add idp to new config scheme
This commit is contained in:
+50
-48
@@ -3,6 +3,7 @@ package flagset
|
||||
import (
|
||||
"github.com/micro/cli/v2"
|
||||
"github.com/owncloud/ocis/idp/pkg/config"
|
||||
"github.com/owncloud/ocis/ocis-pkg/flags"
|
||||
)
|
||||
|
||||
// RootWithConfig applies cfg to the root flagset
|
||||
@@ -34,7 +35,7 @@ func HealthWithConfig(cfg *config.Config) []cli.Flag {
|
||||
return []cli.Flag{
|
||||
&cli.StringFlag{
|
||||
Name: "debug-addr",
|
||||
Value: "0.0.0.0:9134",
|
||||
Value: flags.OverrideDefaultString(cfg.Debug.Addr, "0.0.0.0:9134"),
|
||||
Usage: "Address to debug endpoint",
|
||||
EnvVars: []string{"IDP_DEBUG_ADDR"},
|
||||
Destination: &cfg.Debug.Addr,
|
||||
@@ -47,7 +48,7 @@ func ServerWithConfig(cfg *config.Config) []cli.Flag {
|
||||
return []cli.Flag{
|
||||
&cli.StringFlag{
|
||||
Name: "config-file",
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.File, ""),
|
||||
Usage: "Path to config file",
|
||||
EnvVars: []string{"IDP_CONFIG_FILE"},
|
||||
Destination: &cfg.File,
|
||||
@@ -60,42 +61,42 @@ func ServerWithConfig(cfg *config.Config) []cli.Flag {
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "tracing-type",
|
||||
Value: "jaeger",
|
||||
Value: flags.OverrideDefaultString(cfg.Tracing.Type, "jaeger"),
|
||||
Usage: "Tracing backend type",
|
||||
EnvVars: []string{"IDP_TRACING_TYPE"},
|
||||
Destination: &cfg.Tracing.Type,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "tracing-endpoint",
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.Tracing.Endpoint, ""),
|
||||
Usage: "Endpoint for the agent",
|
||||
EnvVars: []string{"IDP_TRACING_ENDPOINT"},
|
||||
Destination: &cfg.Tracing.Endpoint,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "tracing-collector",
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.Tracing.Collector, ""),
|
||||
Usage: "Endpoint for the collector",
|
||||
EnvVars: []string{"IDP_TRACING_COLLECTOR"},
|
||||
Destination: &cfg.Tracing.Collector,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "tracing-service",
|
||||
Value: "idp",
|
||||
Value: flags.OverrideDefaultString(cfg.Tracing.Service, "idp"),
|
||||
Usage: "Service name for tracing",
|
||||
EnvVars: []string{"IDP_TRACING_SERVICE"},
|
||||
Destination: &cfg.Tracing.Service,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "debug-addr",
|
||||
Value: "0.0.0.0:9134",
|
||||
Value: flags.OverrideDefaultString(cfg.Debug.Addr, "0.0.0.0:9134"),
|
||||
Usage: "Address to bind debug server",
|
||||
EnvVars: []string{"IDP_DEBUG_ADDR"},
|
||||
Destination: &cfg.Debug.Addr,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "debug-token",
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.Debug.Token, ""),
|
||||
Usage: "Token to grant metrics access",
|
||||
EnvVars: []string{"IDP_DEBUG_TOKEN"},
|
||||
Destination: &cfg.Debug.Token,
|
||||
@@ -114,135 +115,135 @@ func ServerWithConfig(cfg *config.Config) []cli.Flag {
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "http-addr",
|
||||
Value: "0.0.0.0:9130",
|
||||
Value: flags.OverrideDefaultString(cfg.HTTP.Addr, "0.0.0.0:9130"),
|
||||
Usage: "Address to bind http server",
|
||||
EnvVars: []string{"IDP_HTTP_ADDR"},
|
||||
Destination: &cfg.HTTP.Addr,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "http-root",
|
||||
Value: "/",
|
||||
Value: flags.OverrideDefaultString(cfg.HTTP.Root, "/"),
|
||||
Usage: "Root path of http server",
|
||||
EnvVars: []string{"IDP_HTTP_ROOT"},
|
||||
Destination: &cfg.HTTP.Root,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "http-namespace",
|
||||
Value: "com.owncloud.web",
|
||||
Value: flags.OverrideDefaultString(cfg.Service.Namespace, "com.owncloud.web"),
|
||||
Usage: "Set the base namespace for service discovery",
|
||||
EnvVars: []string{"IDP_HTTP_NAMESPACE"},
|
||||
Destination: &cfg.Service.Namespace,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "name",
|
||||
Value: "idp",
|
||||
Value: flags.OverrideDefaultString(cfg.Service.Name, "idp"),
|
||||
Usage: "Service name",
|
||||
EnvVars: []string{"IDP_NAME"},
|
||||
Destination: &cfg.Service.Name,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "identity-manager",
|
||||
Value: "ldap",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.IdentityManager, "ldap"),
|
||||
Usage: "Identity manager (one of ldap,kc,cookie,dummy)",
|
||||
EnvVars: []string{"IDP_IDENTITY_MANAGER"},
|
||||
Destination: &cfg.IDP.IdentityManager,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "ldap-uri",
|
||||
Value: "ldap://localhost:9125",
|
||||
Value: flags.OverrideDefaultString(cfg.Ldap.URI, "http://localhost:9125"),
|
||||
Usage: "URI of the LDAP server (glauth)",
|
||||
EnvVars: []string{"IDP_LDAP_URI"},
|
||||
Destination: &cfg.Ldap.URI,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "ldap-bind-dn",
|
||||
Value: "cn=idp,ou=sysusers,dc=example,dc=org",
|
||||
Value: flags.OverrideDefaultString(cfg.Ldap.BindDN, "cn=idp,ou=sysusers,dc=example,dc=org"),
|
||||
Usage: "Bind DN for the LDAP server (glauth)",
|
||||
EnvVars: []string{"IDP_LDAP_BIND_DN"},
|
||||
Destination: &cfg.Ldap.BindDN,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "ldap-bind-password",
|
||||
Value: "idp",
|
||||
Value: flags.OverrideDefaultString(cfg.Ldap.BindPassword, "idp"),
|
||||
Usage: "Password for the Bind DN of the LDAP server (glauth)",
|
||||
EnvVars: []string{"IDP_LDAP_BIND_PASSWORD"},
|
||||
Destination: &cfg.Ldap.BindPassword,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "ldap-base-dn",
|
||||
Value: "ou=users,dc=example,dc=org",
|
||||
Value: flags.OverrideDefaultString(cfg.Ldap.BaseDN, "ou=users,dc=example,dc=org"),
|
||||
Usage: "LDAP base DN of the oCIS users",
|
||||
EnvVars: []string{"IDP_LDAP_BASE_DN"},
|
||||
Destination: &cfg.Ldap.BaseDN,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "ldap-scope",
|
||||
Value: "sub",
|
||||
Value: flags.OverrideDefaultString(cfg.Ldap.Scope, "sub"),
|
||||
Usage: "LDAP scope of the oCIS users",
|
||||
EnvVars: []string{"IDP_LDAP_SCOPE"},
|
||||
Destination: &cfg.Ldap.Scope,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "ldap-login-attribute",
|
||||
Value: "cn",
|
||||
Value: flags.OverrideDefaultString(cfg.Ldap.LoginAttribute, "cn"),
|
||||
Usage: "LDAP login attribute of the oCIS users",
|
||||
EnvVars: []string{"IDP_LDAP_LOGIN_ATTRIBUTE"},
|
||||
Destination: &cfg.Ldap.LoginAttribute,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "ldap-email-attribute",
|
||||
Value: "mail",
|
||||
Value: flags.OverrideDefaultString(cfg.Ldap.EmailAttribute, "mail"),
|
||||
Usage: "LDAP email attribute of the oCIS users",
|
||||
EnvVars: []string{"IDP_LDAP_EMAIL_ATTRIBUTE"},
|
||||
Destination: &cfg.Ldap.EmailAttribute,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "ldap-name-attribute",
|
||||
Value: "sn",
|
||||
Value: flags.OverrideDefaultString(cfg.Ldap.NameAttribute, "sn"),
|
||||
Usage: "LDAP name attribute of the oCIS users",
|
||||
EnvVars: []string{"IDP_LDAP_NAME_ATTRIBUTE"},
|
||||
Destination: &cfg.Ldap.NameAttribute,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "ldap-uuid-attribute",
|
||||
Value: "uid",
|
||||
Value: flags.OverrideDefaultString(cfg.Ldap.UUIDAttribute, "uid"),
|
||||
Usage: "LDAP UUID attribute of the oCIS users",
|
||||
EnvVars: []string{"IDP_LDAP_UUID_ATTRIBUTE"},
|
||||
Destination: &cfg.Ldap.UUIDAttribute,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "ldap-uuid-attribute-type",
|
||||
Value: "text",
|
||||
Value: flags.OverrideDefaultString(cfg.Ldap.UUIDAttributeType, "text"),
|
||||
Usage: "LDAP UUID attribute type of the oCIS users",
|
||||
EnvVars: []string{"IDP_LDAP_UUID_ATTRIBUTE_TYPE"},
|
||||
Destination: &cfg.Ldap.UUIDAttributeType,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "ldap-filter",
|
||||
Value: "(objectClass=posixaccount)",
|
||||
Value: flags.OverrideDefaultString(cfg.Ldap.Filter, "(objectClass=posixaccount)"),
|
||||
Usage: "LDAP filter of the oCIS users",
|
||||
EnvVars: []string{"IDP_LDAP_FILTER"},
|
||||
Destination: &cfg.Ldap.Filter,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "transport-tls-cert",
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.HTTP.TLSCert, ""),
|
||||
Usage: "Certificate file for transport encryption",
|
||||
EnvVars: []string{"IDP_TRANSPORT_TLS_CERT"},
|
||||
Destination: &cfg.HTTP.TLSCert,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "transport-tls-key",
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.HTTP.TLSKey, ""),
|
||||
Usage: "Secret file for transport encryption",
|
||||
EnvVars: []string{"IDP_TRANSPORT_TLS_KEY"},
|
||||
Destination: &cfg.HTTP.TLSKey,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "iss",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.Iss, "https://localhost:9200"),
|
||||
Usage: "OIDC issuer URL",
|
||||
EnvVars: []string{"IDP_ISS", "OCIS_URL"}, // IDP_ISS takes precedence over OCIS_URL
|
||||
Value: "https://localhost:9200",
|
||||
Destination: &cfg.IDP.Iss,
|
||||
},
|
||||
&cli.StringSliceFlag{
|
||||
@@ -255,68 +256,68 @@ func ServerWithConfig(cfg *config.Config) []cli.Flag {
|
||||
Name: "signing-kid",
|
||||
Usage: "Value of kid field to use in created tokens (uniquely identifying the signing-private-key)",
|
||||
EnvVars: []string{"IDP_SIGNING_KID"},
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.SigningKid, ""),
|
||||
Destination: &cfg.IDP.SigningKid,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "validation-keys-path",
|
||||
Usage: "Full path to a folder containg PEM encoded private or public key files used for token validaton (file name without extension is used as kid)",
|
||||
EnvVars: []string{"IDP_VALIDATION_KEYS_PATH"},
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.ValidationKeysPath, ""),
|
||||
Destination: &cfg.IDP.ValidationKeysPath,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "encryption-secret",
|
||||
Usage: "Full path to a file containing a %d bytes secret key",
|
||||
EnvVars: []string{"IDP_ENCRYPTION_SECRET"},
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.EncryptionSecretFile, ""),
|
||||
Destination: &cfg.IDP.EncryptionSecretFile,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "signing-method",
|
||||
Usage: "JWT default signing method",
|
||||
EnvVars: []string{"IDP_SIGNING_METHOD"},
|
||||
Value: "PS256",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.SigningMethod, "PS256"),
|
||||
Destination: &cfg.IDP.SigningMethod,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "uri-base-path",
|
||||
Usage: "Custom base path for URI endpoints",
|
||||
EnvVars: []string{"IDP_URI_BASE_PATH"},
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.URIBasePath, ""),
|
||||
Destination: &cfg.IDP.URIBasePath,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "sign-in-uri",
|
||||
Usage: "Custom redirection URI to sign-in form",
|
||||
EnvVars: []string{"IDP_SIGN_IN_URI"},
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.SignInURI, ""),
|
||||
Destination: &cfg.IDP.SignInURI,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "signed-out-uri",
|
||||
Usage: "Custom redirection URI to signed-out goodbye page",
|
||||
EnvVars: []string{"IDP_SIGN_OUT_URI"},
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.SignedOutURI, ""),
|
||||
Destination: &cfg.IDP.SignedOutURI,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "authorization-endpoint-uri",
|
||||
Usage: "Custom authorization endpoint URI",
|
||||
EnvVars: []string{"IDP_ENDPOINT_URI"},
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.AuthorizationEndpointURI, ""),
|
||||
Destination: &cfg.IDP.AuthorizationEndpointURI,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "endsession-endpoint-uri",
|
||||
Usage: "Custom endsession endpoint URI",
|
||||
EnvVars: []string{"IDP_ENDSESSION_ENDPOINT_URI"},
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.EndsessionEndpointURI, ""),
|
||||
Destination: &cfg.IDP.EndsessionEndpointURI,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "asset-path",
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.Asset.Path, ""),
|
||||
Usage: "Path to custom assets",
|
||||
EnvVars: []string{"IDP_ASSET_PATH"},
|
||||
Destination: &cfg.Asset.Path,
|
||||
@@ -325,21 +326,21 @@ func ServerWithConfig(cfg *config.Config) []cli.Flag {
|
||||
Name: "identifier-client-path",
|
||||
Usage: "Path to the identifier web client base folder",
|
||||
EnvVars: []string{"IDP_IDENTIFIER_CLIENT_PATH"},
|
||||
Value: "/var/tmp/ocis/idp",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.IdentifierClientPath, "/var/tmp/ocis/idp"),
|
||||
Destination: &cfg.IDP.IdentifierClientPath,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "identifier-registration-conf",
|
||||
Usage: "Path to a identifier-registration.yaml configuration file",
|
||||
EnvVars: []string{"IDP_IDENTIFIER_REGISTRATION_CONF"},
|
||||
Value: "./config/identifier-registration.yaml",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.IdentifierRegistrationConf, "./config/identifier-registration.yaml"),
|
||||
Destination: &cfg.IDP.IdentifierRegistrationConf,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "identifier-scopes-conf",
|
||||
Usage: "Path to a scopes.yaml configuration file",
|
||||
EnvVars: []string{"IDP_IDENTIFIER_SCOPES_CONF"},
|
||||
Value: "",
|
||||
Value: flags.OverrideDefaultString(cfg.IDP.IdentifierScopesConf, ""),
|
||||
Destination: &cfg.IDP.IdentifierScopesConf,
|
||||
},
|
||||
&cli.BoolFlag{
|
||||
@@ -352,7 +353,7 @@ func ServerWithConfig(cfg *config.Config) []cli.Flag {
|
||||
Name: "tls",
|
||||
Usage: "Use TLS (disable only if idp is behind a TLS-terminating reverse-proxy).",
|
||||
EnvVars: []string{"IDP_TLS"},
|
||||
Value: false,
|
||||
Value: flags.OverrideDefaultBool(cfg.HTTP.TLS, false),
|
||||
Destination: &cfg.HTTP.TLS,
|
||||
},
|
||||
&cli.StringSliceFlag{
|
||||
@@ -377,14 +378,14 @@ func ServerWithConfig(cfg *config.Config) []cli.Flag {
|
||||
Name: "allow-dynamic-client-registration",
|
||||
Usage: "Allow dynamic OAuth2 client registration",
|
||||
EnvVars: []string{"IDP_ALLOW_DYNAMIC_CLIENT_REGISTRATION"},
|
||||
Value: true,
|
||||
Value: flags.OverrideDefaultBool(cfg.IDP.AllowDynamicClientRegistration, true),
|
||||
Destination: &cfg.IDP.AllowDynamicClientRegistration,
|
||||
},
|
||||
&cli.BoolFlag{
|
||||
Name: "disable-identifier-webapp",
|
||||
Usage: "Disable built-in identifier-webapp to use a frontend hosted elsewhere.",
|
||||
EnvVars: []string{"IDP_DISABLE_IDENTIFIER_WEBAPP"},
|
||||
Value: true,
|
||||
Value: flags.OverrideDefaultBool(cfg.IDP.IdentifierClientDisabled, true),
|
||||
Destination: &cfg.IDP.IdentifierClientDisabled,
|
||||
},
|
||||
&cli.Uint64Flag{
|
||||
@@ -392,21 +393,22 @@ func ServerWithConfig(cfg *config.Config) []cli.Flag {
|
||||
Usage: "Expiration time of access tokens in seconds since generated",
|
||||
EnvVars: []string{"IDP_ACCESS_TOKEN_EXPIRATION"},
|
||||
Destination: &cfg.IDP.AccessTokenDurationSeconds,
|
||||
Value: 60 * 10, // 10 Minutes.
|
||||
Value: flags.OverrideDefaultUint64(cfg.IDP.AccessTokenDurationSeconds, 60*10), // 10 minutes
|
||||
},
|
||||
&cli.Uint64Flag{
|
||||
Name: "id-token-expiration",
|
||||
Usage: "Expiration time of id tokens in seconds since generated",
|
||||
EnvVars: []string{"IDP_ID_TOKEN_EXPIRATION"},
|
||||
Destination: &cfg.IDP.IDTokenDurationSeconds,
|
||||
Value: 60 * 60, // 1 Hour
|
||||
Value: flags.OverrideDefaultUint64(cfg.IDP.IDTokenDurationSeconds, 60*60), // 1 hour
|
||||
},
|
||||
&cli.Uint64Flag{
|
||||
Name: "refresh-token-expiration",
|
||||
Usage: "Expiration time of refresh tokens in seconds since generated",
|
||||
EnvVars: []string{"IDP_REFRESH_TOKEN_EXPIRATION"},
|
||||
Destination: &cfg.IDP.RefreshTokenDurationSeconds,
|
||||
Value: 60 * 60 * 24 * 365 * 3, // 1 year
|
||||
Value: flags.OverrideDefaultUint64(cfg.IDP.RefreshTokenDurationSeconds, 60*60*24*365*3), // 1 year
|
||||
|
||||
},
|
||||
}
|
||||
}
|
||||
@@ -415,14 +417,14 @@ func ServerWithConfig(cfg *config.Config) []cli.Flag {
|
||||
func ListIDPWithConfig(cfg *config.Config) []cli.Flag {
|
||||
return []cli.Flag{&cli.StringFlag{
|
||||
Name: "http-namespace",
|
||||
Value: "com.owncloud.web",
|
||||
Value: flags.OverrideDefaultString(cfg.Service.Namespace, "com.owncloud.web"),
|
||||
Usage: "Set the base namespace for service discovery",
|
||||
EnvVars: []string{"IDP_HTTP_NAMESPACE"},
|
||||
Destination: &cfg.Service.Namespace,
|
||||
},
|
||||
&cli.StringFlag{
|
||||
Name: "name",
|
||||
Value: "idp",
|
||||
Value: flags.OverrideDefaultString(cfg.Service.Name, "idp"),
|
||||
Usage: "Service name",
|
||||
EnvVars: []string{"IDP_NAME"},
|
||||
Destination: &cfg.Service.Name,
|
||||
|
||||
@@ -43,3 +43,14 @@ func OverrideDefaultInt64(v, def int64) int64 {
|
||||
|
||||
return def
|
||||
}
|
||||
|
||||
// OverrideDefaultUint64 checks whether the default value of v is the zero value, if so, ensure the flag has a correct
|
||||
// value by providing one. A value different than zero would mean that it was read from a config file either from an
|
||||
// extension or from a higher source (i.e: ocis command).
|
||||
func OverrideDefaultUint64(v, def uint64) uint64 {
|
||||
if v != 0 {
|
||||
return v
|
||||
}
|
||||
|
||||
return def
|
||||
}
|
||||
|
||||
@@ -20,6 +20,9 @@ func IDPCommand(cfg *config.Config) *cli.Command {
|
||||
Subcommands: []*cli.Command{
|
||||
command.PrintVersion(cfg.IDP),
|
||||
},
|
||||
Before: func(ctx *cli.Context) error {
|
||||
return ParseConfig(ctx, cfg)
|
||||
},
|
||||
Action: func(c *cli.Context) error {
|
||||
idpCommand := command.Server(configureIDP(cfg))
|
||||
|
||||
|
||||
Reference in New Issue
Block a user