A scalable stateless Authorization Service for Federated Identities including Google and Facebook.
10K+
A scalable stateless Authorization Service for Federated Identities including Google and Facebook
Explore documentation with the Ego Read the Docs.
Authorization Service built to provide Single Sign On for various microservices in an application. EGO works with Identity Providers such as Google, Facebook to provide social logins in the application. EGO provides stateless authorization using JWT (JSON Web Tokens) and can scale very well to a large number of users.
Interactive documentation of the API is provided using Swagger UI.
When run locally this can be found at: http://localhost:8081/swagger-ui.html
EGO Architecture
Here are some of the features of EGO:
The application is written in JAVA using Spring Boot and Spring Security Frameworks.
The goal of this quick start is to get a working application quickly up and running.
Set the API_HOST_PORT where ego is to be run, then run docker compose:
API_HOST_PORT=8080 docker-compose up -d
Ego should now be deployed locally with the swagger ui at
http://localhost:8080/swagger-ui.html
Database migrations and versioning is managed by flyway.
Get current version information:
./fly
Run outstanding migrations:
./fly migrate
To see the migration naming convention, click here.
$ mvn clean package
To run from command line with maven:
$ mvn spring-boot:run
ego JWT will have a similar format as the one described in RFC: kf-auth-rfc An example ego JWT is mentioned below:
{
"alg": "HS512"
}
.
{
"sub": "1234567",
"iss": "ego:56fc3842ccf2c1c7ec5c5d14",
"iat": 1459458458,
"exp": 1459487258,
"jti": "56fd919accf2c1c7ec5c5d16",
"aud": [
"service1-id",
"service2-id",
"service3-id"
],
"context": {
"user": {
"name": "[email protected]",
"email": "[email protected]",
"status": "Approved",
"firstName": "Demo",
"lastName": "User",
"createdAt": "2017-11-23 10:24:41",
"lastLogin": "2017-11-23 11:23:58",
"preferredLanguage": null,
"roles": ["ADMIN"],
"groups": ["GroupOne", "GroupTwo"],
"permissions": ["Study001.WRITE", "Study002.DENY"]
}
}
}
.
[signature]
Applications can be added to EGO with a client ID/Secret pair. The ID and Secret can be used to authenticate with EGO to retrieve a JWT.
An application JWT will not have roles but will list the groups the application is associated with. Other applications are responsible for controlling authorization for applications based on the content of their signed JWT.
To register an application with EGO make a request as documented at /swagger-ui.html#!/application-controller/createUsingPOST
This request must have an ADMIN role JWT in the Authorization field.
Keep the client ID/Secret pair in a secret place, for use by the application only. Do not make these values visible in the browser or in your code base.
Authentication uses the oauth client_credentials flow. This can be handled out-of-the-box by many REST clients (ex. Insomnia).
The Authenticate request details, to recreate manually:
POST request to https://{{ego-domain}}/oauth/tokenx-www-form-urlencoded
grant_type:client_credentialsclient_id:{{application's client id}}client_secret:{{application's client secret}}curl example:
http://localhost:8081/oauth/token \
-H 'Content-Type: application/x-www-form-urlencoded' \
-d 'grant_type=client_credentials&client_id=my-app-id&client_secret=secretpassword'
Many thanks to Browserstack for giving our test capabilities a powerup!
Content type
Image
Digest
sha256:7f5f2f1c9…
Size
169.4 MB
Last updated
about 3 years ago
docker pull overture/ego:edge