diff options
| author | Joe Mou <dev@mou.fo> | 2025-04-15 22:26:50 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2025-06-16 13:58:57 -0400 |
| commit | 278f61844675775af9532e9812f8138ba1deabb8 (patch) | |
| tree | 08c86ac883cb0c2f201d8c41216d5459775f02b1 /hostnix | |
| parent | ab1be6d042aba753dbb0041a0316ac3541c4daf2 (diff) | |
In progress attempt to use Dex for OIDC
Dex really doesn't want to be the authoritative identity provider.
Static users are not very configurable. The sub claim is a base64
internal representation that we can't use in backends directly. We could
jury rig email, but never got that working.
Basic authentication works, but Home Assistant fails to login the user.
Diffstat (limited to 'hostnix')
| -rw-r--r-- | hostnix/elmo/home-assistant.nix | 17 | ||||
| -rw-r--r-- | hostnix/elmo/oidc.nix | 39 |
2 files changed, 52 insertions, 4 deletions
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix index 7c66951..0b23db0 100644 --- a/hostnix/elmo/home-assistant.nix +++ b/hostnix/elmo/home-assistant.nix @@ -63,7 +63,14 @@ use_x_forwarded_for = true; }; recorder.db_url = "postgresql://@/hass"; - auth_header = { }; + # FIXME doesn't authenticate + # auth_header.username_header = "X-Email"; + auth_header.debug = true; + logger = { + default = "info"; + logs."custom_components.auth_header" = "debug"; + }; + #binary_sensor: # - platform: template @@ -651,6 +658,14 @@ auth_request off; ''; }; + # FIXME testing shim + locations."/test" = { + proxyPass = "http://127.0.0.1:8000"; + extraConfig = '' + proxy_set_header X-User $user; + proxy_set_header X-Email $email; + ''; + }; # Disable service worker caching that works improperly with reverse proxy. # https://github.com/home-assistant/frontend/issues/14836 # https://community.home-assistant.io/t/disabling-service-worker-reverse-proxy-auth-causes-issues/167082 diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index 00d2fcf..88f8e9a 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -1,6 +1,40 @@ { lib, pkgs, ... }: { + services.dex = { + enable = true; + settings = { + issuer = "https://op.mou.fo/dex"; + storage = { + # TODO persistence? + type = "memory"; + }; + web = { + # TODO port + http = "0.0.0.0:5556"; + }; + enablePasswordDB = true; + staticPasswords = [ + { + email = "joe"; + username = "joe"; + hash = "$2y$10$Vp2MTFeHs6AYpNofOpY5YehFPhE/44VY7Z3TtdsHnBre/N64kM4Ii"; + # userID = "b0c5bafa-fa25-4b20-a9aa-ab79f4d57d18"; + userID = "joe"; + } + ]; + staticClients = [ + { + id = "288565372746006652@mou.fo"; + name = "oauth2-proxy"; + redirectURIs = [ "https://op.mou.fo/oauth2/callback" ]; + # TODO consolidate w/ oauth2-proxy.env? + secretFile = "/var/secrets/oauth2-proxy.secret"; + } + ]; + }; + }; + services.postgresql = { ensureDatabases = [ "zitadel" ]; ensureUsers = [{ @@ -71,7 +105,7 @@ reverseProxy = true; provider = "oidc"; clientID = "288565372746006652@mou.fo"; - oidcIssuerUrl = "https://zd.mou.fo"; + oidcIssuerUrl = "https://op.mou.fo/dex"; # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. keyFile = "/var/secrets/oauth2-proxy.env"; # Ignore e-mail address. @@ -79,8 +113,6 @@ extraConfig = { code-challenge-method = "S256"; whitelist-domain = ".mou.fo"; # allowed redirects after authentication - # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761 - oidc-email-claim = "sub"; }; }; @@ -97,5 +129,6 @@ services.nginx.virtualHosts."op.mou.fo" = { enableACME = true; forceSSL = true; + locations."/dex".proxyPass = "http://127.0.0.1:5556"; }; } |
