oidc_server.js 8.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252
  1. Oidc = {};
  2. httpCa = false;
  3. if (process.env.OAUTH2_CA_CERT !== undefined) {
  4. try {
  5. const fs = Npm.require('fs');
  6. if (fs.existsSync(process.env.OAUTH2_CA_CERT)) {
  7. httpCa = fs.readFileSync(process.env.OAUTH2_CA_CERT);
  8. }
  9. } catch(e) {
  10. console.log('WARNING: failed loading: ' + process.env.OAUTH2_CA_CERT);
  11. console.log(e);
  12. }
  13. }
  14. OAuth.registerService('oidc', 2, null, function (query) {
  15. var debug = process.env.DEBUG || false;
  16. var token = getToken(query);
  17. if (debug) console.log('XXX: register token:', token);
  18. var accessToken = token.access_token || token.id_token;
  19. var expiresAt = (+new Date) + (1000 * parseInt(token.expires_in, 10));
  20. var claimsInAccessToken = (process.env.OAUTH2_ADFS_ENABLED === 'true' || process.env.OAUTH2_ADFS_ENABLED === true) || false;
  21. var userinfo;
  22. if(claimsInAccessToken)
  23. {
  24. // hack when using custom claims in the accessToken. On premise ADFS
  25. userinfo = getTokenContent(accessToken);
  26. }
  27. else
  28. {
  29. // normal behaviour, getting the claims from UserInfo endpoint.
  30. userinfo = getUserInfo(accessToken);
  31. }
  32. if (userinfo.ocs) userinfo = userinfo.ocs.data; // Nextcloud hack
  33. if (userinfo.metadata) userinfo = userinfo.metadata // Openshift hack
  34. if (debug) console.log('XXX: userinfo:', userinfo);
  35. var serviceData = {};
  36. serviceData.id = userinfo[process.env.OAUTH2_ID_MAP]; // || userinfo["id"];
  37. serviceData.username = userinfo[process.env.OAUTH2_USERNAME_MAP]; // || userinfo["uid"];
  38. serviceData.fullname = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  39. serviceData.accessToken = accessToken;
  40. serviceData.expiresAt = expiresAt;
  41. // If on Oracle OIM email is empty or null, get info from username
  42. if (process.env.ORACLE_OIM_ENABLED === 'true' || process.env.ORACLE_OIM_ENABLED === true) {
  43. if (userinfo[process.env.OAUTH2_EMAIL_MAP]) {
  44. serviceData.email = userinfo[process.env.OAUTH2_EMAIL_MAP];
  45. } else {
  46. serviceData.email = userinfo[process.env.OAUTH2_USERNAME_MAP];
  47. }
  48. }
  49. if (process.env.ORACLE_OIM_ENABLED !== 'true' && process.env.ORACLE_OIM_ENABLED !== true) {
  50. serviceData.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  51. }
  52. if (accessToken) {
  53. var tokenContent = getTokenContent(accessToken);
  54. var fields = _.pick(tokenContent, getConfiguration().idTokenWhitelistFields);
  55. _.extend(serviceData, fields);
  56. }
  57. if (token.refresh_token)
  58. serviceData.refreshToken = token.refresh_token;
  59. if (debug) console.log('XXX: serviceData:', serviceData);
  60. var profile = {};
  61. profile.name = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  62. profile.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  63. if (debug) console.log('XXX: profile:', profile);
  64. return {
  65. serviceData: serviceData,
  66. options: { profile: profile }
  67. };
  68. });
  69. var userAgent = "Meteor";
  70. if (Meteor.release) {
  71. userAgent += "/" + Meteor.release;
  72. }
  73. if (process.env.ORACLE_OIM_ENABLED !== 'true' && process.env.ORACLE_OIM_ENABLED !== true) {
  74. var getToken = function (query) {
  75. var debug = process.env.DEBUG || false;
  76. var config = getConfiguration();
  77. if(config.tokenEndpoint.includes('https://')){
  78. var serverTokenEndpoint = config.tokenEndpoint;
  79. }else{
  80. var serverTokenEndpoint = config.serverUrl + config.tokenEndpoint;
  81. }
  82. var requestPermissions = config.requestPermissions;
  83. var response;
  84. try {
  85. var postOptions = {
  86. headers: {
  87. Accept: 'application/json',
  88. "User-Agent": userAgent
  89. },
  90. params: {
  91. code: query.code,
  92. client_id: config.clientId,
  93. client_secret: OAuth.openSecret(config.secret),
  94. redirect_uri: OAuth._redirectUri('oidc', config),
  95. grant_type: 'authorization_code',
  96. state: query.state
  97. }
  98. };
  99. if (httpCa) {
  100. postOptions['npmRequestOptions'] = { ca: httpCa };
  101. }
  102. response = HTTP.post(serverTokenEndpoint, postOptions);
  103. } catch (err) {
  104. throw _.extend(new Error("Failed to get token from OIDC " + serverTokenEndpoint + ": " + err.message),
  105. { response: err.response });
  106. }
  107. if (response.data.error) {
  108. // if the http response was a json object with an error attribute
  109. throw new Error("Failed to complete handshake with OIDC " + serverTokenEndpoint + ": " + response.data.error);
  110. } else {
  111. if (debug) console.log('XXX: getToken response: ', response.data);
  112. return response.data;
  113. }
  114. };
  115. }
  116. if (process.env.ORACLE_OIM_ENABLED === 'true' || process.env.ORACLE_OIM_ENABLED === true) {
  117. var getToken = function (query) {
  118. var debug = (process.env.DEBUG === 'true' || process.env.DEBUG === true) || false;
  119. var config = getConfiguration();
  120. if(config.tokenEndpoint.includes('https://')){
  121. var serverTokenEndpoint = config.tokenEndpoint;
  122. }else{
  123. var serverTokenEndpoint = config.serverUrl + config.tokenEndpoint;
  124. }
  125. var requestPermissions = config.requestPermissions;
  126. var response;
  127. // OIM needs basic Authentication token in the header - ClientID + SECRET in base64
  128. var dataToken=null;
  129. var strBasicToken=null;
  130. var strBasicToken64=null;
  131. dataToken = process.env.OAUTH2_CLIENT_ID + ':' + process.env.OAUTH2_SECRET;
  132. strBasicToken = new Buffer(dataToken);
  133. strBasicToken64 = strBasicToken.toString('base64');
  134. // eslint-disable-next-line no-console
  135. if (debug) console.log('Basic Token: ', strBasicToken64);
  136. try {
  137. var postOptions = {
  138. headers: {
  139. Accept: 'application/json',
  140. "User-Agent": userAgent,
  141. "Authorization": "Basic " + strBasicToken64
  142. },
  143. params: {
  144. code: query.code,
  145. client_id: config.clientId,
  146. client_secret: OAuth.openSecret(config.secret),
  147. redirect_uri: OAuth._redirectUri('oidc', config),
  148. grant_type: 'authorization_code',
  149. state: query.state
  150. }
  151. };
  152. if (httpCa) {
  153. postOptions['npmRequestOptions'] = { ca: httpCa };
  154. }
  155. response = HTTP.post(serverTokenEndpoint, postOptions);
  156. } catch (err) {
  157. throw _.extend(new Error("Failed to get token from OIDC " + serverTokenEndpoint + ": " + err.message),
  158. { response: err.response });
  159. }
  160. if (response.data.error) {
  161. // if the http response was a json object with an error attribute
  162. throw new Error("Failed to complete handshake with OIDC " + serverTokenEndpoint + ": " + response.data.error);
  163. } else {
  164. // eslint-disable-next-line no-console
  165. if (debug) console.log('XXX: getToken response: ', response.data);
  166. return response.data;
  167. }
  168. };
  169. }
  170. var getUserInfo = function (accessToken) {
  171. var debug = process.env.DEBUG || false;
  172. var config = getConfiguration();
  173. // Some userinfo endpoints use a different base URL than the authorization or token endpoints.
  174. // This logic allows the end user to override the setting by providing the full URL to userinfo in their config.
  175. if (config.userinfoEndpoint.includes("https://")) {
  176. var serverUserinfoEndpoint = config.userinfoEndpoint;
  177. } else {
  178. var serverUserinfoEndpoint = config.serverUrl + config.userinfoEndpoint;
  179. }
  180. var response;
  181. try {
  182. var getOptions = {
  183. headers: {
  184. "User-Agent": userAgent,
  185. "Authorization": "Bearer " + accessToken
  186. }
  187. };
  188. if (httpCa) {
  189. getOptions['npmRequestOptions'] = { ca: httpCa };
  190. }
  191. response = HTTP.get(serverUserinfoEndpoint, getOptions);
  192. } catch (err) {
  193. throw _.extend(new Error("Failed to fetch userinfo from OIDC " + serverUserinfoEndpoint + ": " + err.message),
  194. {response: err.response});
  195. }
  196. if (debug) console.log('XXX: getUserInfo response: ', response.data);
  197. return response.data;
  198. };
  199. var getConfiguration = function () {
  200. var config = ServiceConfiguration.configurations.findOne({ service: 'oidc' });
  201. if (!config) {
  202. throw new ServiceConfiguration.ConfigError('Service oidc not configured.');
  203. }
  204. return config;
  205. };
  206. var getTokenContent = function (token) {
  207. var content = null;
  208. if (token) {
  209. try {
  210. var parts = token.split('.');
  211. var header = JSON.parse(Buffer.from(parts[0], 'base64').toString());
  212. content = JSON.parse(Buffer.from(parts[1], 'base64').toString());
  213. var signature = Buffer.from(parts[2], 'base64');
  214. var signed = parts[0] + '.' + parts[1];
  215. } catch (err) {
  216. this.content = {
  217. exp: 0
  218. };
  219. }
  220. }
  221. return content;
  222. }
  223. Oidc.retrieveCredential = function (credentialToken, credentialSecret) {
  224. return OAuth.retrieveCredential(credentialToken, credentialSecret);
  225. };