diff options
| -rw-r--r-- | hostnix/elmo/home-assistant.nix | 17 | ||||
| -rw-r--r-- | hostnix/elmo/oidc.nix | 39 |
2 files changed, 52 insertions, 4 deletions
diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix index 7c66951..0b23db0 100644 --- a/hostnix/elmo/home-assistant.nix +++ b/hostnix/elmo/home-assistant.nix @@ -63,7 +63,14 @@ use_x_forwarded_for = true; }; recorder.db_url = "postgresql://@/hass"; - auth_header = { }; + # FIXME doesn't authenticate + # auth_header.username_header = "X-Email"; + auth_header.debug = true; + logger = { + default = "info"; + logs."custom_components.auth_header" = "debug"; + }; + #binary_sensor: # - platform: template @@ -651,6 +658,14 @@ auth_request off; ''; }; + # FIXME testing shim + locations."/test" = { + proxyPass = "http://127.0.0.1:8000"; + extraConfig = '' + proxy_set_header X-User $user; + proxy_set_header X-Email $email; + ''; + }; # Disable service worker caching that works improperly with reverse proxy. # https://github.com/home-assistant/frontend/issues/14836 # https://community.home-assistant.io/t/disabling-service-worker-reverse-proxy-auth-causes-issues/167082 diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index 00d2fcf..88f8e9a 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -1,6 +1,40 @@ { lib, pkgs, ... }: { + services.dex = { + enable = true; + settings = { + issuer = "https://op.mou.fo/dex"; + storage = { + # TODO persistence? + type = "memory"; + }; + web = { + # TODO port + http = "0.0.0.0:5556"; + }; + enablePasswordDB = true; + staticPasswords = [ + { + email = "joe"; + username = "joe"; + hash = "$2y$10$Vp2MTFeHs6AYpNofOpY5YehFPhE/44VY7Z3TtdsHnBre/N64kM4Ii"; + # userID = "b0c5bafa-fa25-4b20-a9aa-ab79f4d57d18"; + userID = "joe"; + } + ]; + staticClients = [ + { + id = "288565372746006652@mou.fo"; + name = "oauth2-proxy"; + redirectURIs = [ "https://op.mou.fo/oauth2/callback" ]; + # TODO consolidate w/ oauth2-proxy.env? + secretFile = "/var/secrets/oauth2-proxy.secret"; + } + ]; + }; + }; + services.postgresql = { ensureDatabases = [ "zitadel" ]; ensureUsers = [{ @@ -71,7 +105,7 @@ reverseProxy = true; provider = "oidc"; clientID = "288565372746006652@mou.fo"; - oidcIssuerUrl = "https://zd.mou.fo"; + oidcIssuerUrl = "https://op.mou.fo/dex"; # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. keyFile = "/var/secrets/oauth2-proxy.env"; # Ignore e-mail address. @@ -79,8 +113,6 @@ extraConfig = { code-challenge-method = "S256"; whitelist-domain = ".mou.fo"; # allowed redirects after authentication - # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761 - oidc-email-claim = "sub"; }; }; @@ -97,5 +129,6 @@ services.nginx.virtualHosts."op.mou.fo" = { enableACME = true; forceSSL = true; + locations."/dex".proxyPass = "http://127.0.0.1:5556"; }; } |
