Sign inSign up

j0rsa/gh-auth

By j0rsa

•Updated over 5 years ago

Image
0

907

j0rsa/gh-auth repository overview

⁠Github OAuth Authentication service

This is a simple service to authenticate users via Github OAuth and use it as an authentication middleware in a bundle with Traefik

Traefik setup⁠

Docker Cloud Automated build Docker Cloud Build Status

CodeFactor

⁠Flow

Flow diagram

⁠Endpoints

MethodURLDescription
GET/healthHealthcheck which returns Code 200
GET/auth/loginRedirect to login page with required scopes for provided client id
POST/auth/tokenGet JWT token by passing user code { "code": "<code>"} after auth on https://github.com/login/oauth/authorize?scope=user%3Aread,user%3Aemail&client_id=⁠...
GET/auth/checkChecks the token and returns code 200 with Headers: X-Auth-Id with user id, X-Auth-User with user name and X-Github-Token with github oauth user token
POST/auth/refreshRefresh token with a new one by passing the old valid one { "token": "eyJhbGciOiJIUz..." }

⁠Environment variables

VariableDefault valueDescription
RUST_LOGinfodefines the log level of app
BIND_ADDRESS0.0.0.0Address of web server to listen connections
BIND_PORT8080Port of web server to listen connections
JWT_SECRET--JWT HS256 Secret Key
JWT_ISS""iss (issuer): Issuer of the JWT
JWT_AUD""aud (audience): Recipient for which the JWT is intended
JWT_EXP_DAYS30exp (expiration time): Time in days after which the JWT expires
JWT_NBF_DAYS0nbf (not before time): Time in days before which the JWT must not be accepted for processing
JWT_LEEWAY_SEC0leeway (in seconds) to the exp, iat and nbf validation to account for clock skew
GH_CLIENT_ID""Github oAuth App client id
GH_CLIENT_SECRET""Github oAuth App client secret
GH_CODE_REDIRECT""Redirect page after login
GH_SCOPE"user:read,user:email"Github Scope to request

*Bold variables are required to specify

⁠Build

⁠Build release locally

cargo build --release

⁠Build release in docker and prepare an image

docker build -t j0rsa/github-oauth-service .

ref: https://shaneutt.com/blog/rust-fast-small-docker-image-builds/⁠

ref: https://medium.com/@gdiener/how-to-build-a-smaller-docker-image-76779e18d48a⁠

⁠Troubleshooting

⁠Inspect image filesystem

docker run --rm -it <image name or id> sh

⁠Test run

docker run --rm -it github-oauth-service

Tag summary

Content type

Image

Digest

Size

8.6 MB

Last updated

over 5 years ago

docker pull j0rsa/gh-auth