Skip to content

Commit f0daeb4

Browse files
committed
(WIP) authssobackend: support subroots
1 parent 2b1b41a commit f0daeb4

4 files changed

Lines changed: 15 additions & 2 deletions

File tree

‎go.mod‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ require (
1414
github.com/function61/certbus v0.0.0-20260822115830-9d8c749d7a41
1515
github.com/function61/eventhorizon v0.2.1-0.20260822112641-bdf8d2936b7f
1616
github.com/function61/gokit v0.0.0-20260822195148-784934b22880
17-
github.com/function61/id v0.0.0-20260818190447-5b4cdbaa3020
17+
github.com/function61/id v0.0.0-20260824122525-b9d5a88d2b97
1818
github.com/peterbourgon/diskv v2.0.1+incompatible
1919
github.com/prometheus/client_golang v1.24.1
2020
github.com/scylladb/termtables v1.0.0

‎go.sum‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -66,6 +66,10 @@ github.com/function61/gokit v0.0.0-20260822195148-784934b22880 h1:grjWMxamUkVZtZ
6666
github.com/function61/gokit v0.0.0-20260822195148-784934b22880/go.mod h1:ewGYmDoaszHKjwN9S2AM30oQwe4mhvuRUA4uvzzkmRw=
6767
github.com/function61/id v0.0.0-20260818190447-5b4cdbaa3020 h1:oZSeyh0lCNx99cvXDIqbE2GzPLb37rX2Mnsn9ubgBVU=
6868
github.com/function61/id v0.0.0-20260818190447-5b4cdbaa3020/go.mod h1:6U3gEM2iYBUvTftYOxtggLsbxZGiF4zfRzT9Zls5VWg=
69+
github.com/function61/id v0.0.0-20260824112419-7d0822757eac h1:0vVsBv3cTzI2fwt1akR0uQ2zKnWzE6l/rzuQLZeBXkw=
70+
github.com/function61/id v0.0.0-20260824112419-7d0822757eac/go.mod h1:6U3gEM2iYBUvTftYOxtggLsbxZGiF4zfRzT9Zls5VWg=
71+
github.com/function61/id v0.0.0-20260824122525-b9d5a88d2b97 h1:rqbuwL1fwWD7z72srDizU2EE9PHrx0n599nEwmvaz7g=
72+
github.com/function61/id v0.0.0-20260824122525-b9d5a88d2b97/go.mod h1:6U3gEM2iYBUvTftYOxtggLsbxZGiF4zfRzT9Zls5VWg=
6973
github.com/google/btree v1.1.3 h1:CVpQJjYgC4VbzxeGVHfvZrv1ctoYCAI8vbl07Fcxlyg=
7074
github.com/google/btree v1.1.3/go.mod h1:qOPhT0dTNdNzV6Z/lhRX0YXUafgPLFUh+gZMl761Gm4=
7175
github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8=

‎pkg/erbackend/authssobackend/sso.go‎

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,13 +26,21 @@ func New(
2626
return nil, errors.New("empty audience")
2727
}
2828

29-
authGateway := idpClient.CreateAuthGateway(router, opts.Audience)
29+
if opts.Audience == "t-1/loppi.org-assets" && opts.Subroot == "" { // FIXME: temporary hack. identifying app "loppi.org-assets"
30+
opts.Subroot = "/assets"
31+
}
32+
33+
authGateway := idpClient.CreateAuthGateway(router, opts.Audience, opts.Subroot)
3034

3135
backendAuthorizer := authGateway.Protect(
3236
idclient.UserListAuthorizer(opts.AllowedUserIds...),
3337
authorizedBackend)
3438

3539
// catch-all route; ServeMux selects the more specific auth gateway endpoints first.
40+
// we now have something like this:
41+
// - /_auth/redirect => take auth token from SSH, put it to cookie and redirect to "next" (where we tried to go before requiring login)
42+
// - /_auth/logout => delete auth cookie and go to logged out page
43+
// - (catch-all) => if user logged in passthrough to authorized handler. if not redirect to SSO otherwise
3644
router.Handle("/", backendAuthorizer)
3745

3846
return router, nil

‎pkg/erconfig/appconfig.go‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -169,6 +169,7 @@ type BackendOptsAuthSso struct {
169169
IDServerURL string `json:"id_server_url,omitempty"`
170170
AllowedUserIds []string `json:"allowed_user_ids"`
171171
Audience string `json:"audience"`
172+
Subroot string `json:"subroot,omitempty"` // (optional) if app mounted under e.g. `/myapp`, scopes the auth cookie and auth gateway under the subroot
172173
AuthorizedBackend *Backend `json:"authorized_backend"` // ptr for validation
173174
}
174175

0 commit comments

Comments
 (0)