summaryrefslogtreecommitdiff
path: root/hostnix/elmo/oidc.nix
diff options
context:
space:
mode:
Diffstat (limited to 'hostnix/elmo/oidc.nix')
-rw-r--r--hostnix/elmo/oidc.nix39
1 files changed, 36 insertions, 3 deletions
diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix
index 00d2fcf..88f8e9a 100644
--- a/hostnix/elmo/oidc.nix
+++ b/hostnix/elmo/oidc.nix
@@ -1,6 +1,40 @@
{ lib, pkgs, ... }:
{
+ services.dex = {
+ enable = true;
+ settings = {
+ issuer = "https://op.mou.fo/dex";
+ storage = {
+ # TODO persistence?
+ type = "memory";
+ };
+ web = {
+ # TODO port
+ http = "0.0.0.0:5556";
+ };
+ enablePasswordDB = true;
+ staticPasswords = [
+ {
+ email = "joe";
+ username = "joe";
+ hash = "$2y$10$Vp2MTFeHs6AYpNofOpY5YehFPhE/44VY7Z3TtdsHnBre/N64kM4Ii";
+ # userID = "b0c5bafa-fa25-4b20-a9aa-ab79f4d57d18";
+ userID = "joe";
+ }
+ ];
+ staticClients = [
+ {
+ id = "288565372746006652@mou.fo";
+ name = "oauth2-proxy";
+ redirectURIs = [ "https://op.mou.fo/oauth2/callback" ];
+ # TODO consolidate w/ oauth2-proxy.env?
+ secretFile = "/var/secrets/oauth2-proxy.secret";
+ }
+ ];
+ };
+ };
+
services.postgresql = {
ensureDatabases = [ "zitadel" ];
ensureUsers = [{
@@ -71,7 +105,7 @@
reverseProxy = true;
provider = "oidc";
clientID = "288565372746006652@mou.fo";
- oidcIssuerUrl = "https://zd.mou.fo";
+ oidcIssuerUrl = "https://op.mou.fo/dex";
# Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
keyFile = "/var/secrets/oauth2-proxy.env";
# Ignore e-mail address.
@@ -79,8 +113,6 @@
extraConfig = {
code-challenge-method = "S256";
whitelist-domain = ".mou.fo"; # allowed redirects after authentication
- # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761
- oidc-email-claim = "sub";
};
};
@@ -97,5 +129,6 @@
services.nginx.virtualHosts."op.mou.fo" = {
enableACME = true;
forceSSL = true;
+ locations."/dex".proxyPass = "http://127.0.0.1:5556";
};
}