mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
OAuth now uses client TLS certs (if configured) (#5042)
* OAuth now uses client TLS certs (if configured) * Update docs * Cleaning * Fix lint errors and generate static files * Fix lint error and regenerate more static files * Suppress lint error
This commit is contained in:
@@ -282,6 +282,16 @@ func newConfig() *codersdk.DeploymentConfig {
|
||||
Flag: "tls-min-version",
|
||||
Default: "tls12",
|
||||
},
|
||||
ClientCertFile: &codersdk.DeploymentConfigField[string]{
|
||||
Name: "TLS Client Cert File",
|
||||
Usage: "Path to certificate for client TLS authentication. It requires a PEM-encoded file.",
|
||||
Flag: "tls-client-cert-file",
|
||||
},
|
||||
ClientKeyFile: &codersdk.DeploymentConfigField[string]{
|
||||
Name: "TLS Client Key File",
|
||||
Usage: "Path to key for client TLS authentication. It requires a PEM-encoded file.",
|
||||
Flag: "tls-client-key-file",
|
||||
},
|
||||
},
|
||||
Trace: &codersdk.TraceConfig{
|
||||
Enable: &codersdk.DeploymentConfigField[bool]{
|
||||
|
||||
@@ -392,6 +392,11 @@ func Server(vip *viper.Viper, newAPI func(context.Context, *coderd.Options) (*co
|
||||
return xerrors.Errorf("OIDC issuer URL must be set!")
|
||||
}
|
||||
|
||||
ctx, err := handleOauth2ClientCertificates(ctx, cfg)
|
||||
if err != nil {
|
||||
return xerrors.Errorf("configure oidc client certificates: %w", err)
|
||||
}
|
||||
|
||||
oidcProvider, err := oidc.NewProvider(ctx, cfg.OIDC.IssuerURL.Value)
|
||||
if err != nil {
|
||||
return xerrors.Errorf("configure oidc provider: %w", err)
|
||||
@@ -1249,3 +1254,21 @@ func startBuiltinPostgres(ctx context.Context, cfg config.Root, logger slog.Logg
|
||||
}
|
||||
return connectionURL, ep.Stop, nil
|
||||
}
|
||||
|
||||
func handleOauth2ClientCertificates(ctx context.Context, cfg *codersdk.DeploymentConfig) (context.Context, error) {
|
||||
if cfg.TLS.ClientCertFile.Value != "" && cfg.TLS.ClientKeyFile.Value != "" {
|
||||
certificates, err := loadCertificates([]string{cfg.TLS.ClientCertFile.Value}, []string{cfg.TLS.ClientKeyFile.Value})
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
return context.WithValue(ctx, oauth2.HTTPClient, &http.Client{
|
||||
Transport: &http.Transport{
|
||||
TLSClientConfig: &tls.Config{ //nolint:gosec
|
||||
Certificates: certificates,
|
||||
},
|
||||
},
|
||||
}), nil
|
||||
}
|
||||
return ctx, nil
|
||||
}
|
||||
|
||||
+8
@@ -177,6 +177,14 @@ Flags:
|
||||
used for checking the authenticity of
|
||||
client
|
||||
Consumes $CODER_TLS_CLIENT_CA_FILE
|
||||
--tls-client-cert-file string Path to certificate for client TLS
|
||||
authentication. It requires a PEM-encoded
|
||||
file.
|
||||
Consumes $CODER_TLS_CLIENT_CERT_FILE
|
||||
--tls-client-key-file string Path to key for client TLS
|
||||
authentication. It requires a PEM-encoded
|
||||
file.
|
||||
Consumes $CODER_TLS_CLIENT_KEY_FILE
|
||||
--tls-enable Whether TLS will be enabled.
|
||||
Consumes $CODER_TLS_ENABLE
|
||||
--tls-key-file strings Paths to the private keys for each of the
|
||||
|
||||
Reference in New Issue
Block a user