Sign inSign up

gunet/simple-oidc-tester

By gunet

•Updated 12 months ago

simple OIDC tester

Buildkit cache
Image
0

10K+

gunet/simple-oidc-tester repository overview

⁠OIDC-test-client

A simple OIDC tester based on the OIDC-test-client⁠

Reference for the OIDC protocol is in OIDC-Tutorial.md

Exposed port: 9009

There are numerous environment variables available but the important ones are the following (the rest have been set to default values so that a connection to the gunet/simple-cas will work correctly):

  • OIDC_ROOT_URL: The URL of the OIDC tester. Default value: http://oidc-tester:3000
  • OIDC_PROVIDER: The root URL for the OIDC provider. Default value: https://host.docker.internal:8443/cas/oidc (to work with gunet/simple-cas)

The environment variables should be set to a value using the actual public IP, especially in a multi-container Docker compose setup.

⁠URLs

  • http://localhost:9009/health: Healthcheck URL, used by the docker healtcheck.
  • http://localhost:9009/auth/callback: OAuth Callback URL
  • http://localhost:9009/: Test URL, initiated OAuth Code flow
  • http://localhost:9009/implicit/: Tests an Implicit OIDC flow using id_token token

⁠Configuration

  • OIDC_BIND: Which address and port to bind to. (defaults 0.0.0.0:9009).
  • OIDC_CLIENT_ID: OAuth2 Client ID to use. (defaults to client)
  • OIDC_CLIENT_SECRET: OAuth2 Client Secret to use. Can be set to an empty string when only implicit flow is tested. (defaults to secret)
  • OIDC_ROOT_URL: URL under which you access this Client. Must be reachable by the user web browser (default http://oidc-tester:3000)
  • OIDC_PROVIDER: Optional URL that metadata is fetched from. The metadata is fetched on the first request to / (defaults to https://sso:8443/cas/oidc)
  • OIDC_SCOPES: Scopes to request from the provider. Defaults to openid
  • OIDC_DO_REFRESH: Whether refresh-token related checks are enabled (don't ask for a refresh token) (default: false)
  • OIDC_DO_INTROSPECTION: Whether introspection related checks are enabled (don't call introspection endpoint) (default: false)
  • OIDC_DO_USER_INFO: Whether user-info related checks are enabled (don't use userinfo endpoint) (default: true)
  • OIDC_TLS_VERIFY: Whether to verify TLS certicates (set to "false" for self-signed) (default: false)

⁠Running

This service is intended to be run in a docker container

docker run -d --rm \
    -p 9009:9009 \
    -e OIDC_CLIENT_ID=test-id \
    -e OIDC_CLIENT_SECRET=test-secret \
    -e OIDC_PROVIDER=https://sso:8443/cas/oidc/ \
    --name oidc-tester ghcr.io/gunet/simple-oidc-tester

Or if you want to use docker-compose, use this in your docker-compose.yaml.

  oidc-tester:
    image: gunet/simple-oidc-tester
    ports:
      - ${OIDC_TESTER_PORT:-3000}:9009
    environment:
      - OIDC_PROVIDER=${OIDC_PROVIDER:-https://host.docker.internal:8443/cas/oidc}
      - OIDC_ROOT_URL=${OIDC_ROOT_URL:-http://host.docker.interval:3000}
    extra_hosts:
      - "host.docker.internal:host-gateway"
    depends_on:
      ldap:
        condition: service_healthy
      sso:
        condition: service_healthy

Tag summary

Content type

Image

Digest

sha256:50dae3656…

Size

10.4 MB

Last updated

12 months ago

docker pull gunet/simple-oidc-tester