From a6e4299abd1c3ff56622041daef6c5bf51164891 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Thu, 2 Jun 2022 13:09:03 +0300 Subject: [PATCH 1/7] inital config --- etc/docker/certs/eshop-ssl.conf | 2 +- etc/docker/docker-compose.yml | 5 +-- etc/docker/nginx/conf.d/default.conf | 44 +++++++++++++++++++++++- etc/docker/nginx/conf.d/default.conf_1 | 47 ++++++++++++++++++++++++++ 4 files changed, 94 insertions(+), 4 deletions(-) create mode 100644 etc/docker/nginx/conf.d/default.conf_1 diff --git a/etc/docker/certs/eshop-ssl.conf b/etc/docker/certs/eshop-ssl.conf index e82d4494..e433b42b 100644 --- a/etc/docker/certs/eshop-ssl.conf +++ b/etc/docker/certs/eshop-ssl.conf @@ -28,7 +28,7 @@ DNS.6 = app-publicweb DNS.7 = gateway-web DNS.8 = gateway-web-public DNS.9 = administration-service -DNS.10 = identity-service +DNS.10 = identity-service DNS.11 = catalog-service DNS.12 = basket-service DNS.13 = ordering-service diff --git a/etc/docker/docker-compose.yml b/etc/docker/docker-compose.yml index 10e400cc..86ae293a 100644 --- a/etc/docker/docker-compose.yml +++ b/etc/docker/docker-compose.yml @@ -3,12 +3,13 @@ version: '3.7' services: lb: image: nginx:1.21 + container_name: load-balancer-container ports: - 80:80 - 443:443 volumes: - - ./nginx/certs/app-publicweb+2.pem:/etc/nginx/certs/app-cert.pem:ro - - ./nginx/certs/app-publicweb+2-key.pem:/etc/nginx/certs/app-key.pem:ro + - ./nginx/certs/app-cert.pem:/etc/nginx/certs/app-cert.pem:ro + - ./nginx/certs/app-key.pem:/etc/nginx/certs/app-key.pem:ro - ./nginx/conf.d:/etc/nginx/conf.d:ro networks: - eshoponabp-network diff --git a/etc/docker/nginx/conf.d/default.conf b/etc/docker/nginx/conf.d/default.conf index 4dbfcbf5..5c5a7dbb 100644 --- a/etc/docker/nginx/conf.d/default.conf +++ b/etc/docker/nginx/conf.d/default.conf @@ -8,8 +8,50 @@ server { ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_prefer_server_ciphers on; - location / { + location /administration-service { proxy_pass http://administration-service:80; proxy_set_header Host $host; } + # location /identity-service { + # proxy_pass http://identity-service:80; + # proxy_set_header Host $host; + # } + # location /catalog-service { + # proxy_pass http://catalog-service:80; + # proxy_set_header Host $host; + # } + # location /basket-service { + # proxy_pass http://basket-service:80; + # proxy_set_header Host $host; + # } + # location /ordering-service { + # proxy_pass http://ordering-service:80; + # proxy_set_header Host $host; + # } + # location /payment-service { + # proxy_pass http://payment-service:80; + # proxy_set_header Host $host; + # } + + # location /app-web { + # proxy_pass http://app-web:80; + # proxy_set_header Host $host; + # } + # location /app-publicweb { + # proxy_pass http://app-publicweb:80; + # proxy_set_header Host $host; + # } + # location /app-authserver { + # proxy_pass http://app-authserver:80; + # proxy_set_header Host $host; + # } + + # location /gateway-web { + # proxy_pass http://gateway-web:80; + # proxy_set_header Host $host; + # } + # location /gateway-web-public { + # proxy_pass http://gateway-web-public:80; + # proxy_set_header Host $host; + # } } diff --git a/etc/docker/nginx/conf.d/default.conf_1 b/etc/docker/nginx/conf.d/default.conf_1 new file mode 100644 index 00000000..2970ffb9 --- /dev/null +++ b/etc/docker/nginx/conf.d/default.conf_1 @@ -0,0 +1,47 @@ +server { + listen 80; + listen 443 ssl; + server_name administration-service; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://administration-service:80; + proxy_set_header Host $host; + } +} + +server { + listen 80; + listen 443 ssl; + server_name identity-service; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://identity-service:80; + proxy_set_header Host $host; + } +} + +server { + listen 80; + listen 443 ssl; + server_name catalog-service; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://catalog-service:80; + proxy_set_header Host $host; + } +} \ No newline at end of file From 4c0a680441a412f2e7d9ef63000003879a08924a Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Thu, 2 Jun 2022 17:20:49 +0300 Subject: [PATCH 2/7] added administration, authserver and identity configurations --- etc/docker/docker-compose.yml | 89 +++++++++++++++++----------- etc/docker/nginx/conf.d/default.conf | 78 +++++++++++------------- 2 files changed, 87 insertions(+), 80 deletions(-) diff --git a/etc/docker/docker-compose.yml b/etc/docker/docker-compose.yml index 86ae293a..94f250c2 100644 --- a/etc/docker/docker-compose.yml +++ b/etc/docker/docker-compose.yml @@ -8,28 +8,37 @@ services: - 80:80 - 443:443 volumes: - - ./nginx/certs/app-cert.pem:/etc/nginx/certs/app-cert.pem:ro - - ./nginx/certs/app-key.pem:/etc/nginx/certs/app-key.pem:ro + - ./nginx/certs/eshop-st-web+10.pem:/etc/nginx/certs/eshop-st-web+10.pem:ro + - ./nginx/certs/eshop-st-web+10-key.pem:/etc/nginx/certs/eshop-st-web+10-key.pem:ro - ./nginx/conf.d:/etc/nginx/conf.d:ro + depends_on: + - eshop-st-administration + - eshop-st-authserver + - eshop-st-identity networks: - eshoponabp-network - administration-service: + eshop-st-administration: image: eshoponabp/service-administration:latest container_name: administration-service-container build: context: ../../ dockerfile: services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker + # - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=http://+:80 - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - # - Redis__Configuration=redis - # - RabbitMQ__Connections__Default__HostName=rabbitmq - # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - # ports: - # - "44353:443" + - App__SelfUrl=https://eshop-st-administration + - App__CorsOrigins=https://gateway-web,gateway-web-public + - RemoteServices__AbpIdentity__BaseUrl=eshop-st-identity + - RemoteServices__AbpIdentity__UseCurrentAccessToken=false + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false + - IdentityClients__Default__Authority=http://eshop-st-identity + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq + # - AuthServer__SwaggerClientId=WebGateway_Swagger + # - AuthServer__SwaggerClientSecret=1q2w3e* depends_on: redis: condition: service_healthy @@ -42,23 +51,36 @@ services: - eshoponabp-network # volumes: # - ./certs:/root/certificate - identity-service: + eshop-st-identity: image: eshoponabp/service-identity:latest container_name: identity-service-container build: context: ../../ dockerfile: services/identity/src/EShopOnAbp.IdentityService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker + # - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=http://+:80 - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - App__SelfUrl=https://eshop-st-identity + - App__CorsOrigins=https://gateway-web,gateway-web-public + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false + - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq - - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; - - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - # ports: - # - "44351:443" + # - AuthServer__SwaggerClientId=WebGateway_Swagger + # - AuthServer__SwaggerClientSecret=1q2w3e* + - IdentityServerClients__Web__RootUrl=http://localhost:4200 + - IdentityServerClients__PublicWeb__RootUrl=https://localhost:44335 + - IdentityServerClients__WebGateway__RootUrl=https://localhost:44372 + - IdentityServerClients__PublicWebGateway__RootUrl=https://localhost:44373 + - IdentityServerClients__IdentityService__RootUrl=https://eshop-st-identity + - IdentityServerClients__AdministrationService__RootUrl=https://eshop-st-administration + - IdentityServerClients__AccountService__RootUrl=https://eshop-st-authserver + - IdentityServerClients__CatalogService__RootUrl=https://localhost:44354 + - IdentityServerClients__BasketService__RootUrl=https://localhost:44355 + - IdentityServerClients__OrderingService__RootUrl=https://localhost:44356 + - IdentityServerClients__PaymentService__RootUrl=https://localhost:44357 depends_on: redis: condition: service_healthy @@ -217,29 +239,26 @@ services: - eshoponabp-network # volumes: # - ./certs:/root/certificate - app-authserver: + eshop-st-authserver: image: eshoponabp/app-authserver:latest container_name: app-authserver-container build: context: ../../ dockerfile: apps/auth-server/src/EShopOnAbp.AuthServer/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker - - ASPNETCORE_URLS=https://+:443;http://+:80; - - ASPNETCORE_HTTPS_PORT=44330 - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - # - Redis__Configuration=redis - # - RabbitMQ__Connections__Default__HostName=rabbitmq - # - App__SelfUrl=https://app-authserver - # - App__CorsOrigins=http://app-web,https://identity-service,https://administration-service,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service + # - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=http://+:80; + - App__SelfUrl=https://eshop-st-authserver + - App__CorsOrigins=http://app-web,https://identity-service,https://eshop-st-administration,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service # - App__RedirectAllowedUrls=http://app-web - - AuthServer__Authority=https://app-authserver - - AuthServer__RequireHttpsMetadata=true - # - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; - # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - # ports: - # - "44330:443" + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false + - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq + # - AuthServer__SwaggerClientId=WebGateway_Swagger + # - AuthServer__SwaggerClientSecret=1q2w3e* depends_on: redis: condition: service_healthy diff --git a/etc/docker/nginx/conf.d/default.conf b/etc/docker/nginx/conf.d/default.conf index 5c5a7dbb..6cb0eb49 100644 --- a/etc/docker/nginx/conf.d/default.conf +++ b/etc/docker/nginx/conf.d/default.conf @@ -1,57 +1,45 @@ server { listen 80; listen 443 ssl; - server_name administration-service; + server_name eshop-st-administration; - ssl_certificate /etc/nginx/certs/app-cert.pem; - ssl_certificate_key /etc/nginx/certs/app-key.pem; + ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; + ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_prefer_server_ciphers on; - location /administration-service { - proxy_pass http://administration-service:80; + location / { + proxy_pass http://eshop-st-administration:80; proxy_set_header Host $host; } - # location /identity-service { - # proxy_pass http://identity-service:80; - # proxy_set_header Host $host; - # } - # location /catalog-service { - # proxy_pass http://catalog-service:80; - # proxy_set_header Host $host; - # } - # location /basket-service { - # proxy_pass http://basket-service:80; - # proxy_set_header Host $host; - # } - # location /ordering-service { - # proxy_pass http://ordering-service:80; - # proxy_set_header Host $host; - # } - # location /payment-service { - # proxy_pass http://payment-service:80; - # proxy_set_header Host $host; - # } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-identity; - # location /app-web { - # proxy_pass http://app-web:80; - # proxy_set_header Host $host; - # } - # location /app-publicweb { - # proxy_pass http://app-publicweb:80; - # proxy_set_header Host $host; - # } - # location /app-authserver { - # proxy_pass http://app-authserver:80; - # proxy_set_header Host $host; - # } + ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; + ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; - # location /gateway-web { - # proxy_pass http://gateway-web:80; - # proxy_set_header Host $host; - # } - # location /gateway-web-public { - # proxy_pass http://gateway-web-public:80; - # proxy_set_header Host $host; - # } + location / { + proxy_pass http://eshop-st-identity:80; + proxy_set_header Host $host; + } } +server { + listen 80; + listen 443 ssl; + server_name eshop-st-authserver; + + ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; + ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-authserver:80; + proxy_set_header Host $host; + } +} \ No newline at end of file From 6c1ff3628c2ad18a46794b9f8c59c7c1c02c1a42 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Thu, 2 Jun 2022 19:08:49 +0300 Subject: [PATCH 3/7] added basket, catalog, public web and publicweb gateway --- etc/docker/docker-compose.yml | 115 +++++++++++++-------------- etc/docker/nginx/conf.d/default.conf | 64 +++++++++++++++ 2 files changed, 118 insertions(+), 61 deletions(-) diff --git a/etc/docker/docker-compose.yml b/etc/docker/docker-compose.yml index 94f250c2..85808628 100644 --- a/etc/docker/docker-compose.yml +++ b/etc/docker/docker-compose.yml @@ -15,6 +15,10 @@ services: - eshop-st-administration - eshop-st-authserver - eshop-st-identity + - eshop-st-basket + - eshop-st-catalog + - eshop-st-public-web + - eshop-st-gateway-web-public networks: - eshoponabp-network @@ -71,9 +75,9 @@ services: # - AuthServer__SwaggerClientId=WebGateway_Swagger # - AuthServer__SwaggerClientSecret=1q2w3e* - IdentityServerClients__Web__RootUrl=http://localhost:4200 - - IdentityServerClients__PublicWeb__RootUrl=https://localhost:44335 + - IdentityServerClients__PublicWeb__RootUrl=https://eshop-st-public-web - IdentityServerClients__WebGateway__RootUrl=https://localhost:44372 - - IdentityServerClients__PublicWebGateway__RootUrl=https://localhost:44373 + - IdentityServerClients__PublicWebGateway__RootUrl=https://eshop-st-gateway-web-public - IdentityServerClients__IdentityService__RootUrl=https://eshop-st-identity - IdentityServerClients__AdministrationService__RootUrl=https://eshop-st-administration - IdentityServerClients__AccountService__RootUrl=https://eshop-st-authserver @@ -93,28 +97,26 @@ services: - eshoponabp-network # volumes: # - ./certs:/root/certificate - catalog-service: + eshop-st-catalog: image: eshoponabp/service-catalog:latest container_name: catalog-service-container build: context: ../../ dockerfile: services/catalog/src/EShopOnAbp.CatalogService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker - - ASPNETCORE_URLS=https://+:443;http://+:80;http://+:81; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + # - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=http://+:80;http://+:81; + - App__SelfUrl=https://eshop-st-catalog + - App__CorsOrigins=https://eshop-st-gateway-web,https://eshop-st-gateway-web-public,https://eshop-st-public-web,https://eshop-st-web + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false - Kestrel__EndPoints__Http__Url=http://docker.host.internal:80 - - Kestrel__EndPoints__Https__Url=https://docker.host.internal:443 - Kestrel__EndPoints__gRPC__Url=http://docker.host.internal:81 - # - Redis__Configuration=redis - # - RabbitMQ__Connections__Default__HostName=rabbitmq - # - ConnectionStrings__CatalogService=mongodb://mongodb/EShopOnAbp_Catalog - # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - # ports: - # - "44354:443" - # - "5000:80" - # - "81:81" + - Kestrel__EndPoints__gRPC__Protocols=Http2 + - ConnectionStrings__CatalogService=mongodb://mongodb/EShopOnAbp_Catalog + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq depends_on: redis: condition: service_healthy @@ -127,24 +129,24 @@ services: - eshoponabp-network # volumes: # - ./certs:/root/certificate - basket-service: + eshop-st-basket: image: eshoponabp/service-basket:latest container_name: basket-service-container build: context: ../../ dockerfile: services/basket/src/EShopOnAbp.BasketService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker - - ASPNETCORE_URLS=https://+:443;http://+:80; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - # - Redis__Configuration=redis - # - RabbitMQ__Connections__Default__HostName=rabbitmq - # - RemoteServices__Catalog__BaseUrl=https://catalog-service - # - RemoteServices__Catalog__GrpcUrl=http://catalog-service - # - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - # ports: - # - "44355:443" + # - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=http://+:80 + - App__SelfUrl=https://eshop-st-basket + - App__CorsOrigins=https://eshop-st-gateway-web,https://eshop-st-gateway-web-public,https://eshop-st-public-web + - RemoteServices__Catalog__BaseUrl=http://eshop-st-catalog:80 + - RemoteServices__Catalog__GrpcUrl=http://eshop-st-catalog:81 + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq depends_on: redis: condition: service_healthy @@ -249,7 +251,7 @@ services: # - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=http://+:80; - App__SelfUrl=https://eshop-st-authserver - - App__CorsOrigins=http://app-web,https://identity-service,https://eshop-st-administration,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service + - App__CorsOrigins=http://app-web,https://eshop-st-public-web,https://identity-service,http://eshop-st-administration,https://eshop-st-administration,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service # - App__RedirectAllowedUrls=http://app-web - AuthServer__Authority=http://eshop-st-authserver - AuthServer__RequireHttpsMetadata=false @@ -271,26 +273,22 @@ services: - eshoponabp-network # volumes: # - ./certs:/root/certificate - app-publicweb: + eshop-st-public-web: image: eshoponabp/app-publicweb:latest container_name: app-publicweb-container build: context: ../../ dockerfile: apps/public-web/src/EShopOnAbp.PublicWeb/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker - - ASPNETCORE_URLS=https://+:443;http://+:80; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - # - Redis__Configuration=redis - # - RabbitMQ__Connections__Default__HostName=rabbitmq - # - App__SelfUrl=https://app-publicweb - - AuthServer__Authority=https://app-authserver - - AuthServer__RequireHttpsMetadata=true - # - RemoteServices__Default__BaseUrl=http://gateway-web-public - # - ReverseProxy__Clusters__cluster1__Destinations__destination1__Address=http://gateway-web-public - # ports: - # - "44335:443" + # - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=http://+:80; + - App__SelfUrl=https://eshop-st-public-web + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false + - RemoteServices__Default__BaseUrl=http://eshop-st-gateway-web-public/ + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq + - ReverseProxy__Clusters__cluster1__Destinations__destination1__Address=http://eshop-st-gateway-web-public depends_on: redis: condition: service_healthy @@ -299,8 +297,6 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate gateway-web: image: eshoponabp/gateway-web:latest container_name: gateway-web-container @@ -333,27 +329,26 @@ services: - eshoponabp-network # volumes: # - ./certs:/root/certificate - gateway-web-public: + eshop-st-gateway-web-public: image: eshoponabp/gateway-web-public:latest container_name: gateway-web-public-container build: context: ../../ dockerfile: gateways/web-public/src/EShopOnAbp.WebPublicGateway/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden - - ASPNETCORE_URLS=https://+:443;http://+:80; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + # - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden + - ASPNETCORE_URLS=http://+:80; + - App__SelfUrl=https://eshop-st-gateway-web-public + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false - Redis__Configuration=redis - - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://app-authserver - - ReverseProxy__Clusters__administrationCluster__Destinations__destination1__Address=http://administration-service - - ReverseProxy__Clusters__catalogCluster__Destinations__destination1__Address=http://catalog-service - - ReverseProxy__Clusters__basketCluster__Destinations__destination1__Address=http://basket-service - - ReverseProxy__Clusters__orderingCluster__Destinations__destination1__Address=http://ordering-service - - ReverseProxy__Clusters__paymentCluster__Destinations__destination1__Address=http://payment-service - - ReverseProxy__Clusters__productPictureCluster__Destinations__destination1__Address=http://catalog-service - # ports: - # - "44373:443" + - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://eshop-st-authserver + - ReverseProxy__Clusters__administrationCluster__Destinations__destination1__Address=http://eshop-st-administration + - ReverseProxy__Clusters__catalogCluster__Destinations__destination1__Address=http://eshop-st-catalog + - ReverseProxy__Clusters__basketCluster__Destinations__destination1__Address=http://eshop-st-basket + - ReverseProxy__Clusters__orderingCluster__Destinations__destination1__Address=http://eshop-st-ordering + - ReverseProxy__Clusters__paymentCluster__Destinations__destination1__Address=http://eshop-st-payment + - ReverseProxy__Clusters__productPictureCluster__Destinations__destination1__Address=http://eshop-st-catalog depends_on: redis: condition: service_healthy @@ -362,8 +357,6 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate networks: eshoponabp-network: diff --git a/etc/docker/nginx/conf.d/default.conf b/etc/docker/nginx/conf.d/default.conf index 6cb0eb49..c294cc10 100644 --- a/etc/docker/nginx/conf.d/default.conf +++ b/etc/docker/nginx/conf.d/default.conf @@ -42,4 +42,68 @@ server { proxy_pass http://eshop-st-authserver:80; proxy_set_header Host $host; } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-public-web; + + ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; + ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-public-web:80; + proxy_set_header Host $host; + + proxy_buffer_size 128k; + proxy_buffers 4 256k; + proxy_busy_buffers_size 256k; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-gateway-web-public; + + ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; + ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-gateway-web-public:80; + proxy_set_header Host $host; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-basket; + + ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; + ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-basket:80; + proxy_set_header Host $host; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-catalog; + + ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; + ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-catalog:80; + proxy_set_header Host $host; + } } \ No newline at end of file From 6c3b91997a862d10ba671d30612380257fcffea2 Mon Sep 17 00:00:00 2001 From: Enis Necipoglu Date: Fri, 3 Jun 2022 09:00:46 +0300 Subject: [PATCH 4/7] Add SameSiteCookiePolicy to authserver --- .../EShopOnAbpAuthServerModule.cs | 6 ++ ...eSiteCookiesServiceCollectionExtensions.cs | 70 +++++++++++++++++++ 2 files changed, 76 insertions(+) create mode 100644 apps/auth-server/src/EShopOnAbp.AuthServer/SameSiteCookiesServiceCollectionExtensions.cs diff --git a/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs b/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs index 8b57f016..05c20b0d 100644 --- a/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs +++ b/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs @@ -148,6 +148,11 @@ public class EShopOnAbpAuthServerModule : AbpModule } } + private void ConfigureSameSiteCookiePolicy(ServiceConfigurationContext context) + { + context.Services.AddSameSiteCookiePolicy(); + } + public override void OnApplicationInitialization(ApplicationInitializationContext context) { var app = context.GetApplicationBuilder(); @@ -181,6 +186,7 @@ public class EShopOnAbpAuthServerModule : AbpModule app.UseStaticFiles(); app.UseRouting(); app.UseCors(); + app.UseCookiePolicy(); app.UseAuthentication(); app.UseJwtTokenMiddleware(); app.UseAbpSerilogEnrichers(); diff --git a/apps/auth-server/src/EShopOnAbp.AuthServer/SameSiteCookiesServiceCollectionExtensions.cs b/apps/auth-server/src/EShopOnAbp.AuthServer/SameSiteCookiesServiceCollectionExtensions.cs new file mode 100644 index 00000000..f888c976 --- /dev/null +++ b/apps/auth-server/src/EShopOnAbp.AuthServer/SameSiteCookiesServiceCollectionExtensions.cs @@ -0,0 +1,70 @@ +using Microsoft.AspNetCore.Builder; +using Microsoft.AspNetCore.Http; + +namespace Microsoft.Extensions.DependencyInjection +{ + public static class SameSiteCookiesServiceCollectionExtensions + { + public static IServiceCollection AddSameSiteCookiePolicy(this IServiceCollection services) + { + services.Configure(options => + { + options.MinimumSameSitePolicy = SameSiteMode.Unspecified; + options.OnAppendCookie = cookieContext => + CheckSameSite(cookieContext.Context, cookieContext.CookieOptions); + options.OnDeleteCookie = cookieContext => + CheckSameSite(cookieContext.Context, cookieContext.CookieOptions); + }); + + return services; + } + + private static void CheckSameSite(HttpContext httpContext, CookieOptions options) + { + if (options.SameSite == SameSiteMode.None) + { + var userAgent = httpContext.Request.Headers["User-Agent"].ToString(); + if (!httpContext.Request.IsHttps || DisallowsSameSiteNone(userAgent)) + { + // For .NET Core < 3.1 set SameSite = (SameSiteMode)(-1) + options.SameSite = SameSiteMode.Unspecified; + } + } + } + + private static bool DisallowsSameSiteNone(string userAgent) + { + // Cover all iOS based browsers here. This includes: + // - Safari on iOS 12 for iPhone, iPod Touch, iPad + // - WkWebview on iOS 12 for iPhone, iPod Touch, iPad + // - Chrome on iOS 12 for iPhone, iPod Touch, iPad + // All of which are broken by SameSite=None, because they use the iOS networking stack + if (userAgent.Contains("CPU iPhone OS 12") || userAgent.Contains("iPad; CPU OS 12")) + { + return true; + } + + // Cover Mac OS X based browsers that use the Mac OS networking stack. This includes: + // - Safari on Mac OS X. + // This does not include: + // - Chrome on Mac OS X + // Because they do not use the Mac OS networking stack. + if (userAgent.Contains("Macintosh; Intel Mac OS X 10_14") && + userAgent.Contains("Version/") && userAgent.Contains("Safari")) + { + return true; + } + + // Cover Chrome 50-69, because some versions are broken by SameSite=None, + // and none in this range require it. + // Note: this covers some pre-Chromium Edge versions, + // but pre-Chromium Edge does not require SameSite=None. + if (userAgent.Contains("Chrome/5") || userAgent.Contains("Chrome/6")) + { + return true; + } + + return false; + } + } +} \ No newline at end of file From dc2a25fe7c8b5e8e2c9de7edd6b306706f3f502c Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Fri, 3 Jun 2022 15:57:06 +0300 Subject: [PATCH 5/7] added app support with web gateway also renamed cert name --- etc/docker/docker-compose.yml | 133 +++++++++++-------------- etc/docker/nginx/conf.d/default.conf | 101 +++++++++++++++---- etc/docker/nginx/conf.d/default.conf_1 | 47 --------- etc/docker/nginx/dynamic-env.json | 21 ++++ 4 files changed, 161 insertions(+), 141 deletions(-) delete mode 100644 etc/docker/nginx/conf.d/default.conf_1 create mode 100644 etc/docker/nginx/dynamic-env.json diff --git a/etc/docker/docker-compose.yml b/etc/docker/docker-compose.yml index 85808628..9b4aa284 100644 --- a/etc/docker/docker-compose.yml +++ b/etc/docker/docker-compose.yml @@ -8,8 +8,8 @@ services: - 80:80 - 443:443 volumes: - - ./nginx/certs/eshop-st-web+10.pem:/etc/nginx/certs/eshop-st-web+10.pem:ro - - ./nginx/certs/eshop-st-web+10-key.pem:/etc/nginx/certs/eshop-st-web+10-key.pem:ro + - ./nginx/certs/eshop-st-web+10.pem:/etc/nginx/certs/app-cert.pem:ro + - ./nginx/certs/eshop-st-web+10-key.pem:/etc/nginx/certs/app-cert-key.pem:ro - ./nginx/conf.d:/etc/nginx/conf.d:ro depends_on: - eshop-st-administration @@ -17,8 +17,12 @@ services: - eshop-st-identity - eshop-st-basket - eshop-st-catalog + - eshop-st-ordering + - eshop-st-payment + - eshop-st-web - eshop-st-public-web - eshop-st-gateway-web-public + - eshop-st-gateway-web networks: - eshoponabp-network @@ -41,8 +45,6 @@ services: - IdentityClients__Default__Authority=http://eshop-st-identity - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq - # - AuthServer__SwaggerClientId=WebGateway_Swagger - # - AuthServer__SwaggerClientSecret=1q2w3e* depends_on: redis: condition: service_healthy @@ -53,8 +55,6 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate eshop-st-identity: image: eshoponabp/service-identity:latest container_name: identity-service-container @@ -72,8 +72,6 @@ services: - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq - # - AuthServer__SwaggerClientId=WebGateway_Swagger - # - AuthServer__SwaggerClientSecret=1q2w3e* - IdentityServerClients__Web__RootUrl=http://localhost:4200 - IdentityServerClients__PublicWeb__RootUrl=https://eshop-st-public-web - IdentityServerClients__WebGateway__RootUrl=https://localhost:44372 @@ -95,8 +93,6 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate eshop-st-catalog: image: eshoponabp/service-catalog:latest container_name: catalog-service-container @@ -127,8 +123,6 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate eshop-st-basket: image: eshoponabp/service-basket:latest container_name: basket-service-container @@ -157,25 +151,23 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate - ordering-service: + eshop-st-ordering: image: eshoponabp/service-ordering:latest container_name: ordering-service-container build: context: ../../ dockerfile: services/ordering/src/EShopOnAbp.OrderingService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker - - ASPNETCORE_URLS=https://+:443;http://+:80; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + # - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=http://+:80; + - App__SelfUrl=https://eshop-st-ordering + - App__CorsOrigins=https://eshop-st-gateway-web,https://eshop-st-gateway-web-public,https://eshop-st-web + - ConnectionStrings__OrderingService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Ordering;Pooling=false; + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq - - ConnectionStrings__OrderingService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Ordering;Pooling=false; - - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - # ports: - # - "44356:443" depends_on: redis: condition: service_healthy @@ -188,26 +180,26 @@ services: - eshoponabp-network # volumes: # - ./certs:/root/certificate - payment-service: + eshop-st-payment: image: eshoponabp/service-payment:latest container_name: payment-service-container build: context: ../../ dockerfile: services/payment/src/EShopOnAbp.PaymentService.HttpApi.Host/Dockerfile environment: - - ASPNETCORE_ENVIRONMENT=Docker - - ASPNETCORE_URLS=https://+:443;http://+:80; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 - - Redis__Configuration=redis - - RabbitMQ__Connections__Default__HostName=rabbitmq + # - ASPNETCORE_ENVIRONMENT=Docker + - ASPNETCORE_URLS=http://+:80; + - App__SelfUrl=https://eshop-st-payment + - App__CorsOrigins=https://eshop-st-gateway-web,https://eshop-st-gateway-web-public - ConnectionStrings__PaymentService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Payment;Pooling=false; - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false + - Redis__Configuration=redis + - RabbitMQ__Connections__Default__HostName=rabbitmq - Payment__PayPal__ClientId=PAYPAL_CLIENT_ID - Payment__PayPal__Secret=PAYPAL_SECRET - Payment__PayPal__Environment=Sandbox - # ports: - # - "44357:443" depends_on: redis: condition: service_healthy @@ -218,29 +210,6 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate - app-web: - image: eshoponabp/app-web:latest - container_name: app-web-container - build: - context: ../../ - dockerfile: apps/angular/Dockerfile - environment: - - RabbitMQ__Connections__Default__HostName=rabbitmq - - RemoteServices__Default__BaseUrl=http://gateway-web-public - # ports: - # - "4200:80" - depends_on: - redis: - condition: service_healthy - rabbitmq: - condition: service_healthy - restart: on-failure - networks: - - eshoponabp-network - # volumes: - # - ./certs:/root/certificate eshop-st-authserver: image: eshoponabp/app-authserver:latest container_name: app-authserver-container @@ -251,16 +220,14 @@ services: # - ASPNETCORE_ENVIRONMENT=Docker - ASPNETCORE_URLS=http://+:80; - App__SelfUrl=https://eshop-st-authserver - - App__CorsOrigins=http://app-web,https://eshop-st-public-web,https://identity-service,http://eshop-st-administration,https://eshop-st-administration,https://catalog-service,https://basket-service,https://ordering-service,https://payment-service - # - App__RedirectAllowedUrls=http://app-web + - App__CorsOrigins=https://eshop-st-web,https://eshop-st-public-web,https://eshop-st-identity,http://eshop-st-administration,https://eshop-st-administration,https://eshop-st-catalog,https://eshop-st-basket,https://eshop-st-ordering,https://eshop-st-payment + - App__RedirectAllowedUrls=http://eshop-st-web - AuthServer__Authority=http://eshop-st-authserver - AuthServer__RequireHttpsMetadata=false - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - Redis__Configuration=redis - - RabbitMQ__Connections__Default__HostName=rabbitmq - # - AuthServer__SwaggerClientId=WebGateway_Swagger - # - AuthServer__SwaggerClientSecret=1q2w3e* + - RabbitMQ__Connections__Default__HostName=rabbitmq depends_on: redis: condition: service_healthy @@ -271,8 +238,22 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate + eshop-st-web: + image: eshoponabp/app-web:latest + container_name: app-web-container + build: + context: ../../ + dockerfile: apps/angular/Dockerfile + volumes: + - ./nginx/dynamic-env.json://usr/share/nginx/html/dynamic-env.json + depends_on: + redis: + condition: service_healthy + rabbitmq: + condition: service_healthy + restart: on-failure + networks: + - eshoponabp-network eshop-st-public-web: image: eshoponabp/app-publicweb:latest container_name: app-publicweb-container @@ -297,7 +278,7 @@ services: restart: on-failure networks: - eshoponabp-network - gateway-web: + eshop-st-gateway-web: image: eshoponabp/gateway-web:latest container_name: gateway-web-container build: @@ -305,18 +286,20 @@ services: dockerfile: gateways/web/src/EShopOnAbp.WebGateway/Dockerfile environment: - ASPNETCORE_ENVIRONMENT=Docker # Yarp can't resolve dns, needs to be overridden - - ASPNETCORE_URLS=https://+:443;http://+:80; - # - Kestrel__Certificates__Default__Path=/root/certificate/eshop-dk.pfx - # - Kestrel__Certificates__Default__Password=8b6039b6-c67a-448b-977b-0ce6d3fcfd49 + - ASPNETCORE_URLS=http://+:80; + - App__SelfUrl=https://eshop-st-gateway-web + - App__CorsOrigins=https://eshop-st-web + - AuthServer__Authority=http://eshop-st-authserver + - AuthServer__RequireHttpsMetadata=false - Redis__Configuration=redis - - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://app-authserver - - ReverseProxy__Clusters__identityCluster__Destinations__destination1__Address=http://identity-service - - ReverseProxy__Clusters__administrationCluster__Destinations__destination1__Address=http://administration-service - - ReverseProxy__Clusters__catalogCluster__Destinations__destination1__Address=http://catalog-service - - ReverseProxy__Clusters__orderingCluster__Destinations__destination1__Address=http://ordering-service - - ReverseProxy__Clusters__feature-management-cluster__Destinations__destination1__Address=http://administration-service - - ReverseProxy__Clusters__permission-management-cluster__Destinations__destination1__Address=http://administration-service - - ReverseProxy__Clusters__setting-management-cluster__Destinations__destination1__Address=http://administration-service + - ReverseProxy__Clusters__accountCluster__Destinations__destination1__Address=http://eshop-st-authserver + - ReverseProxy__Clusters__identityCluster__Destinations__destination1__Address=http://eshop-st-identity + - ReverseProxy__Clusters__administrationCluster__Destinations__destination1__Address=http://eshop-st-administration + - ReverseProxy__Clusters__catalogCluster__Destinations__destination1__Address=http://eshop-st-catalog + - ReverseProxy__Clusters__orderingCluster__Destinations__destination1__Address=http://eshop-st-ordering + - ReverseProxy__Clusters__feature-management-cluster__Destinations__destination1__Address=http://eshop-st-administration + - ReverseProxy__Clusters__permission-management-cluster__Destinations__destination1__Address=http://eshop-st-administration + - ReverseProxy__Clusters__setting-management-cluster__Destinations__destination1__Address=http://eshop-st-administration # ports: # - "44372:443" depends_on: @@ -327,8 +310,6 @@ services: restart: on-failure networks: - eshoponabp-network - # volumes: - # - ./certs:/root/certificate eshop-st-gateway-web-public: image: eshoponabp/gateway-web-public:latest container_name: gateway-web-public-container diff --git a/etc/docker/nginx/conf.d/default.conf b/etc/docker/nginx/conf.d/default.conf index c294cc10..60df3f24 100644 --- a/etc/docker/nginx/conf.d/default.conf +++ b/etc/docker/nginx/conf.d/default.conf @@ -3,8 +3,8 @@ server { listen 443 ssl; server_name eshop-st-administration; - ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; - ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_prefer_server_ciphers on; @@ -18,8 +18,8 @@ server { listen 443 ssl; server_name eshop-st-identity; - ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; - ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_prefer_server_ciphers on; @@ -33,28 +33,29 @@ server { listen 443 ssl; server_name eshop-st-authserver; - ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; - ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_prefer_server_ciphers on; location / { proxy_pass http://eshop-st-authserver:80; proxy_set_header Host $host; + add_header from-ingress true; } } server { listen 80; listen 443 ssl; - server_name eshop-st-public-web; + server_name eshop-st-web; - ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; - ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_prefer_server_ciphers on; location / { - proxy_pass http://eshop-st-public-web:80; + proxy_pass http://eshop-st-web:80; proxy_set_header Host $host; proxy_buffer_size 128k; @@ -65,16 +66,20 @@ server { server { listen 80; listen 443 ssl; - server_name eshop-st-gateway-web-public; + server_name eshop-st-public-web; - ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; - ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_prefer_server_ciphers on; location / { - proxy_pass http://eshop-st-gateway-web-public:80; + proxy_pass http://eshop-st-public-web:80; proxy_set_header Host $host; + + proxy_buffer_size 128k; + proxy_buffers 4 256k; + proxy_busy_buffers_size 256k; } } server { @@ -82,8 +87,8 @@ server { listen 443 ssl; server_name eshop-st-basket; - ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; - ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_prefer_server_ciphers on; @@ -97,8 +102,8 @@ server { listen 443 ssl; server_name eshop-st-catalog; - ssl_certificate /etc/nginx/certs/eshop-st-web+10.pem; - ssl_certificate_key /etc/nginx/certs/eshop-st-web+10-key.pem; + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; ssl_protocols TLSv1 TLSv1.1 TLSv1.2; ssl_prefer_server_ciphers on; @@ -106,4 +111,64 @@ server { proxy_pass http://eshop-st-catalog:80; proxy_set_header Host $host; } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-ordering; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-ordering:80; + proxy_set_header Host $host; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-payment; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-payment:80; + proxy_set_header Host $host; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-gateway-web-public; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-gateway-web-public:80; + proxy_set_header Host $host; + } +} +server { + listen 80; + listen 443 ssl; + server_name eshop-st-gateway-web; + + ssl_certificate /etc/nginx/certs/app-cert.pem; + ssl_certificate_key /etc/nginx/certs/app-cert-key.pem; + ssl_protocols TLSv1 TLSv1.1 TLSv1.2; + ssl_prefer_server_ciphers on; + + location / { + proxy_pass http://eshop-st-gateway-web:80; + proxy_set_header Host $host; + } } \ No newline at end of file diff --git a/etc/docker/nginx/conf.d/default.conf_1 b/etc/docker/nginx/conf.d/default.conf_1 deleted file mode 100644 index 2970ffb9..00000000 --- a/etc/docker/nginx/conf.d/default.conf_1 +++ /dev/null @@ -1,47 +0,0 @@ -server { - listen 80; - listen 443 ssl; - server_name administration-service; - - ssl_certificate /etc/nginx/certs/app-cert.pem; - ssl_certificate_key /etc/nginx/certs/app-key.pem; - ssl_protocols TLSv1 TLSv1.1 TLSv1.2; - ssl_prefer_server_ciphers on; - - location / { - proxy_pass http://administration-service:80; - proxy_set_header Host $host; - } -} - -server { - listen 80; - listen 443 ssl; - server_name identity-service; - - ssl_certificate /etc/nginx/certs/app-cert.pem; - ssl_certificate_key /etc/nginx/certs/app-key.pem; - ssl_protocols TLSv1 TLSv1.1 TLSv1.2; - ssl_prefer_server_ciphers on; - - location / { - proxy_pass http://identity-service:80; - proxy_set_header Host $host; - } -} - -server { - listen 80; - listen 443 ssl; - server_name catalog-service; - - ssl_certificate /etc/nginx/certs/app-cert.pem; - ssl_certificate_key /etc/nginx/certs/app-key.pem; - ssl_protocols TLSv1 TLSv1.1 TLSv1.2; - ssl_prefer_server_ciphers on; - - location / { - proxy_pass http://catalog-service:80; - proxy_set_header Host $host; - } -} \ No newline at end of file diff --git a/etc/docker/nginx/dynamic-env.json b/etc/docker/nginx/dynamic-env.json new file mode 100644 index 00000000..fd380d32 --- /dev/null +++ b/etc/docker/nginx/dynamic-env.json @@ -0,0 +1,21 @@ +{ + "production": true, + "application": { + "baseUrl":"https://eshop-st-web", + "name": "EShopOnAbp", + "logoUrl": "" + }, + "oAuthConfig": { + "issuer": "https://eshop-st-authserver", + "redirectUri": "https://eshop-st-web", + "clientId": "Web", + "responseType": "password", + "scope": "offline_access openid profile email phone AccountService IdentityService AdministrationService CatalogService OrderingService" + }, + "apis": { + "default": { + "url": "https://eshop-st-gateway-web", + "rootNamespace": "EShopOnAbp" + } + } +} \ No newline at end of file From 293490d32a326d1135566e3ac2f48ebaa145f8f9 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Mon, 6 Jun 2022 14:35:42 +0300 Subject: [PATCH 6/7] updated angular oidc configuration --- etc/docker/docker-compose.yml | 6 +++--- etc/docker/nginx/dynamic-env.json | 7 +++++-- 2 files changed, 8 insertions(+), 5 deletions(-) diff --git a/etc/docker/docker-compose.yml b/etc/docker/docker-compose.yml index 9b4aa284..769b0e49 100644 --- a/etc/docker/docker-compose.yml +++ b/etc/docker/docker-compose.yml @@ -69,10 +69,10 @@ services: - AuthServer__Authority=http://eshop-st-authserver - AuthServer__RequireHttpsMetadata=false - ConnectionStrings__IdentityService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Identity;Pooling=false; - - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; + - ConnectionStrings__AdministrationService=User ID=postgres;Password=myPassw0rd;Host=postgres-db;Port=5432;Database=EShopOnAbp_Administration;Pooling=false; - Redis__Configuration=redis - RabbitMQ__Connections__Default__HostName=rabbitmq - - IdentityServerClients__Web__RootUrl=http://localhost:4200 + - IdentityServerClients__Web__RootUrl=https://eshop-st-web - IdentityServerClients__PublicWeb__RootUrl=https://eshop-st-public-web - IdentityServerClients__WebGateway__RootUrl=https://localhost:44372 - IdentityServerClients__PublicWebGateway__RootUrl=https://eshop-st-gateway-web-public @@ -251,7 +251,7 @@ services: condition: service_healthy rabbitmq: condition: service_healthy - restart: on-failure + restart: on-failure networks: - eshoponabp-network eshop-st-public-web: diff --git a/etc/docker/nginx/dynamic-env.json b/etc/docker/nginx/dynamic-env.json index fd380d32..c9127782 100644 --- a/etc/docker/nginx/dynamic-env.json +++ b/etc/docker/nginx/dynamic-env.json @@ -9,8 +9,11 @@ "issuer": "https://eshop-st-authserver", "redirectUri": "https://eshop-st-web", "clientId": "Web", - "responseType": "password", - "scope": "offline_access openid profile email phone AccountService IdentityService AdministrationService CatalogService OrderingService" + "responseType": "code", + "scope": "offline_access openid profile email phone AccountService IdentityService AdministrationService CatalogService OrderingService", + "strictDiscoveryDocumentValidation": false, + "skipIssuerCheck": true, + "requireHttps": false }, "apis": { "default": { From 525a83bfc5a58db2477e87adacb81b104ce4d0c5 Mon Sep 17 00:00:00 2001 From: Galip Tolga Erdem Date: Mon, 6 Jun 2022 14:55:14 +0300 Subject: [PATCH 7/7] fixed angular login problem --- apps/angular/src/index.html | 28 +++++++++++-------- .../EShopOnAbpAuthServerModule.cs | 1 + etc/docker/nginx/dynamic-env.json | 1 - 3 files changed, 17 insertions(+), 13 deletions(-) diff --git a/apps/angular/src/index.html b/apps/angular/src/index.html index 1e325c50..54ba34c2 100644 --- a/apps/angular/src/index.html +++ b/apps/angular/src/index.html @@ -1,16 +1,20 @@ - - - EShopOnAbp - - - - - - -
-
- + + + + EShopOnAbp + + + + + + + + +
+
+ + diff --git a/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs b/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs index 05c20b0d..3f1ebc6b 100644 --- a/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs +++ b/apps/auth-server/src/EShopOnAbp.AuthServer/EShopOnAbpAuthServerModule.cs @@ -78,6 +78,7 @@ public class EShopOnAbpAuthServerModule : AbpModule var hostingEnvironment = context.Services.GetHostingEnvironment(); var configuration = context.Services.GetConfiguration(); + ConfigureSameSiteCookiePolicy(context); ConfigureSwagger(context, configuration); context.Services.AddAuthentication() diff --git a/etc/docker/nginx/dynamic-env.json b/etc/docker/nginx/dynamic-env.json index c9127782..56c559a2 100644 --- a/etc/docker/nginx/dynamic-env.json +++ b/etc/docker/nginx/dynamic-env.json @@ -12,7 +12,6 @@ "responseType": "code", "scope": "offline_access openid profile email phone AccountService IdentityService AdministrationService CatalogService OrderingService", "strictDiscoveryDocumentValidation": false, - "skipIssuerCheck": true, "requireHttps": false }, "apis": {