Merge pull request #2095 from owncloud/oidc-token-basic-auth

forward basic auth to OpenID connect token authentication endpoint
This commit is contained in:
Jörn Friedrich Dreyer
2021-07-26 15:20:57 +02:00
committed by GitHub
2 changed files with 13 additions and 1 deletions
@@ -0,0 +1,6 @@
Bugfix: forward basic auth to OpenID connect token authentication endpoint
When using `PROXY_ENABLE_BASIC_AUTH=true` we now forward request to the idp instead of trying to authenticate the request ourself.
https://github.com/owncloud/ocis/issues/2095
https://github.com/owncloud/ocis/issues/2094
+7 -1
View File
@@ -31,7 +31,7 @@ func BasicAuth(optionSetters ...Option) func(next http.Handler) http.Handler {
return func(next http.Handler) http.Handler {
return http.HandlerFunc(
func(w http.ResponseWriter, req *http.Request) {
if h.isPublicLink(req) || !h.isBasicAuth(req) {
if h.isPublicLink(req) || !h.isBasicAuth(req) || h.isOIDCTokenAuth(req) {
if !h.isPublicLink(req) {
userAgentAuthenticateLockIn(w, req, options.CredentialsByUserAgent, "basic")
}
@@ -107,6 +107,12 @@ func (m basicAuth) isPublicLink(req *http.Request) bool {
return ok && login == "public" && strings.HasPrefix(req.URL.Path, publicFilesEndpoint)
}
// The token auth endpoint uses basic auth for clients, see https://openid.net/specs/openid-connect-basic-1_0.html#TokenRequest
// > The Client MUST authenticate to the Token Endpoint using the HTTP Basic method, as described in 2.3.1 of OAuth 2.0.
func (m basicAuth) isOIDCTokenAuth(req *http.Request) bool {
return req.URL.Path == "/konnect/v1/token"
}
func (m basicAuth) isBasicAuth(req *http.Request) bool {
_, _, ok := req.BasicAuth()
return m.enabled && ok