oidc_server.js 5.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163
  1. Oidc = {};
  2. OAuth.registerService('oidc', 2, null, function (query) {
  3. var debug = process.env.DEBUG || false;
  4. var token = getToken(query);
  5. if (debug) console.log('XXX: register token:', token);
  6. var accessToken = token.access_token || token.id_token;
  7. var expiresAt = (+new Date) + (1000 * parseInt(token.expires_in, 10));
  8. var claimsInAccessToken = process.env.OAUTH2_ADFS || false;
  9. var userinfo;
  10. if(claimsInAccessToken)
  11. {
  12. // hack when using custom claims in the accessToken. On premise ADFS
  13. userinfo = getTokenContent(accessToken);
  14. }
  15. else
  16. {
  17. // normal behaviour, getting the claims from UserInfo endpoint.
  18. userinfo = getUserInfo(accessToken);
  19. }
  20. if (userinfo.ocs) userinfo = userinfo.ocs.data; // Nextcloud hack
  21. if (userinfo.metadata) userinfo = userinfo.metadata // Openshift hack
  22. if (debug) console.log('XXX: userinfo:', userinfo);
  23. var serviceData = {};
  24. serviceData.id = userinfo[process.env.OAUTH2_ID_MAP]; // || userinfo["id"];
  25. serviceData.username = userinfo[process.env.OAUTH2_USERNAME_MAP]; // || userinfo["uid"];
  26. serviceData.fullname = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  27. serviceData.accessToken = accessToken;
  28. serviceData.expiresAt = expiresAt;
  29. serviceData.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  30. if (accessToken) {
  31. var tokenContent = getTokenContent(accessToken);
  32. var fields = _.pick(tokenContent, getConfiguration().idTokenWhitelistFields);
  33. _.extend(serviceData, fields);
  34. }
  35. if (token.refresh_token)
  36. serviceData.refreshToken = token.refresh_token;
  37. if (debug) console.log('XXX: serviceData:', serviceData);
  38. var profile = {};
  39. profile.name = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  40. profile.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  41. if (debug) console.log('XXX: profile:', profile);
  42. return {
  43. serviceData: serviceData,
  44. options: { profile: profile }
  45. };
  46. });
  47. var userAgent = "Meteor";
  48. if (Meteor.release) {
  49. userAgent += "/" + Meteor.release;
  50. }
  51. var getToken = function (query) {
  52. var debug = process.env.DEBUG || false;
  53. var config = getConfiguration();
  54. if(config.tokenEndpoint.includes('https://')){
  55. var serverTokenEndpoint = config.tokenEndpoint;
  56. }else{
  57. var serverTokenEndpoint = config.serverUrl + config.tokenEndpoint;
  58. }
  59. var requestPermissions = config.requestPermissions;
  60. var response;
  61. try {
  62. response = HTTP.post(
  63. serverTokenEndpoint,
  64. {
  65. headers: {
  66. Accept: 'application/json',
  67. "User-Agent": userAgent
  68. },
  69. params: {
  70. code: query.code,
  71. client_id: config.clientId,
  72. client_secret: OAuth.openSecret(config.secret),
  73. redirect_uri: OAuth._redirectUri('oidc', config),
  74. grant_type: 'authorization_code',
  75. state: query.state
  76. }
  77. }
  78. );
  79. } catch (err) {
  80. throw _.extend(new Error("Failed to get token from OIDC " + serverTokenEndpoint + ": " + err.message),
  81. { response: err.response });
  82. }
  83. if (response.data.error) {
  84. // if the http response was a json object with an error attribute
  85. throw new Error("Failed to complete handshake with OIDC " + serverTokenEndpoint + ": " + response.data.error);
  86. } else {
  87. if (debug) console.log('XXX: getToken response: ', response.data);
  88. return response.data;
  89. }
  90. };
  91. var getUserInfo = function (accessToken) {
  92. var debug = process.env.DEBUG || false;
  93. var config = getConfiguration();
  94. // Some userinfo endpoints use a different base URL than the authorization or token endpoints.
  95. // This logic allows the end user to override the setting by providing the full URL to userinfo in their config.
  96. if (config.userinfoEndpoint.includes("https://")) {
  97. var serverUserinfoEndpoint = config.userinfoEndpoint;
  98. } else {
  99. var serverUserinfoEndpoint = config.serverUrl + config.userinfoEndpoint;
  100. }
  101. var response;
  102. try {
  103. response = HTTP.get(
  104. serverUserinfoEndpoint,
  105. {
  106. headers: {
  107. "User-Agent": userAgent,
  108. "Authorization": "Bearer " + accessToken
  109. }
  110. }
  111. );
  112. } catch (err) {
  113. throw _.extend(new Error("Failed to fetch userinfo from OIDC " + serverUserinfoEndpoint + ": " + err.message),
  114. {response: err.response});
  115. }
  116. if (debug) console.log('XXX: getUserInfo response: ', response.data);
  117. return response.data;
  118. };
  119. var getConfiguration = function () {
  120. var config = ServiceConfiguration.configurations.findOne({ service: 'oidc' });
  121. if (!config) {
  122. throw new ServiceConfiguration.ConfigError('Service oidc not configured.');
  123. }
  124. return config;
  125. };
  126. var getTokenContent = function (token) {
  127. var content = null;
  128. if (token) {
  129. try {
  130. var parts = token.split('.');
  131. var header = JSON.parse(Buffer.from(parts[0], 'base64').toString());
  132. content = JSON.parse(Buffer.from(parts[1], 'base64').toString());
  133. var signature = Buffer.from(parts[2], 'base64');
  134. var signed = parts[0] + '.' + parts[1];
  135. } catch (err) {
  136. this.content = {
  137. exp: 0
  138. };
  139. }
  140. }
  141. return content;
  142. }
  143. Oidc.retrieveCredential = function (credentialToken, credentialSecret) {
  144. return OAuth.retrieveCredential(credentialToken, credentialSecret);
  145. };