oidc_server.js 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309
  1. import {addGroupsWithAttributes, addEmail, changeFullname, changeUsername} from './loginHandler';
  2. Oidc = {};
  3. httpCa = false;
  4. if (process.env.OAUTH2_CA_CERT !== undefined) {
  5. try {
  6. const fs = Npm.require('fs');
  7. if (fs.existsSync(process.env.OAUTH2_CA_CERT)) {
  8. httpCa = fs.readFileSync(process.env.OAUTH2_CA_CERT);
  9. }
  10. } catch(e) {
  11. console.log('WARNING: failed loading: ' + process.env.OAUTH2_CA_CERT);
  12. console.log(e);
  13. }
  14. }
  15. var profile = {};
  16. var serviceData = {};
  17. var userinfo = {};
  18. OAuth.registerService('oidc', 2, null, function (query) {
  19. var debug = process.env.DEBUG || false;
  20. var token = getToken(query);
  21. if (debug) console.log('XXX: register token:', token);
  22. var accessToken = token.access_token || token.id_token;
  23. var expiresAt = (+new Date) + (1000 * parseInt(token.expires_in, 10));
  24. var claimsInAccessToken = (process.env.OAUTH2_ADFS_ENABLED === 'true' || process.env.OAUTH2_ADFS_ENABLED === true) || false;
  25. if(claimsInAccessToken)
  26. {
  27. // hack when using custom claims in the accessToken. On premise ADFS
  28. userinfo = getTokenContent(accessToken);
  29. }
  30. else
  31. {
  32. // normal behaviour, getting the claims from UserInfo endpoint.
  33. userinfo = getUserInfo(accessToken);
  34. }
  35. if (userinfo.ocs) userinfo = userinfo.ocs.data; // Nextcloud hack
  36. if (userinfo.metadata) userinfo = userinfo.metadata // Openshift hack
  37. if (debug) console.log('XXX: userinfo:', userinfo);
  38. serviceData.id = userinfo[process.env.OAUTH2_ID_MAP]; // || userinfo["id"];
  39. serviceData.username = userinfo[process.env.OAUTH2_USERNAME_MAP]; // || userinfo["uid"];
  40. serviceData.fullname = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  41. serviceData.accessToken = accessToken;
  42. serviceData.expiresAt = expiresAt;
  43. // If on Oracle OIM email is empty or null, get info from username
  44. if (process.env.ORACLE_OIM_ENABLED === 'true' || process.env.ORACLE_OIM_ENABLED === true) {
  45. if (userinfo[process.env.OAUTH2_EMAIL_MAP]) {
  46. serviceData.email = userinfo[process.env.OAUTH2_EMAIL_MAP];
  47. } else {
  48. serviceData.email = userinfo[process.env.OAUTH2_USERNAME_MAP];
  49. }
  50. }
  51. if (process.env.ORACLE_OIM_ENABLED !== 'true' && process.env.ORACLE_OIM_ENABLED !== true) {
  52. serviceData.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  53. }
  54. if (accessToken) {
  55. var tokenContent = getTokenContent(accessToken);
  56. var fields = _.pick(tokenContent, getConfiguration().idTokenWhitelistFields);
  57. _.extend(serviceData, fields);
  58. }
  59. if (token.refresh_token)
  60. serviceData.refreshToken = token.refresh_token;
  61. if (debug) console.log('XXX: serviceData:', serviceData);
  62. profile.name = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  63. profile.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  64. if (debug) console.log('XXX: profile:', profile);
  65. //temporarily store data from oidc in user.services.oidc.groups to update groups
  66. serviceData.groups = (userinfo["groups"] && userinfo["wekanGroups"]) ? userinfo["wekanGroups"] : userinfo["groups"];
  67. // groups arriving as array of strings indicate there is no scope set in oidc privider
  68. // to assign teams and keep admin privileges
  69. // data needs to be treated differently.
  70. // use case: in oidc provider no scope is set, hence no group attributes.
  71. // therefore: keep admin privileges for wekan as before
  72. if(Array.isArray(serviceData.groups) && serviceData.groups.length && typeof serviceData.groups[0] === "string" )
  73. {
  74. user = Meteor.users.findOne({'_id': serviceData.id});
  75. serviceData.groups.forEach(function(groupName, i)
  76. {
  77. if(user?.isAdmin && i == 0)
  78. {
  79. // keep information of user.isAdmin since in loginHandler the user will // be updated regarding group admin privileges provided via oidc
  80. serviceData.groups[i] = {"isAdmin": true};
  81. serviceData.groups[i]["displayName"]= groupName;
  82. }
  83. else
  84. {
  85. serviceData.groups[i] = {"displayName": groupName};
  86. }
  87. });
  88. }
  89. // Fix OIDC login loop for integer user ID. Thanks to danielkaiser.
  90. // https://github.com/wekan/wekan/issues/4795
  91. Meteor.call('groupRoutineOnLogin',serviceData, ""+serviceData.id);
  92. return {
  93. serviceData: serviceData,
  94. options: { profile: profile }
  95. };
  96. });
  97. var userAgent = "Meteor";
  98. if (Meteor.release) {
  99. userAgent += "/" + Meteor.release;
  100. }
  101. if (process.env.ORACLE_OIM_ENABLED !== 'true' && process.env.ORACLE_OIM_ENABLED !== true) {
  102. var getToken = function (query) {
  103. var debug = process.env.DEBUG || false;
  104. var config = getConfiguration();
  105. if(config.tokenEndpoint.includes('https://')){
  106. var serverTokenEndpoint = config.tokenEndpoint;
  107. }else{
  108. var serverTokenEndpoint = config.serverUrl + config.tokenEndpoint;
  109. }
  110. var requestPermissions = config.requestPermissions;
  111. var response;
  112. try {
  113. var postOptions = {
  114. headers: {
  115. Accept: 'application/json',
  116. "User-Agent": userAgent
  117. },
  118. params: {
  119. code: query.code,
  120. client_id: config.clientId,
  121. client_secret: OAuth.openSecret(config.secret),
  122. redirect_uri: OAuth._redirectUri('oidc', config),
  123. grant_type: 'authorization_code',
  124. state: query.state
  125. }
  126. };
  127. if (httpCa) {
  128. postOptions['npmRequestOptions'] = { ca: httpCa };
  129. }
  130. response = HTTP.post(serverTokenEndpoint, postOptions);
  131. } catch (err) {
  132. throw _.extend(new Error("Failed to get token from OIDC " + serverTokenEndpoint + ": " + err.message),
  133. { response: err.response });
  134. }
  135. if (response.data.error) {
  136. // if the http response was a json object with an error attribute
  137. throw new Error("Failed to complete handshake with OIDC " + serverTokenEndpoint + ": " + response.data.error);
  138. } else {
  139. if (debug) console.log('XXX: getToken response: ', response.data);
  140. return response.data;
  141. }
  142. };
  143. }
  144. if (process.env.ORACLE_OIM_ENABLED === 'true' || process.env.ORACLE_OIM_ENABLED === true) {
  145. var getToken = function (query) {
  146. var debug = (process.env.DEBUG === 'true' || process.env.DEBUG === true) || false;
  147. var config = getConfiguration();
  148. if(config.tokenEndpoint.includes('https://')){
  149. var serverTokenEndpoint = config.tokenEndpoint;
  150. }else{
  151. var serverTokenEndpoint = config.serverUrl + config.tokenEndpoint;
  152. }
  153. var requestPermissions = config.requestPermissions;
  154. var response;
  155. // OIM needs basic Authentication token in the header - ClientID + SECRET in base64
  156. var dataToken=null;
  157. var strBasicToken=null;
  158. var strBasicToken64=null;
  159. dataToken = process.env.OAUTH2_CLIENT_ID + ':' + process.env.OAUTH2_SECRET;
  160. strBasicToken = new Buffer(dataToken);
  161. strBasicToken64 = strBasicToken.toString('base64');
  162. // eslint-disable-next-line no-console
  163. if (debug) console.log('Basic Token: ', strBasicToken64);
  164. try {
  165. var postOptions = {
  166. headers: {
  167. Accept: 'application/json',
  168. "User-Agent": userAgent,
  169. "Authorization": "Basic " + strBasicToken64
  170. },
  171. params: {
  172. code: query.code,
  173. client_id: config.clientId,
  174. client_secret: OAuth.openSecret(config.secret),
  175. redirect_uri: OAuth._redirectUri('oidc', config),
  176. grant_type: 'authorization_code',
  177. state: query.state
  178. }
  179. };
  180. if (httpCa) {
  181. postOptions['npmRequestOptions'] = { ca: httpCa };
  182. }
  183. response = HTTP.post(serverTokenEndpoint, postOptions);
  184. } catch (err) {
  185. throw _.extend(new Error("Failed to get token from OIDC " + serverTokenEndpoint + ": " + err.message),
  186. { response: err.response });
  187. }
  188. if (response.data.error) {
  189. // if the http response was a json object with an error attribute
  190. throw new Error("Failed to complete handshake with OIDC " + serverTokenEndpoint + ": " + response.data.error);
  191. } else {
  192. // eslint-disable-next-line no-console
  193. if (debug) console.log('XXX: getToken response: ', response.data);
  194. return response.data;
  195. }
  196. };
  197. }
  198. var getUserInfo = function (accessToken) {
  199. var debug = process.env.DEBUG || false;
  200. var config = getConfiguration();
  201. // Some userinfo endpoints use a different base URL than the authorization or token endpoints.
  202. // This logic allows the end user to override the setting by providing the full URL to userinfo in their config.
  203. if (config.userinfoEndpoint.includes("https://")) {
  204. var serverUserinfoEndpoint = config.userinfoEndpoint;
  205. } else {
  206. var serverUserinfoEndpoint = config.serverUrl + config.userinfoEndpoint;
  207. }
  208. var response;
  209. try {
  210. var getOptions = {
  211. headers: {
  212. "User-Agent": userAgent,
  213. "Authorization": "Bearer " + accessToken
  214. }
  215. };
  216. if (httpCa) {
  217. getOptions['npmRequestOptions'] = { ca: httpCa };
  218. }
  219. response = HTTP.get(serverUserinfoEndpoint, getOptions);
  220. } catch (err) {
  221. throw _.extend(new Error("Failed to fetch userinfo from OIDC " + serverUserinfoEndpoint + ": " + err.message),
  222. {response: err.response});
  223. }
  224. if (debug) console.log('XXX: getUserInfo response: ', response.data);
  225. return response.data;
  226. };
  227. var getConfiguration = function () {
  228. var config = ServiceConfiguration.configurations.findOne({ service: 'oidc' });
  229. if (!config) {
  230. throw new ServiceConfiguration.ConfigError('Service oidc not configured.');
  231. }
  232. return config;
  233. };
  234. var getTokenContent = function (token) {
  235. var content = null;
  236. if (token) {
  237. try {
  238. var parts = token.split('.');
  239. var header = JSON.parse(Buffer.from(parts[0], 'base64').toString());
  240. content = JSON.parse(Buffer.from(parts[1], 'base64').toString());
  241. var signature = Buffer.from(parts[2], 'base64');
  242. var signed = parts[0] + '.' + parts[1];
  243. } catch (err) {
  244. this.content = {
  245. exp: 0
  246. };
  247. }
  248. }
  249. return content;
  250. }
  251. Meteor.methods({
  252. 'groupRoutineOnLogin': function(info, userId)
  253. {
  254. check(info, Object);
  255. check(userId, String);
  256. var propagateOidcData = process.env.PROPAGATE_OIDC_DATA || false;
  257. if (propagateOidcData)
  258. {
  259. users= Meteor.users;
  260. user = users.findOne({'services.oidc.id': userId});
  261. if(user)
  262. {
  263. //updates/creates Groups and user admin privileges accordingly
  264. addGroupsWithAttributes(user, info.groups);
  265. if(info.email) addEmail(user, info.email);
  266. if(info.fullname) changeFullname(user, info.fullname);
  267. if(info.username) changeUsername(user, info.username);
  268. }
  269. }
  270. }
  271. });
  272. Oidc.retrieveCredential = function (credentialToken, credentialSecret) {
  273. return OAuth.retrieveCredential(credentialToken, credentialSecret);
  274. };