diff --git a/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs b/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs index 58e1f408..0bc83acb 100644 --- a/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs +++ b/apps/public-web/src/EShopOnAbp.PublicWeb/EShopOnAbpPublicWebModule.cs @@ -141,27 +141,68 @@ public class EShopOnAbpPublicWebModule : AbpModule .AddCookie("Cookies", options => { options.ExpireTimeSpan = TimeSpan.FromDays(365); }) .AddAbpOpenIdConnect("oidc", options => { - options.Authority = configuration["AuthServer:Authority"]; - options.RequireHttpsMetadata = Convert.ToBoolean(configuration["AuthServer:RequireHttpsMetadata"]); - options.ResponseType = OpenIdConnectResponseType.CodeIdToken; - - options.ClientId = configuration["AuthServer:ClientId"]; - options.ClientSecret = configuration["AuthServer:ClientSecret"]; - - options.SaveTokens = true; + /* + * ASP.NET core uses the http://*:5000 and https://*:5001 ports for default communication with the OIDC middleware + * The app requires load balancing services to work with :80 or :443 + * These needs to be added to the keycloak client, in order for the redirect to work. + * If you however intend to use the app by itself then, + * Change the ports in launchsettings.json, but beware to also change the options.CallbackPath and options.SignedOutCallbackPath! + * Use LB services whenever possible, to reduce the config hazzle :) + */ + + //Use default signin scheme + // options.SignInScheme = CookieAuthenticationDefaults.AuthenticationScheme; + //Keycloak server + options.Authority = configuration["Keycloak:ServerRealm"]; + //Keycloak client ID + options.ClientId = configuration["Keycloak:ClientId"]; + //Keycloak client secret + options.ClientSecret = configuration["Keycloak:ClientSecret"]; + //Keycloak .wellknown config origin to fetch config + options.MetadataAddress = configuration["Keycloak:Metadata"]; + //Require keycloak to use SSL + options.RequireHttpsMetadata = false; options.GetClaimsFromUserInfoEndpoint = true; - - options.Scope.Add("role"); - options.Scope.Add("email"); - options.Scope.Add("phone"); - options.Scope.Add("AccountService"); - options.Scope.Add("AdministrationService"); - options.Scope.Add("BasketService"); - options.Scope.Add("CatalogService"); - options.Scope.Add("PaymentService"); - options.Scope.Add("OrderingService"); - options.Scope.Add("CmskitService"); + options.Scope.Add("openid"); + options.Scope.Add("profile"); + //Save the token + options.SaveTokens = true; + //Token response type, will sometimes need to be changed to IdToken, depending on config. + options.ResponseType = OpenIdConnectResponseType.Code; + //SameSite is needed for Chrome/Firefox, as they will give http error 500 back, if not set to unspecified. + // options.NonceCookie.SameSite = SameSiteMode.Unspecified; + // options.CorrelationCookie.SameSite = SameSiteMode.Unspecified; + // + // options.TokenValidationParameters = new TokenValidationParameters + // { + // NameClaimType = "name", + // RoleClaimType = ClaimTypes.Role, + // ValidateIssuer = true + // }; }); + // .AddAbpOpenIdConnect("oidc", options => + // { + // options.Authority = configuration["AuthServer:Authority"]; + // options.RequireHttpsMetadata = Convert.ToBoolean(configuration["AuthServer:RequireHttpsMetadata"]); + // options.ResponseType = OpenIdConnectResponseType.CodeIdToken; + // + // options.ClientId = configuration["AuthServer:ClientId"]; + // options.ClientSecret = configuration["AuthServer:ClientSecret"]; + // + // options.SaveTokens = true; + // options.GetClaimsFromUserInfoEndpoint = true; + // + // options.Scope.Add("role"); + // options.Scope.Add("email"); + // options.Scope.Add("phone"); + // options.Scope.Add("AccountService"); + // options.Scope.Add("AdministrationService"); + // options.Scope.Add("BasketService"); + // options.Scope.Add("CatalogService"); + // options.Scope.Add("PaymentService"); + // options.Scope.Add("OrderingService"); + // options.Scope.Add("CmskitService"); + // }); if (Convert.ToBoolean(configuration["AuthServer:IsOnProd"])) { context.Services.Configure("oidc", options => diff --git a/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.json b/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.json index 8d0d9e5b..bcf0d7ef 100644 --- a/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.json +++ b/apps/public-web/src/EShopOnAbp.PublicWeb/appsettings.json @@ -43,6 +43,14 @@ "IsOnProd": "false", "MetaAddress": "https://localhost:44330" }, + "Keycloak": { + "ServerRealm": "http://localhost:8080/realms/master", + "Metadata": "http://localhost:8080/realms/master/.well-known/openid-configuration", + "ClientId": "PublicWeb", + "ClientSecret": "mPpj650ADqHwQ0g9qvwWNxCqQmefrGw7", + "TokenExchange": "http://localhost:8080/realms/master/protocol/openid-connect/token", + "Audience": "some-audience" + }, "ReverseProxy": { "Routes": { "route1" : { diff --git a/etc/docker/docker-compose.infrastructure.override.yml b/etc/docker/docker-compose.infrastructure.override.yml index 249946e7..c3c7ddeb 100644 --- a/etc/docker/docker-compose.infrastructure.override.yml +++ b/etc/docker/docker-compose.infrastructure.override.yml @@ -30,7 +30,7 @@ services: keycloak: ports: - - "44320:8080" + - "8080:8080" environment: DB_VENDOR: postgres DB_ADDR: "postgres-db" @@ -41,5 +41,5 @@ services: KEYCLOAK_ADMIN_PASSWORD: admin KC_HEALTH_ENABLED: true entrypoint: ["/opt/keycloak/bin/kc.sh", "start-dev"] - + \ No newline at end of file diff --git a/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.json b/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.json index 8610b450..620ba213 100644 --- a/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.json +++ b/services/administration/src/EShopOnAbp.AdministrationService.HttpApi.Host/appsettings.json @@ -4,8 +4,8 @@ "CorsOrigins": "https://localhost:44372,https://localhost:44373" }, "AuthServer": { - "Authority": "https://localhost:44330", - "RequireHttpsMetadata": "true", + "Authority": "http://localhost:8080/realms/master", + "RequireHttpsMetadata": "false", "SwaggerClientId": "WebGateway_Swagger", "SwaggerClientSecret": "1q2w3e*" },