oidc_server.js 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163
  1. Oidc = {};
  2. OAuth.registerService('oidc', 2, null, function(query) {
  3. var debug = process.env.DEBUG || false;
  4. var token = getToken(query);
  5. if (debug) console.log('XXX: register token:', token);
  6. var accessToken = token.access_token || token.id_token;
  7. var expiresAt = +new Date() + 1000 * parseInt(token.expires_in, 10);
  8. var userinfo = getUserInfo(accessToken);
  9. if (debug) console.log('XXX: userinfo:', userinfo);
  10. var serviceData = {};
  11. serviceData.id = userinfo[process.env.OAUTH2_ID_MAP]; // || userinfo["id"];
  12. serviceData.username = userinfo[process.env.OAUTH2_USERNAME_MAP]; // || userinfo["uid"];
  13. serviceData.fullname = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  14. serviceData.accessToken = accessToken;
  15. serviceData.expiresAt = expiresAt;
  16. serviceData.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  17. if (accessToken) {
  18. var tokenContent = getTokenContent(accessToken);
  19. var fields = _.pick(
  20. tokenContent,
  21. getConfiguration().idTokenWhitelistFields,
  22. );
  23. _.extend(serviceData, fields);
  24. }
  25. if (token.refresh_token) serviceData.refreshToken = token.refresh_token;
  26. if (debug) console.log('XXX: serviceData:', serviceData);
  27. var profile = {};
  28. profile.name = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  29. profile.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  30. if (debug) console.log('XXX: profile:', profile);
  31. return {
  32. serviceData: serviceData,
  33. options: { profile: profile },
  34. };
  35. });
  36. var userAgent = 'Meteor';
  37. if (Meteor.release) {
  38. userAgent += '/' + Meteor.release;
  39. }
  40. var getToken = function(query) {
  41. var debug = process.env.DEBUG || false;
  42. var config = getConfiguration();
  43. if (config.tokenEndpoint.includes('https://')) {
  44. var serverTokenEndpoint = config.tokenEndpoint;
  45. } else {
  46. var serverTokenEndpoint = config.serverUrl + config.tokenEndpoint;
  47. }
  48. var requestPermissions = config.requestPermissions;
  49. var response;
  50. try {
  51. response = HTTP.post(serverTokenEndpoint, {
  52. headers: {
  53. Accept: 'application/json',
  54. 'User-Agent': userAgent,
  55. },
  56. params: {
  57. code: query.code,
  58. client_id: config.clientId,
  59. client_secret: OAuth.openSecret(config.secret),
  60. redirect_uri: OAuth._redirectUri('oidc', config),
  61. grant_type: 'authorization_code',
  62. scope: requestPermissions,
  63. state: query.state,
  64. },
  65. });
  66. } catch (err) {
  67. throw _.extend(
  68. new Error(
  69. 'Failed to get token from OIDC ' +
  70. serverTokenEndpoint +
  71. ': ' +
  72. err.message,
  73. ),
  74. { response: err.response },
  75. );
  76. }
  77. if (response.data.error) {
  78. // if the http response was a json object with an error attribute
  79. throw new Error(
  80. 'Failed to complete handshake with OIDC ' +
  81. serverTokenEndpoint +
  82. ': ' +
  83. response.data.error,
  84. );
  85. } else {
  86. if (debug) console.log('XXX: getToken response: ', response.data);
  87. return response.data;
  88. }
  89. };
  90. var getUserInfo = function(accessToken) {
  91. var debug = process.env.DEBUG || false;
  92. var config = getConfiguration();
  93. // Some userinfo endpoints use a different base URL than the authorization or token endpoints.
  94. // This logic allows the end user to override the setting by providing the full URL to userinfo in their config.
  95. if (config.userinfoEndpoint.includes('https://')) {
  96. var serverUserinfoEndpoint = config.userinfoEndpoint;
  97. } else {
  98. var serverUserinfoEndpoint = config.serverUrl + config.userinfoEndpoint;
  99. }
  100. var response;
  101. try {
  102. response = HTTP.get(serverUserinfoEndpoint, {
  103. headers: {
  104. 'User-Agent': userAgent,
  105. Authorization: 'Bearer ' + accessToken,
  106. },
  107. });
  108. } catch (err) {
  109. throw _.extend(
  110. new Error(
  111. 'Failed to fetch userinfo from OIDC ' +
  112. serverUserinfoEndpoint +
  113. ': ' +
  114. err.message,
  115. ),
  116. { response: err.response },
  117. );
  118. }
  119. if (debug) console.log('XXX: getUserInfo response: ', response.data);
  120. return response.data;
  121. };
  122. var getConfiguration = function() {
  123. var config = ServiceConfiguration.configurations.findOne({ service: 'oidc' });
  124. if (!config) {
  125. throw new ServiceConfiguration.ConfigError('Service oidc not configured.');
  126. }
  127. return config;
  128. };
  129. var getTokenContent = function(token) {
  130. var content = null;
  131. if (token) {
  132. try {
  133. var parts = token.split('.');
  134. var header = JSON.parse(new Buffer(parts[0], 'base64').toString());
  135. content = JSON.parse(new Buffer(parts[1], 'base64').toString());
  136. var signature = new Buffer(parts[2], 'base64');
  137. var signed = parts[0] + '.' + parts[1];
  138. } catch (err) {
  139. this.content = {
  140. exp: 0,
  141. };
  142. }
  143. }
  144. return content;
  145. };
  146. Oidc.retrieveCredential = function(credentialToken, credentialSecret) {
  147. return OAuth.retrieveCredential(credentialToken, credentialSecret);
  148. };