|
|
|
@ -23,16 +23,15 @@ import (
|
|
|
|
|
"crypto/x509"
|
|
|
|
|
"encoding/base64"
|
|
|
|
|
"fmt"
|
|
|
|
|
"log/slog"
|
|
|
|
|
"net/http"
|
|
|
|
|
"os"
|
|
|
|
|
"time"
|
|
|
|
|
|
|
|
|
|
"code.cacert.org/cacert/oidc-demo-app/ui"
|
|
|
|
|
"github.com/knadh/koanf"
|
|
|
|
|
"github.com/knadh/koanf/parsers/toml"
|
|
|
|
|
"github.com/knadh/koanf/providers/confmap"
|
|
|
|
|
log "github.com/sirupsen/logrus"
|
|
|
|
|
|
|
|
|
|
"code.cacert.org/cacert/oidc-demo-app/ui"
|
|
|
|
|
|
|
|
|
|
"code.cacert.org/cacert/oidc-demo-app/internal/handlers"
|
|
|
|
|
"code.cacert.org/cacert/oidc-demo-app/internal/services"
|
|
|
|
@ -85,44 +84,58 @@ func (f *StaticFileInfoWrapper) ModTime() time.Time {
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func main() {
|
|
|
|
|
logger := log.New()
|
|
|
|
|
|
|
|
|
|
config, err := services.ConfigureApplication(
|
|
|
|
|
logger,
|
|
|
|
|
"RESOURCE_APP",
|
|
|
|
|
services.DefaultConfiguration,
|
|
|
|
|
var (
|
|
|
|
|
logLevel = new(slog.LevelVar)
|
|
|
|
|
logHandler slog.Handler
|
|
|
|
|
logger *slog.Logger
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
logHandler = slog.NewTextHandler(os.Stdout, &slog.HandlerOptions{Level: logLevel})
|
|
|
|
|
logger = slog.New(logHandler)
|
|
|
|
|
slog.SetDefault(logger)
|
|
|
|
|
|
|
|
|
|
config, err := services.ConfigureApplication("RESOURCE_APP", services.DefaultConfiguration)
|
|
|
|
|
if err != nil {
|
|
|
|
|
log.Fatalf("error loading configuration: %v", err)
|
|
|
|
|
logger.Error("error loading configuration", "error", err)
|
|
|
|
|
os.Exit(1)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
oidcServer := config.MustString("oidc.server")
|
|
|
|
|
oidcClientID := config.MustString("oidc.client-id")
|
|
|
|
|
oidcClientSecret := config.MustString("oidc.client-secret")
|
|
|
|
|
|
|
|
|
|
if level := config.String("log.level"); level != "" {
|
|
|
|
|
logLevel, err := log.ParseLevel(level)
|
|
|
|
|
if err != nil {
|
|
|
|
|
logger.WithError(err).Fatal("could not parse log level")
|
|
|
|
|
if level := config.Bytes("log.level"); level != nil {
|
|
|
|
|
if err := logLevel.UnmarshalText(level); err != nil {
|
|
|
|
|
logger.Error("could not parse log level", "error", err)
|
|
|
|
|
os.Exit(1)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
logger.SetLevel(logLevel)
|
|
|
|
|
slog.SetLogLoggerLevel(logLevel.Level())
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if config.Bool("log.json") {
|
|
|
|
|
logger.SetFormatter(&log.JSONFormatter{})
|
|
|
|
|
logHandler = slog.NewJSONHandler(os.Stdout, &slog.HandlerOptions{Level: logLevel})
|
|
|
|
|
logger = slog.New(logHandler)
|
|
|
|
|
slog.SetDefault(logger)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
logger.WithFields(log.Fields{
|
|
|
|
|
"version": version, "commit": commit, "date": date,
|
|
|
|
|
}).Info("Starting CAcert OpenID Connect demo application")
|
|
|
|
|
logger.Infoln("Server is starting")
|
|
|
|
|
logLogger := slog.NewLogLogger(logger.Handler(), logLevel.Level())
|
|
|
|
|
|
|
|
|
|
logger.Info(
|
|
|
|
|
"Starting CAcert OpenID Connect demo application",
|
|
|
|
|
"version", version, "commit", commit, "date", date,
|
|
|
|
|
)
|
|
|
|
|
logger.Info("Server is starting")
|
|
|
|
|
|
|
|
|
|
bundle, catalog := services.InitI18n(logger, config.Strings("i18n.languages"))
|
|
|
|
|
|
|
|
|
|
services.AddMessages(catalog)
|
|
|
|
|
|
|
|
|
|
tlsClientConfig := getTLSConfig(config)
|
|
|
|
|
tlsClientConfig, err := getTLSConfig(config)
|
|
|
|
|
if err != nil {
|
|
|
|
|
logger.Error("error loading tls config", "error", err)
|
|
|
|
|
os.Exit(1)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
apiTransport := &http.Transport{TLSClientConfig: tlsClientConfig}
|
|
|
|
|
apiClient := &http.Client{Transport: apiTransport}
|
|
|
|
@ -134,37 +147,50 @@ func main() {
|
|
|
|
|
APIClient: apiClient,
|
|
|
|
|
})
|
|
|
|
|
if err != nil {
|
|
|
|
|
logger.WithError(err).Fatal("OpenID Connect discovery failed")
|
|
|
|
|
logger.Error("OpenID Connect discovery failed", "error", err)
|
|
|
|
|
os.Exit(1)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
sessionPath, sessionAuthKey, sessionEncKey := configureSessionParameters(config)
|
|
|
|
|
services.InitSessionStore(logger, sessionPath, sessionAuthKey, sessionEncKey)
|
|
|
|
|
sessionPath, sessionAuthKey, sessionEncKey, err := configureSessionParameters(logger, config)
|
|
|
|
|
if err := services.InitSessionStore(logger, sessionPath, sessionAuthKey, sessionEncKey); err != nil {
|
|
|
|
|
logger.Error("could not initialize session store", "error", err)
|
|
|
|
|
|
|
|
|
|
os.Exit(1)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
authMiddleware := handlers.Authenticate(oidcInfo.OAuth2Config)
|
|
|
|
|
authMiddleware := handlers.Authenticate(logger, oidcInfo.OAuth2Config)
|
|
|
|
|
|
|
|
|
|
publicURL := buildPublicURL(config.MustString("server.name"), config.MustInt("server.port"))
|
|
|
|
|
|
|
|
|
|
tokenInfoService, err := services.InitTokenInfoService(logger, oidcInfo)
|
|
|
|
|
if err != nil {
|
|
|
|
|
logger.WithError(err).Fatal("could not initialize token info service")
|
|
|
|
|
logger.Error("could not initialize token info service", "error", err)
|
|
|
|
|
|
|
|
|
|
os.Exit(1)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
indexHandler, err := handlers.NewIndexHandler(logger, bundle, catalog, oidcInfo, publicURL, tokenInfoService)
|
|
|
|
|
if err != nil {
|
|
|
|
|
logger.WithError(err).Fatal("could not initialize index handler")
|
|
|
|
|
logger.Error("could not initialize index handler", "error", err)
|
|
|
|
|
os.Exit(1)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
protectedResource, err := handlers.NewProtectedResourceHandler(
|
|
|
|
|
logger, bundle, catalog, oidcInfo, publicURL, tokenInfoService,
|
|
|
|
|
)
|
|
|
|
|
if err != nil {
|
|
|
|
|
logger.WithError(err).Fatal("could not initialize protected resource handler")
|
|
|
|
|
logger.Error("could not initialize protected resource handler", "error", err)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
callbackHandler := handlers.NewCallbackHandler(logger, oidcInfo.KeySet, oidcInfo.OAuth2Config)
|
|
|
|
|
afterLogoutHandler := handlers.NewAfterLogoutHandler(logger)
|
|
|
|
|
|
|
|
|
|
staticFiles := staticFileHandler(logger)
|
|
|
|
|
staticFiles, err := staticFileHandler()
|
|
|
|
|
if err != nil {
|
|
|
|
|
logger.Error("could not initialize static file handler", "error", err)
|
|
|
|
|
|
|
|
|
|
os.Exit(1)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
router := http.NewServeMux()
|
|
|
|
|
router.Handle("/", indexHandler)
|
|
|
|
@ -182,12 +208,13 @@ func main() {
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
tracing := handlers.Tracing(nextRequestID)
|
|
|
|
|
logging := handlers.Logging(logger)
|
|
|
|
|
logging := handlers.Logging(logLogger)
|
|
|
|
|
hsts := handlers.EnableHSTS()
|
|
|
|
|
|
|
|
|
|
errorMiddleware, err := handlers.ErrorHandling(logger, bundle, catalog)
|
|
|
|
|
if err != nil {
|
|
|
|
|
logger.WithError(err).Fatal("could not initialize request error handling")
|
|
|
|
|
logger.Error("could not initialize request error handling", "error", err)
|
|
|
|
|
os.Exit(1)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
tlsConfig := &tls.Config{
|
|
|
|
@ -204,13 +231,16 @@ func main() {
|
|
|
|
|
TLSConfig: tlsConfig,
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
handlers.StartApplication(context.Background(), logger, server, publicURL, config)
|
|
|
|
|
if err := handlers.StartApplication(context.Background(), logger, server, publicURL, config); err != nil {
|
|
|
|
|
logger.Error("could not start application", "error", err)
|
|
|
|
|
os.Exit(1)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func staticFileHandler(logger *log.Logger) func(w http.ResponseWriter, r *http.Request) {
|
|
|
|
|
func staticFileHandler() (func(w http.ResponseWriter, r *http.Request), error) {
|
|
|
|
|
stat, err := os.Stat(os.Args[0])
|
|
|
|
|
if err != nil {
|
|
|
|
|
logger.WithError(err).Fatal("could not use stat on binary")
|
|
|
|
|
return nil, fmt.Errorf("could not use stat on binary: %w", err)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
fileServer := http.FileServer(&StaticFSWrapper{FileSystem: http.FS(ui.Static), ModTime: stat.ModTime()})
|
|
|
|
@ -223,10 +253,10 @@ func staticFileHandler(logger *log.Logger) func(w http.ResponseWriter, r *http.R
|
|
|
|
|
fileServer.ServeHTTP(w, r)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return staticFiles
|
|
|
|
|
return staticFiles, nil
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func getTLSConfig(config *koanf.Koanf) *tls.Config {
|
|
|
|
|
func getTLSConfig(config *koanf.Koanf) (*tls.Config, error) {
|
|
|
|
|
tlsClientConfig := &tls.Config{
|
|
|
|
|
MinVersion: tls.VersionTLS12,
|
|
|
|
|
}
|
|
|
|
@ -237,14 +267,14 @@ func getTLSConfig(config *koanf.Koanf) *tls.Config {
|
|
|
|
|
|
|
|
|
|
pemBytes, err := os.ReadFile(rootCAFile)
|
|
|
|
|
if err != nil {
|
|
|
|
|
log.Fatalf("could not read CA certificate file: %v", err)
|
|
|
|
|
return nil, fmt.Errorf("could not read CA certificate file: %w", err)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
caCertPool.AppendCertsFromPEM(pemBytes)
|
|
|
|
|
tlsClientConfig.RootCAs = caCertPool
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return tlsClientConfig
|
|
|
|
|
return tlsClientConfig, nil
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func buildPublicURL(hostname string, port int) string {
|
|
|
|
@ -257,28 +287,36 @@ func buildPublicURL(hostname string, port int) string {
|
|
|
|
|
return fmt.Sprintf("https://%s", hostname)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func configureSessionParameters(config *koanf.Koanf) (string, []byte, []byte) {
|
|
|
|
|
func configureSessionParameters(logger *slog.Logger, config *koanf.Koanf) (string, []byte, []byte, error) {
|
|
|
|
|
sessionPath := config.MustString("session.path")
|
|
|
|
|
|
|
|
|
|
sessionAuthKey, err := base64.StdEncoding.DecodeString(config.String("session.auth-key"))
|
|
|
|
|
if err != nil {
|
|
|
|
|
log.WithError(err).Fatal("could not decode session auth key")
|
|
|
|
|
return "", nil, nil, fmt.Errorf("could not decode session authentication key: %w", err)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
sessionEncKey, err := base64.StdEncoding.DecodeString(config.String("session.enc-key"))
|
|
|
|
|
if err != nil {
|
|
|
|
|
log.WithError(err).Fatal("could not decode session encryption key")
|
|
|
|
|
return "", nil, nil, fmt.Errorf("could not decode session encryption key: %w", err)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
generated := false
|
|
|
|
|
|
|
|
|
|
if len(sessionAuthKey) != sessionAuthKeyLength {
|
|
|
|
|
sessionAuthKey = services.GenerateKey(sessionAuthKeyLength)
|
|
|
|
|
sessionAuthKey, err = services.GenerateKey(sessionAuthKeyLength)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return "", nil, nil, fmt.Errorf("could not generate session authentication key: %w", err)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
generated = true
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if len(sessionEncKey) != sessionKeyLength {
|
|
|
|
|
sessionEncKey = services.GenerateKey(sessionKeyLength)
|
|
|
|
|
sessionEncKey, err = services.GenerateKey(sessionKeyLength)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return "", nil, nil, fmt.Errorf("could not generate session encryption key: %w", err)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
generated = true
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
@ -290,11 +328,12 @@ func configureSessionParameters(config *koanf.Koanf) (string, []byte, []byte) {
|
|
|
|
|
|
|
|
|
|
tomlData, err := config.Marshal(toml.Parser())
|
|
|
|
|
if err != nil {
|
|
|
|
|
log.WithError(err).Fatal("could not encode session config")
|
|
|
|
|
return "", nil, nil, fmt.Errorf("could not encode session configuration: %w", err)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
log.Infof("put the following in your resource_app.toml:\n%s", string(tomlData))
|
|
|
|
|
logger.Info("put the following in your resource_app.toml")
|
|
|
|
|
fmt.Print(string(tomlData)) //nolint:forbidigo
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return sessionPath, sessionAuthKey, sessionEncKey
|
|
|
|
|
return sessionPath, sessionAuthKey, sessionEncKey, nil
|
|
|
|
|
}
|
|
|
|
|