oidc_server.js 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150
  1. Oidc = {};
  2. OAuth.registerService('oidc', 2, null, function (query) {
  3. var debug = process.env.DEBUG || false;
  4. var token = getToken(query);
  5. if (debug) console.log('XXX: register token:', token);
  6. var accessToken = token.access_token || token.id_token;
  7. var expiresAt = (+new Date) + (1000 * parseInt(token.expires_in, 10));
  8. var userinfo = getUserInfo(accessToken);
  9. if (userinfo.ocs) userinfo = userinfo.ocs.data; // Nextcloud hack
  10. if (userinfo.metadata) userinfo = userinfo.metadata // Openshift hack
  11. if (debug) console.log('XXX: userinfo:', userinfo);
  12. var serviceData = {};
  13. serviceData.id = userinfo[process.env.OAUTH2_ID_MAP]; // || userinfo["id"];
  14. serviceData.username = userinfo[process.env.OAUTH2_USERNAME_MAP]; // || userinfo["uid"];
  15. serviceData.fullname = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  16. serviceData.accessToken = accessToken;
  17. serviceData.expiresAt = expiresAt;
  18. serviceData.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  19. if (accessToken) {
  20. var tokenContent = getTokenContent(accessToken);
  21. var fields = _.pick(tokenContent, getConfiguration().idTokenWhitelistFields);
  22. _.extend(serviceData, fields);
  23. }
  24. if (token.refresh_token)
  25. serviceData.refreshToken = token.refresh_token;
  26. if (debug) console.log('XXX: serviceData:', serviceData);
  27. var profile = {};
  28. profile.name = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  29. profile.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  30. if (debug) console.log('XXX: profile:', profile);
  31. return {
  32. serviceData: serviceData,
  33. options: { profile: profile }
  34. };
  35. });
  36. var userAgent = "Meteor";
  37. if (Meteor.release) {
  38. userAgent += "/" + Meteor.release;
  39. }
  40. var getToken = function (query) {
  41. var debug = process.env.DEBUG || false;
  42. var config = getConfiguration();
  43. if(config.tokenEndpoint.includes('https://')){
  44. var serverTokenEndpoint = config.tokenEndpoint;
  45. }else{
  46. var serverTokenEndpoint = config.serverUrl + config.tokenEndpoint;
  47. }
  48. var requestPermissions = config.requestPermissions;
  49. var response;
  50. try {
  51. response = HTTP.post(
  52. serverTokenEndpoint,
  53. {
  54. headers: {
  55. Accept: 'application/json',
  56. "User-Agent": userAgent
  57. },
  58. params: {
  59. code: query.code,
  60. client_id: config.clientId,
  61. client_secret: OAuth.openSecret(config.secret),
  62. redirect_uri: OAuth._redirectUri('oidc', config),
  63. grant_type: 'authorization_code',
  64. state: query.state
  65. }
  66. }
  67. );
  68. } catch (err) {
  69. throw _.extend(new Error("Failed to get token from OIDC " + serverTokenEndpoint + ": " + err.message),
  70. { response: err.response });
  71. }
  72. if (response.data.error) {
  73. // if the http response was a json object with an error attribute
  74. throw new Error("Failed to complete handshake with OIDC " + serverTokenEndpoint + ": " + response.data.error);
  75. } else {
  76. if (debug) console.log('XXX: getToken response: ', response.data);
  77. return response.data;
  78. }
  79. };
  80. var getUserInfo = function (accessToken) {
  81. var debug = process.env.DEBUG || false;
  82. var config = getConfiguration();
  83. // Some userinfo endpoints use a different base URL than the authorization or token endpoints.
  84. // This logic allows the end user to override the setting by providing the full URL to userinfo in their config.
  85. if (config.userinfoEndpoint.includes("https://")) {
  86. var serverUserinfoEndpoint = config.userinfoEndpoint;
  87. } else {
  88. var serverUserinfoEndpoint = config.serverUrl + config.userinfoEndpoint;
  89. }
  90. var response;
  91. try {
  92. response = HTTP.get(
  93. serverUserinfoEndpoint,
  94. {
  95. headers: {
  96. "User-Agent": userAgent,
  97. "Authorization": "Bearer " + accessToken
  98. }
  99. }
  100. );
  101. } catch (err) {
  102. throw _.extend(new Error("Failed to fetch userinfo from OIDC " + serverUserinfoEndpoint + ": " + err.message),
  103. {response: err.response});
  104. }
  105. if (debug) console.log('XXX: getUserInfo response: ', response.data);
  106. return response.data;
  107. };
  108. var getConfiguration = function () {
  109. var config = ServiceConfiguration.configurations.findOne({ service: 'oidc' });
  110. if (!config) {
  111. throw new ServiceConfiguration.ConfigError('Service oidc not configured.');
  112. }
  113. return config;
  114. };
  115. var getTokenContent = function (token) {
  116. var content = null;
  117. if (token) {
  118. try {
  119. var parts = token.split('.');
  120. var header = JSON.parse(Buffer.from(parts[0], 'base64').toString());
  121. content = JSON.parse(Buffer.from(parts[1], 'base64').toString());
  122. var signature = Buffer.from(parts[2], 'base64');
  123. var signed = parts[0] + '.' + parts[1];
  124. } catch (err) {
  125. this.content = {
  126. exp: 0
  127. };
  128. }
  129. }
  130. return content;
  131. }
  132. Oidc.retrieveCredential = function (credentialToken, credentialSecret) {
  133. return OAuth.retrieveCredential(credentialToken, credentialSecret);
  134. };