.exit(ngx.HTTP_INTERNAL_SERVER_ERROR)
|
ngx.exit(ngx.HTTP_FORBIDDEN)
|
||||||
end
|
end
|
||||||
|
|
||||||
|
-- Or set cookie?
|
||||||
|
-- ngx.req.set_header("Authorization", "Bearer " .. res.access_token)
|
||||||
ngx.req.set_header("X-USER", res.id_token.sub)
|
ngx.req.set_header("X-USER", res.id_token.sub)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
proxy_http_version 1.1;
|
proxy_http_version 1.1;
|
||||||
|
|
||||||
proxy_set_header Host $host;
|
proxy_set_header Host $host;
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user