summaryrefslogtreecommitdiff
path: root/hostnix/elmo/oidc.nix
blob: 40a0528a612cce8690273f16582acc478bf7f6e6 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
{ lib, pkgs, ... }:

{
  systemd.tmpfiles.rules = [
    "d /run/pocket-id 750 pocket-id nginx"
  ];

  # - Create user joe
  # - Create OIDC Client: oauth2-proxy
  #   - Callback URLs: https://op.mou.fo/oauth2/callback
  #   - PKCE
  services.pocket-id = {
    enable = true;
    settings = {
      APP_URL = "https://pi.mou.fo";
      TRUST_PROXY = true;
      UNIX_SOCKET = "/run/pocket-id/socket";
      UNIX_SOCKET_MODE = "0777";

      # https://pocket-id.org/docs/configuration/environment-variables#overriding-the-ui-configuration
      UI_CONFIG_DISABLED = true;
      EMAILS_VERIFIED = true; # needed by oauth2-proxy
      SMTP_HOST = "localhost";
      SMTP_PORT = 25;
      SMTP_FROM = "noreply@pi.mou.fo";
      EMAIL_LOGIN_NOTIFICATION_ENABLED = true;
      EMAIL_API_KEY_EXPIRATION_ENABLED = true;
      EMAIL_ONE_TIME_ACCESS_AS_UNAUTHENTICATED_ENABLED = true;
    };
  };

  services.nginx.virtualHosts."pi.mou.fo" = {
    enableACME = true;
    forceSSL = true;
    locations."/".proxyPass = "http://unix:/run/pocket-id/socket";
  };

  # The oauth2-proxy module has a magic nginx.virtualHosts option that rewrites
  # nginx configs. It can be heavy handed, but we use it for brevity. In
  # particular, it configures Traefik-like ForwardAuth authentication with
  # auth_request. Note if this resource is missing for whatever reason, the
  # module magic will fail open (auth_request unset).
  services.oauth2-proxy = {
    enable = true;
    cookie.domain = "mou.fo";
    nginx.domain = "op.mou.fo";
    setXauthrequest = true; # let oauth2-proxy nginx module pass X-User/X-Email
    reverseProxy = true;
    provider = "oidc";
    clientID = "39edd929-8983-4cb6-b1cd-dc08e2e3358f";
    oidcIssuerUrl = "https://pi.mou.fo";
    # Sets OAUTH2_PROXY_COOKIE_SECRET and OAUTH2_PROXY_CLIENT_SECRET.
    keyFile = "/var/secrets/oauth2-proxy.env";
    # Ignore e-mail address.
    email.domains = [ "*" ];
    extraConfig = {
      code-challenge-method = "S256";
      whitelist-domain = ".mou.fo"; # allowed redirects after authentication
    };
  };

  systemd.services.oauth2-proxy.after = [ "pocket-id.service" ];

  # It's somewhat overkill to assign oauth2-proxy its own domain. We can't use
  # Kanidm's though, because it uses the /oauth2 path which the oauth2-proxy
  # nginx module is hardcoded for (proxyPrefix is ignored); this module magic is
  # also why we do not need to explicitly specify proxyPass.
  services.nginx.virtualHosts."op.mou.fo" = {
    enableACME = true;
    forceSSL = true;
  };
}