From 278f61844675775af9532e9812f8138ba1deabb8 Mon Sep 17 00:00:00 2001 From: Joe Mou Date: Tue, 15 Apr 2025 22:26:50 -0400 Subject: In progress attempt to use Dex for OIDC Dex really doesn't want to be the authoritative identity provider. Static users are not very configurable. The sub claim is a base64 internal representation that we can't use in backends directly. We could jury rig email, but never got that working. Basic authentication works, but Home Assistant fails to login the user. --- hostnix/elmo/home-assistant.nix | 17 ++++++++++++++++- hostnix/elmo/oidc.nix | 39 ++++++++++++++++++++++++++++++++++++--- 2 files changed, 52 insertions(+), 4 deletions(-) (limited to 'hostnix') diff --git a/hostnix/elmo/home-assistant.nix b/hostnix/elmo/home-assistant.nix index 7c66951..0b23db0 100644 --- a/hostnix/elmo/home-assistant.nix +++ b/hostnix/elmo/home-assistant.nix @@ -63,7 +63,14 @@ use_x_forwarded_for = true; }; recorder.db_url = "postgresql://@/hass"; - auth_header = { }; + # FIXME doesn't authenticate + # auth_header.username_header = "X-Email"; + auth_header.debug = true; + logger = { + default = "info"; + logs."custom_components.auth_header" = "debug"; + }; + #binary_sensor: # - platform: template @@ -651,6 +658,14 @@ auth_request off; ''; }; + # FIXME testing shim + locations."/test" = { + proxyPass = "http://127.0.0.1:8000"; + extraConfig = '' + proxy_set_header X-User $user; + proxy_set_header X-Email $email; + ''; + }; # Disable service worker caching that works improperly with reverse proxy. # https://github.com/home-assistant/frontend/issues/14836 # https://community.home-assistant.io/t/disabling-service-worker-reverse-proxy-auth-causes-issues/167082 diff --git a/hostnix/elmo/oidc.nix b/hostnix/elmo/oidc.nix index 00d2fcf..88f8e9a 100644 --- a/hostnix/elmo/oidc.nix +++ b/hostnix/elmo/oidc.nix @@ -1,6 +1,40 @@ { lib, pkgs, ... }: { + services.dex = { + enable = true; + settings = { + issuer = "https://op.mou.fo/dex"; + storage = { + # TODO persistence? + type = "memory"; + }; + web = { + # TODO port + http = "0.0.0.0:5556"; + }; + enablePasswordDB = true; + staticPasswords = [ + { + email = "joe"; + username = "joe"; + hash = "$2y$10$Vp2MTFeHs6AYpNofOpY5YehFPhE/44VY7Z3TtdsHnBre/N64kM4Ii"; + # userID = "b0c5bafa-fa25-4b20-a9aa-ab79f4d57d18"; + userID = "joe"; + } + ]; + staticClients = [ + { + id = "288565372746006652@mou.fo"; + name = "oauth2-proxy"; + redirectURIs = [ "https://op.mou.fo/oauth2/callback" ]; + # TODO consolidate w/ oauth2-proxy.env? + secretFile = "/var/secrets/oauth2-proxy.secret"; + } + ]; + }; + }; + services.postgresql = { ensureDatabases = [ "zitadel" ]; ensureUsers = [{ @@ -71,7 +105,7 @@ reverseProxy = true; provider = "oidc"; clientID = "288565372746006652@mou.fo"; - oidcIssuerUrl = "https://zd.mou.fo"; + oidcIssuerUrl = "https://op.mou.fo/dex"; # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET. keyFile = "/var/secrets/oauth2-proxy.env"; # Ignore e-mail address. @@ -79,8 +113,6 @@ extraConfig = { code-challenge-method = "S256"; whitelist-domain = ".mou.fo"; # allowed redirects after authentication - # https://github.com/oauth2-proxy/oauth2-proxy/issues/1612#issuecomment-1099217761 - oidc-email-claim = "sub"; }; }; @@ -97,5 +129,6 @@ services.nginx.virtualHosts."op.mou.fo" = { enableACME = true; forceSSL = true; + locations."/dex".proxyPass = "http://127.0.0.1:5556"; }; } -- cgit v1.3.1