summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2025-04-15 22:26:50 -0400
committerJoe Mou <dev@mou.fo>2025-06-16 13:58:57 -0400
commit278f61844675775af9532e9812f8138ba1deabb8 (patch)
tree08c86ac883cb0c2f201d8c41216d5459775f02b1
parentab1be6d042aba753dbb0041a0316ac3541c4daf2 (diff)
In progress attempt to use Dex for OIDC
Dex really doesn't want to be the authoritative identity provider. Static users are not very configurable. The sub claim is a base64 internal representation that we can't use in backends directly. We could jury rig email, but never got that working. Basic authentication works, but Home Assistant fails to login the user.
-rw-r--r--hostnix/elmo/home-assistant.nix17
-rw-r--r--hostnix/elmo/oidc.nix39
2 files changed, 52 insertions, 4 deletions
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix
index 7c66951..0b23db0 100644
--- a/hostnix/elmo/home-assistant.nix
+++ b/hostnix/elmo/home-assistant.nix
@@ -63,7 +63,14 @@
use_x_forwarded_for = true;
};
recorder.db_url = "postgresql://@/hass";
- auth_header = { };
+ # FIXME doesn't authenticate
+ # auth_header.username_header = "X-Email";
+ auth_header.debug = true;
+ logger = {
+ default = "info";
+ logs."custom_components.auth_header" = "debug";
+ };
+
#binary_sensor:
# - platform: template
@@ -651,6 +658,14 @@
auth_request off;
'';
};
+ # FIXME testing shim
+ locations."/test" = {
+ proxyPass = "http://127.0.0.1:8000";
+ extraConfig = ''
+ proxy_set_header X-User $user;
+ proxy_set_header X-Email $email;
+ '';
+ };
# Disable service worker caching that works improperly with reverse proxy.
# https://github.com/home-assistant/frontend/issues/14836
# https://community.home-assistant.io/t/disabling-service-worker-reverse-proxy-auth-causes-issues/167082
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index 00d2fcf..88f8e9a 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -1,6 +1,40 @@
{ lib, pkgs, ... }:
{
+ services.dex = {
+ enable = true;
+ settings = {
+ issuer = "https://op.mou.fo/dex";
+ storage = {
+ # TODO persistence?
+ type = "memory";
+ };
+ web = {
+ # TODO port
+ http = "0.0.0.0:5556";
+ };
+ enablePasswordDB = true;
+ staticPasswords = [
+ {
+ email = "joe";
+ username = "joe";
+ hash = "$2y$10$Vp2MTFeHs6AYpNofOpY5YehFPhE/44VY7Z3TtdsHnBre/N64kM4Ii";
+ # userID = "b0c5bafa-fa25-4b20-a9aa-ab79f4d57d18";
+ userID = "joe";
+ }
+ ];
+ staticClients = [
+ {
+ id = "288565372746006652@mou.fo";
+ name = "oauth2-proxy";
+ redirectURIs = [ "https://op.mou.fo/oauth2/callback" ];
+ # TODO consolidate w/ oauth2-proxy.env?
+ secretFile = "/var/secrets/oauth2-proxy.secret";
+ }
+ ];
+ };
+ };
+
services.postgresql = {
ensureDatabases = [ "zitadel" ];
ensureUsers = [{
@@ -71,7 +105,7 @@
reverseProxy = true;
provider = "oidc";
clientID = "288565372746006652@mou.fo";
- oidcIssuerUrl = "https://zd.mou.fo";
+ oidcIssuerUrl = "https://op.mou.fo/dex";
# Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
keyFile = "/var/secrets/oauth2-proxy.env";
# Ignore e-mail address.
@@ -79,8 +113,6 @@
extraConfig = {
code-challenge-method = "S256";
whitelist-domain = ".mou.fo"; # allowed redirects after authentication
- # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761
- oidc-email-claim = "sub";
};
};
@@ -97,5 +129,6 @@
services.nginx.virtualHosts."op.mou.fo" = {
enableACME = true;
forceSSL = true;
+ locations."/dex".proxyPass = "http://127.0.0.1:5556";
};
}