oidc_server.js 8.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236
  1. Oidc = {};
  2. OAuth.registerService('oidc', 2, null, function (query) {
  3. var debug = process.env.DEBUG || false;
  4. var token = getToken(query);
  5. if (debug) console.log('XXX: register token:', token);
  6. var accessToken = token.access_token || token.id_token;
  7. var expiresAt = (+new Date) + (1000 * parseInt(token.expires_in, 10));
  8. var claimsInAccessToken = (process.env.OAUTH2_ADFS_ENABLED === 'true' || process.env.OAUTH2_ADFS_ENABLED === true) || false;
  9. var userinfo;
  10. if(claimsInAccessToken)
  11. {
  12. // hack when using custom claims in the accessToken. On premise ADFS
  13. userinfo = getTokenContent(accessToken);
  14. }
  15. else
  16. {
  17. // normal behaviour, getting the claims from UserInfo endpoint.
  18. userinfo = getUserInfo(accessToken);
  19. }
  20. if (userinfo.ocs) userinfo = userinfo.ocs.data; // Nextcloud hack
  21. if (userinfo.metadata) userinfo = userinfo.metadata // Openshift hack
  22. if (debug) console.log('XXX: userinfo:', userinfo);
  23. var serviceData = {};
  24. serviceData.id = userinfo[process.env.OAUTH2_ID_MAP]; // || userinfo["id"];
  25. serviceData.username = userinfo[process.env.OAUTH2_USERNAME_MAP]; // || userinfo["uid"];
  26. serviceData.fullname = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  27. serviceData.accessToken = accessToken;
  28. serviceData.expiresAt = expiresAt;
  29. // If on Oracle OIM email is empty or null, get info from username
  30. if (process.env.ORACLE_OIM_ENABLED === 'true' || process.env.ORACLE_OIM_ENABLED === true) {
  31. if (userinfo[process.env.OAUTH2_EMAIL_MAP]) {
  32. serviceData.email = userinfo[process.env.OAUTH2_EMAIL_MAP];
  33. } else {
  34. serviceData.email = userinfo[process.env.OAUTH2_USERNAME_MAP];
  35. }
  36. }
  37. if (process.env.ORACLE_OIM_ENABLED !== 'true' && process.env.ORACLE_OIM_ENABLED !== true) {
  38. serviceData.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  39. }
  40. if (accessToken) {
  41. var tokenContent = getTokenContent(accessToken);
  42. var fields = _.pick(tokenContent, getConfiguration().idTokenWhitelistFields);
  43. _.extend(serviceData, fields);
  44. }
  45. if (token.refresh_token)
  46. serviceData.refreshToken = token.refresh_token;
  47. if (debug) console.log('XXX: serviceData:', serviceData);
  48. var profile = {};
  49. profile.name = userinfo[process.env.OAUTH2_FULLNAME_MAP]; // || userinfo["displayName"];
  50. profile.email = userinfo[process.env.OAUTH2_EMAIL_MAP]; // || userinfo["email"];
  51. if (debug) console.log('XXX: profile:', profile);
  52. return {
  53. serviceData: serviceData,
  54. options: { profile: profile }
  55. };
  56. });
  57. var userAgent = "Meteor";
  58. if (Meteor.release) {
  59. userAgent += "/" + Meteor.release;
  60. }
  61. if (process.env.ORACLE_OIM_ENABLED !== 'true' && process.env.ORACLE_OIM_ENABLED !== true) {
  62. var getToken = function (query) {
  63. var debug = process.env.DEBUG || false;
  64. var config = getConfiguration();
  65. if(config.tokenEndpoint.includes('https://')){
  66. var serverTokenEndpoint = config.tokenEndpoint;
  67. }else{
  68. var serverTokenEndpoint = config.serverUrl + config.tokenEndpoint;
  69. }
  70. var requestPermissions = config.requestPermissions;
  71. var response;
  72. try {
  73. response = HTTP.post(
  74. serverTokenEndpoint,
  75. {
  76. headers: {
  77. Accept: 'application/json',
  78. "User-Agent": userAgent
  79. },
  80. params: {
  81. code: query.code,
  82. client_id: config.clientId,
  83. client_secret: OAuth.openSecret(config.secret),
  84. redirect_uri: OAuth._redirectUri('oidc', config),
  85. grant_type: 'authorization_code',
  86. state: query.state
  87. }
  88. }
  89. );
  90. } catch (err) {
  91. throw _.extend(new Error("Failed to get token from OIDC " + serverTokenEndpoint + ": " + err.message),
  92. { response: err.response });
  93. }
  94. if (response.data.error) {
  95. // if the http response was a json object with an error attribute
  96. throw new Error("Failed to complete handshake with OIDC " + serverTokenEndpoint + ": " + response.data.error);
  97. } else {
  98. if (debug) console.log('XXX: getToken response: ', response.data);
  99. return response.data;
  100. }
  101. };
  102. }
  103. if (process.env.ORACLE_OIM_ENABLED === 'true' || process.env.ORACLE_OIM_ENABLED === true) {
  104. var getToken = function (query) {
  105. var debug = (process.env.DEBUG === 'true' || process.env.DEBUG === true) || false;
  106. var config = getConfiguration();
  107. if(config.tokenEndpoint.includes('https://')){
  108. var serverTokenEndpoint = config.tokenEndpoint;
  109. }else{
  110. var serverTokenEndpoint = config.serverUrl + config.tokenEndpoint;
  111. }
  112. var requestPermissions = config.requestPermissions;
  113. var response;
  114. // OIM needs basic Authentication token in the header - ClientID + SECRET in base64
  115. var dataToken=null;
  116. var strBasicToken=null;
  117. var strBasicToken64=null;
  118. dataToken = process.env.OAUTH2_CLIENT_ID + ':' + process.env.OAUTH2_SECRET;
  119. strBasicToken = new Buffer(dataToken);
  120. strBasicToken64 = strBasicToken.toString('base64');
  121. // eslint-disable-next-line no-console
  122. if (debug) console.log('Basic Token: ', strBasicToken64);
  123. try {
  124. response = HTTP.post(
  125. serverTokenEndpoint,
  126. {
  127. headers: {
  128. Accept: 'application/json',
  129. "User-Agent": userAgent,
  130. "Authorization": "Basic " + strBasicToken64
  131. },
  132. params: {
  133. code: query.code,
  134. client_id: config.clientId,
  135. client_secret: OAuth.openSecret(config.secret),
  136. redirect_uri: OAuth._redirectUri('oidc', config),
  137. grant_type: 'authorization_code',
  138. state: query.state
  139. }
  140. }
  141. );
  142. } catch (err) {
  143. throw _.extend(new Error("Failed to get token from OIDC " + serverTokenEndpoint + ": " + err.message),
  144. { response: err.response });
  145. }
  146. if (response.data.error) {
  147. // if the http response was a json object with an error attribute
  148. throw new Error("Failed to complete handshake with OIDC " + serverTokenEndpoint + ": " + response.data.error);
  149. } else {
  150. // eslint-disable-next-line no-console
  151. if (debug) console.log('XXX: getToken response: ', response.data);
  152. return response.data;
  153. }
  154. };
  155. }
  156. var getUserInfo = function (accessToken) {
  157. var debug = process.env.DEBUG || false;
  158. var config = getConfiguration();
  159. // Some userinfo endpoints use a different base URL than the authorization or token endpoints.
  160. // This logic allows the end user to override the setting by providing the full URL to userinfo in their config.
  161. if (config.userinfoEndpoint.includes("https://")) {
  162. var serverUserinfoEndpoint = config.userinfoEndpoint;
  163. } else {
  164. var serverUserinfoEndpoint = config.serverUrl + config.userinfoEndpoint;
  165. }
  166. var response;
  167. try {
  168. response = HTTP.get(
  169. serverUserinfoEndpoint,
  170. {
  171. headers: {
  172. "User-Agent": userAgent,
  173. "Authorization": "Bearer " + accessToken
  174. }
  175. }
  176. );
  177. } catch (err) {
  178. throw _.extend(new Error("Failed to fetch userinfo from OIDC " + serverUserinfoEndpoint + ": " + err.message),
  179. {response: err.response});
  180. }
  181. if (debug) console.log('XXX: getUserInfo response: ', response.data);
  182. return response.data;
  183. };
  184. var getConfiguration = function () {
  185. var config = ServiceConfiguration.configurations.findOne({ service: 'oidc' });
  186. if (!config) {
  187. throw new ServiceConfiguration.ConfigError('Service oidc not configured.');
  188. }
  189. return config;
  190. };
  191. var getTokenContent = function (token) {
  192. var content = null;
  193. if (token) {
  194. try {
  195. var parts = token.split('.');
  196. var header = JSON.parse(Buffer.from(parts[0], 'base64').toString());
  197. content = JSON.parse(Buffer.from(parts[1], 'base64').toString());
  198. var signature = Buffer.from(parts[2], 'base64');
  199. var signed = parts[0] + '.' + parts[1];
  200. } catch (err) {
  201. this.content = {
  202. exp: 0
  203. };
  204. }
  205. }
  206. return content;
  207. }
  208. Oidc.retrieveCredential = function (credentialToken, credentialSecret) {
  209. return OAuth.retrieveCredential(credentialToken, credentialSecret);
  210. };