From ef138c05d48693ab3b6926ffebe4da74f9ffa8ee Mon Sep 17 00:00:00 2001 From: Qiu Jian Date: Thu, 3 Sep 2020 23:52:12 +0800 Subject: [PATCH] fix: remove redundant auth cookie in sso login --- pkg/apigateway/handler/idp.go | 7 +++---- pkg/apigateway/handler/oidc.go | 2 +- 2 files changed, 4 insertions(+), 5 deletions(-) diff --git a/pkg/apigateway/handler/idp.go b/pkg/apigateway/handler/idp.go index 282f48bb34..047bbf6213 100644 --- a/pkg/apigateway/handler/idp.go +++ b/pkg/apigateway/handler/idp.go @@ -28,7 +28,6 @@ import ( "yunion.io/x/pkg/errors" "yunion.io/x/pkg/utils" - "yunion.io/x/onecloud/pkg/apigateway/constants" "yunion.io/x/onecloud/pkg/apigateway/options" api "yunion.io/x/onecloud/pkg/apis/identity" "yunion.io/x/onecloud/pkg/appctx" @@ -76,14 +75,14 @@ func (h *AuthHandlers) getIdpSsoRedirectUri(ctx context.Context, w http.Response query, _ := jsonutils.ParseQueryString(req.URL.RawQuery) var linkuser string if query != nil && query.Contains("linkuser") { - t, authToken, _ := fetchAuthInfo(ctx, req) + t, _, _ := fetchAuthInfo(ctx, req) if t == nil { httperrors.InvalidCredentialError(ctx, w, "invalid credential") return } linkuser = t.GetUserId() - authCookie := authToken.GetAuthCookie(t) - saveCookie(w, constants.YUNION_AUTH_COOKIE, authCookie, "", expires, true) + // authCookie := authToken.GetAuthCookie(t) + // saveCookie(w, constants.YUNION_AUTH_COOKIE, authCookie, "", expires, true) } referer := req.Header.Get(http.CanonicalHeaderKey("referer")) diff --git a/pkg/apigateway/handler/oidc.go b/pkg/apigateway/handler/oidc.go index 36d70b187f..1c05e48dc0 100644 --- a/pkg/apigateway/handler/oidc.go +++ b/pkg/apigateway/handler/oidc.go @@ -292,7 +292,7 @@ func handleOIDCConfiguration(ctx context.Context, w http.ResponseWriter, req *ht userinfoUrl := httputils.JoinPath(options.Options.ApiServer, "api/v1/auth/oidc/user") jwksUrl := httputils.JoinPath(options.Options.ApiServer, "api/v1/auth/oidc/keys") conf := oidcutils.SOIDCConfiguration{ - Issuer: options.Options.ApiServer, + Issuer: httputils.JoinPath(options.Options.ApiServer, "api/v1/auth/oidc"), AuthorizationEndpoint: authUrl, TokenEndpoint: tokenUrl, UserinfoEndpoint: userinfoUrl,