2
0

oidc_server.js 8.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250
  1. Oidc = {};
  2. httpCa = false;
  3. if (process.env.OAUTH2_CA_CERT !== undefined) {
  4. try {
  5. const fs = Npm.require('fs');
  6. httpCa = fs.readFileSync(process.env.OAUTH2_CA_CERT);
  7. } catch(e) {
  8. console.log('WARNING: failed loading: ' + process.env.OAUTH2_CA_CERT);
  9. console.log(e);
  10. }
  11. }
  12. OAuth.registerService('oidc', 2, null, function (query) {
  13. var debug = process.env.DEBUG || false;
  14. var token = getToken(query);
  15. if (debug) console.log('XXX: register token:', token);
  16. var accessToken = token.access_token || token.id_token;
  17. var expiresAt = (+new Date) + (1000 * parseInt(token.expires_in, 10));
  18. var claimsInAccessToken = (process.env.OAUTH2_ADFS_ENABLED === 'true' || process.env.OAUTH2_ADFS_ENABLED === true) || false;
  19. var userinfo;
  20. if(claimsInAccessToken)
  21. {
  22. // hack when using custom claims in the accessToken. On premise ADFS
  23. userinfo = getTokenContent(accessToken);
  24. }
  25. else
  26. {
  27. // normal behaviour, getting the claims from UserInfo endpoint.
  28. userinfo = getUserInfo(accessToken);
  29. }
  30. if (userinfo.ocs) userinfo = userinfo.ocs.data; // Nextcloud hack
  31. if (userinfo.metadata) userinfo = userinfo.metadata // Openshift hack
  32. if (debug) console.log('XXX: userinfo:', userinfo);
  33. var serviceData = {};
  34. serviceData.id = userinfo[process.env.OAUTH2_ID_MAP]; // || userinfo["id"];
  35. serviceData.username = userinfo[process.env.OAUTH2_USERNAME_MAP]; // || userinfo["uid"];
  36. serviceData.fullname = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  37. serviceData.accessToken = accessToken;
  38. serviceData.expiresAt = expiresAt;
  39. // If on Oracle OIM email is empty or null, get info from username
  40. if (process.env.ORACLE_OIM_ENABLED === 'true' || process.env.ORACLE_OIM_ENABLED === true) {
  41. if (userinfo[process.env.OAUTH2_EMAIL_MAP]) {
  42. serviceData.email = userinfo[process.env.OAUTH2_EMAIL_MAP];
  43. } else {
  44. serviceData.email = userinfo[process.env.OAUTH2_USERNAME_MAP];
  45. }
  46. }
  47. if (process.env.ORACLE_OIM_ENABLED !== 'true' && process.env.ORACLE_OIM_ENABLED !== true) {
  48. serviceData.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  49. }
  50. if (accessToken) {
  51. var tokenContent = getTokenContent(accessToken);
  52. var fields = _.pick(tokenContent, getConfiguration().idTokenWhitelistFields);
  53. _.extend(serviceData, fields);
  54. }
  55. if (token.refresh_token)
  56. serviceData.refreshToken = token.refresh_token;
  57. if (debug) console.log('XXX: serviceData:', serviceData);
  58. var profile = {};
  59. profile.name = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  60. profile.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  61. if (debug) console.log('XXX: profile:', profile);
  62. return {
  63. serviceData: serviceData,
  64. options: { profile: profile }
  65. };
  66. });
  67. var userAgent = "Meteor";
  68. if (Meteor.release) {
  69. userAgent += "/" + Meteor.release;
  70. }
  71. if (process.env.ORACLE_OIM_ENABLED !== 'true' && process.env.ORACLE_OIM_ENABLED !== true) {
  72. var getToken = function (query) {
  73. var debug = process.env.DEBUG || false;
  74. var config = getConfiguration();
  75. if(config.tokenEndpoint.includes('https://')){
  76. var serverTokenEndpoint = config.tokenEndpoint;
  77. }else{
  78. var serverTokenEndpoint = config.serverUrl + config.tokenEndpoint;
  79. }
  80. var requestPermissions = config.requestPermissions;
  81. var response;
  82. try {
  83. var postOptions = {
  84. headers: {
  85. Accept: 'application/json',
  86. "User-Agent": userAgent
  87. },
  88. params: {
  89. code: query.code,
  90. client_id: config.clientId,
  91. client_secret: OAuth.openSecret(config.secret),
  92. redirect_uri: OAuth._redirectUri('oidc', config),
  93. grant_type: 'authorization_code',
  94. state: query.state
  95. }
  96. };
  97. if (httpCa) {
  98. postOptions['npmRequestOptions'] = { ca: httpCa };
  99. }
  100. response = HTTP.post(serverTokenEndpoint, postOptions);
  101. } catch (err) {
  102. throw _.extend(new Error("Failed to get token from OIDC " + serverTokenEndpoint + ": " + err.message),
  103. { response: err.response });
  104. }
  105. if (response.data.error) {
  106. // if the http response was a json object with an error attribute
  107. throw new Error("Failed to complete handshake with OIDC " + serverTokenEndpoint + ": " + response.data.error);
  108. } else {
  109. if (debug) console.log('XXX: getToken response: ', response.data);
  110. return response.data;
  111. }
  112. };
  113. }
  114. if (process.env.ORACLE_OIM_ENABLED === 'true' || process.env.ORACLE_OIM_ENABLED === true) {
  115. var getToken = function (query) {
  116. var debug = (process.env.DEBUG === 'true' || process.env.DEBUG === true) || false;
  117. var config = getConfiguration();
  118. if(config.tokenEndpoint.includes('https://')){
  119. var serverTokenEndpoint = config.tokenEndpoint;
  120. }else{
  121. var serverTokenEndpoint = config.serverUrl + config.tokenEndpoint;
  122. }
  123. var requestPermissions = config.requestPermissions;
  124. var response;
  125. // OIM needs basic Authentication token in the header - ClientID + SECRET in base64
  126. var dataToken=null;
  127. var strBasicToken=null;
  128. var strBasicToken64=null;
  129. dataToken = process.env.OAUTH2_CLIENT_ID + ':' + process.env.OAUTH2_SECRET;
  130. strBasicToken = new Buffer(dataToken);
  131. strBasicToken64 = strBasicToken.toString('base64');
  132. // eslint-disable-next-line no-console
  133. if (debug) console.log('Basic Token: ', strBasicToken64);
  134. try {
  135. var postOptions = {
  136. headers: {
  137. Accept: 'application/json',
  138. "User-Agent": userAgent,
  139. "Authorization": "Basic " + strBasicToken64
  140. },
  141. params: {
  142. code: query.code,
  143. client_id: config.clientId,
  144. client_secret: OAuth.openSecret(config.secret),
  145. redirect_uri: OAuth._redirectUri('oidc', config),
  146. grant_type: 'authorization_code',
  147. state: query.state
  148. }
  149. };
  150. if (httpCa) {
  151. postOptions['npmRequestOptions'] = { ca: httpCa };
  152. }
  153. response = HTTP.post(serverTokenEndpoint, postOptions);
  154. } catch (err) {
  155. throw _.extend(new Error("Failed to get token from OIDC " + serverTokenEndpoint + ": " + err.message),
  156. { response: err.response });
  157. }
  158. if (response.data.error) {
  159. // if the http response was a json object with an error attribute
  160. throw new Error("Failed to complete handshake with OIDC " + serverTokenEndpoint + ": " + response.data.error);
  161. } else {
  162. // eslint-disable-next-line no-console
  163. if (debug) console.log('XXX: getToken response: ', response.data);
  164. return response.data;
  165. }
  166. };
  167. }
  168. var getUserInfo = function (accessToken) {
  169. var debug = process.env.DEBUG || false;
  170. var config = getConfiguration();
  171. // Some userinfo endpoints use a different base URL than the authorization or token endpoints.
  172. // This logic allows the end user to override the setting by providing the full URL to userinfo in their config.
  173. if (config.userinfoEndpoint.includes("https://")) {
  174. var serverUserinfoEndpoint = config.userinfoEndpoint;
  175. } else {
  176. var serverUserinfoEndpoint = config.serverUrl + config.userinfoEndpoint;
  177. }
  178. var response;
  179. try {
  180. var getOptions = {
  181. headers: {
  182. "User-Agent": userAgent,
  183. "Authorization": "Bearer " + accessToken
  184. }
  185. };
  186. if (httpCa) {
  187. getOptions['npmRequestOptions'] = { ca: httpCa };
  188. }
  189. response = HTTP.get(serverUserinfoEndpoint, getOptions);
  190. } catch (err) {
  191. throw _.extend(new Error("Failed to fetch userinfo from OIDC " + serverUserinfoEndpoint + ": " + err.message),
  192. {response: err.response});
  193. }
  194. if (debug) console.log('XXX: getUserInfo response: ', response.data);
  195. return response.data;
  196. };
  197. var getConfiguration = function () {
  198. var config = ServiceConfiguration.configurations.findOne({ service: 'oidc' });
  199. if (!config) {
  200. throw new ServiceConfiguration.ConfigError('Service oidc not configured.');
  201. }
  202. return config;
  203. };
  204. var getTokenContent = function (token) {
  205. var content = null;
  206. if (token) {
  207. try {
  208. var parts = token.split('.');
  209. var header = JSON.parse(Buffer.from(parts[0], 'base64').toString());
  210. content = JSON.parse(Buffer.from(parts[1], 'base64').toString());
  211. var signature = Buffer.from(parts[2], 'base64');
  212. var signed = parts[0] + '.' + parts[1];
  213. } catch (err) {
  214. this.content = {
  215. exp: 0
  216. };
  217. }
  218. }
  219. return content;
  220. }
  221. Oidc.retrieveCredential = function (credentialToken, credentialSecret) {
  222. return OAuth.retrieveCredential(credentialToken, credentialSecret);
  223. };