Dockerized JWT key server with auth0/node-jsonwebtoken.
/config/jwt_private.pem, /config/jwt_public.pem, /config/users.json/captcha or /captcha.html and solve the captcha first--captcha and Docker COMMAND to enablepassword_hash.js--plaintext to enable (NOT RECOMMENDED FOR PRODUCTION)All [time] configs accept format supported by vercel/ms.
| ENV variable | Description |
|---|---|
DEBUG | Debug flag (dotenv and server) |
ISSUER | JWT issuer |
EXPIRY | [time] JWT expiry period |
SESSION_TTL | [time] Captcha expiry period |
PUBLIC_KEY_PATH | Path for X.509 RS256 public key |
PRIVATE_KEY_PATH | Path for X.509 RS256 private key |
USERS_PATH | Path for users.json |
Sample RS256 key pair is in sample/, DO NOT use them in production.
RSA key pair creation commands:
openssl req -x509 -sha256 -nodes -days 365 -newkey rsa:2048 \
-keyout jwt_private.pem -out jwt_public.pem
TODO: add Node instructions (with
crypto.generateKeyPairSync())
Sample user_plaintext.json/users.json are in sample/, DO NOT use in production.
Hashed password can be created with:
cd context/app/
./password_hash.js pa$$w0rd # single password
./password_hash.js users_plaintext.json > user.json # hash all `password` fields JSON file
scopefield is added to the claim, it is compatible to Hapi's authorization convention
# local development, configured to load `../../sample/`
cd context/app/
yarn start
# docker staging, using mount
docker run -it --rm --name docker-auth-server -p 8000:8000 \
-v $PWD/sample:/configs \
-v $PWD/context/app:/pwd -w /pwd \
--entrypoint bash \
leesei/auth-server
# docker, using docker secret and config
cd sample/ # or your deployment config
docker secret create jwt_private ./jwt_private.pem
docker secret create users ./users.json
docker config create jwt_public ./jwt_public.pem
docker service create --name docker-auth-server -p 8000:8000 \
--secret source=jwt_private,target=/configs/jwt_private.pem \
--secret source=users,target=/configs/users.json \
--config source=jwt_public,target=/configs/jwt_public.pem \
leesei/auth-server
# getting JWT
http -b POST http://localhost:8000/ username=admin password=admin
http -b POST http://localhost:8000/ username=user password=user
# validating JWT
TOKEN=$(http -b POST http://localhost:8000/ username=admin password=admin)
http -b "http://localhost:8000/verify/$TOKEN"
# validating JWT with captcha enabled
# get and solve captcha at `http://localhost:8000/captcha.html` first
TOKEN=$(http -b POST http://localhost:8000/ username=admin password=admin sessionId=Xe7OiAoluOSLhyVtPD8S9 captcha=ZQJR)
http -b "http://localhost:8000/verify/$TOKEN"
Content type
Image
Digest
sha256:f1e779151…
Size
89.5 MB
Last updated
11 months ago
docker pull leesei/auth-server