Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

add middleware to rewrite the /.well-known/openid-configuration endpoint for external idps #4346

Merged
merged 2 commits into from
Aug 8, 2022
Merged

add middleware to rewrite the /.well-known/openid-configuration endpoint for external idps #4346

merged 2 commits into from
Aug 8, 2022

Conversation

wkloucek
Copy link
Contributor

@wkloucek wkloucek commented Aug 5, 2022

Description

We've added the configuration option PROXY_OIDC_REWRITE_WELLKNOWN to rewrite the /.well-known/openid-configuration endpoint.
If active, it serves the /.well-known/openid-configuration response of the original IDP configured in OCIS_OIDC_ISSUER / PROXY_OIDC_ISSUER. This is needed so that the Desktop Client, Android Client and iOS Client can discover the OIDC identity provider.

Previously this rewrite needed to be performed with an external proxy as NGINX or Traefik if an external IDP was used.

Related Issue

Motivation and Context

How Has This Been Tested?

  • locally
  • deployment examples (see changes)

Screenshots (if appropriate):

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to change)
  • Technical debt
  • Tests only (no source changes)

Checklist:

  • Code changes
  • Unit tests added
  • Acceptance tests added
  • Documentation ticket raised:

@update-docs
Copy link

update-docs bot commented Aug 5, 2022

Thanks for opening this pull request! The maintainers of this repository would appreciate it if you would create a changelog item based on your changes.

@wkloucek wkloucek marked this pull request as draft August 5, 2022 11:49
@wkloucek wkloucek marked this pull request as ready for review August 5, 2022 12:12
@wkloucek wkloucek requested review from rhafer and C0rby August 5, 2022 12:14
@sonarqubecloud
Copy link

sonarqubecloud bot commented Aug 5, 2022

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

0.0% 0.0% Coverage
0.0% 0.0% Duplication

wkloucek added a commit to owncloud/ocis-charts that referenced this pull request Aug 5, 2022
wkloucek added a commit to owncloud/ocis-charts that referenced this pull request Aug 5, 2022
wkloucek added a commit to owncloud/ocis-charts that referenced this pull request Aug 5, 2022
@micbar micbar merged commit 03c6338 into owncloud:master Aug 8, 2022
ownclouders pushed a commit that referenced this pull request Aug 8, 2022
Merge: 98769cc 205f87f
Author: Michael Barz <[email protected]>
Date:   Mon Aug 8 15:36:34 2022 +0200

    Merge pull request #4346 from wkloucek/rewrite-oidc-well-known

    add middleware to rewrite the /.well-known/openid-configuration endpoint for external idps
@micbar micbar mentioned this pull request Aug 11, 2022
26 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Unable to sign-in with native apps with OIDC simplify oCIS deployment with external IDP
3 participants