From 0d34b84c9e8aed15b04107b9f98368a2087cc34c Mon Sep 17 00:00:00 2001 From: Justin Kotalik Date: Wed, 29 Jul 2020 16:27:49 -0700 Subject: [PATCH] Still making progress --- samples/voting/IdentityServer/Startup.cs | 44 ++++++++++++++++++++--- samples/voting/results/Pages/_Host.cshtml | 1 - samples/voting/results/Startup.cs | 10 +++++- samples/voting/results/appsettings.json | 6 ++-- samples/voting/tye.yaml | 8 ++--- 5 files changed, 56 insertions(+), 13 deletions(-) diff --git a/samples/voting/IdentityServer/Startup.cs b/samples/voting/IdentityServer/Startup.cs index 5cc351fa..cb7ad0ed 100644 --- a/samples/voting/IdentityServer/Startup.cs +++ b/samples/voting/IdentityServer/Startup.cs @@ -16,6 +16,10 @@ using IdentityServer4.Services; using Microsoft.Extensions.Logging.Abstractions; using Microsoft.Extensions.Logging; using Microsoft.AspNetCore.Identity.EntityFrameworkCore; +using Microsoft.AspNetCore.Http; +using System.Threading.Tasks; +using IdentityServer4.Extensions; +using Microsoft.AspNetCore.HttpOverrides; namespace IdentityServer { @@ -41,7 +45,7 @@ namespace IdentityServer options.Events.RaiseInformationEvents = true; options.Events.RaiseFailureEvents = true; options.Events.RaiseSuccessEvents = true; - // options.IssuerUri = $"{publicIp}/identityserver"; + options.IssuerUri = $"{publicIp}/identityserver"; // see https://identityserver4.readthedocs.io/en/latest/topics/resources.html options.EmitStaticAudienceClaim = true; }) @@ -63,10 +67,9 @@ namespace IdentityServer AllowedGrantTypes = GrantTypes.Code, // These currently break when ingress is in place for redirect. - - RedirectUris = { $"{publicIp}/results/signin-oidc", $"{Configuration.GetServiceUri("results:http")}results/signin-oidc", $"{Configuration.GetServiceUri("results:http")}signin-oidc" }, + RedirectUris = { $"{publicIp}/results/signin-oidc"}, // $"{Configuration.GetServiceUri("results:http")}results/signin-oidc", $"{Configuration.GetServiceUri("results:http")}signin-oidc" FrontChannelLogoutUri = $"{publicIp}/results/signout-oidc", - PostLogoutRedirectUris = { $"{publicIp}/results/signout-callback-oidc", $"{Configuration.GetServiceUri("results:http")}results/signout-callback-oidc", $"{Configuration.GetServiceUri("results:http")}signout-callback-oidc" }, + PostLogoutRedirectUris = { $"{publicIp}/results/signout-callback-oidc" }, // , $"{Configuration.GetServiceUri("results:http")}results/signout-callback-oidc", $"{Configuration.GetServiceUri("results:http")}signout-callback-oidc" AllowOfflineAccess = true, AllowedScopes = new List{IdentityServerConstants.StandardScopes.OpenId,IdentityServerConstants.StandardScopes.Profile, "scope"} @@ -83,9 +86,20 @@ namespace IdentityServer { app.UseDeveloperExceptionPage(); } + // app.UseForwardedHeaders(); + app.UsePathBase("/identityserver"); app.UseStaticFiles(); + app.UseForwardedHeaders(new ForwardedHeadersOptions() + { + ForwardedHeaders = ForwardedHeaders.All + }); + + var publicIp = Configuration["public-ip"]; + + app.UseMiddleware($"{publicIp}"); + app.UseRouting(); app.UseIdentityServer(); app.UseAuthorization(); @@ -94,5 +108,27 @@ namespace IdentityServer endpoints.MapDefaultControllerRoute(); }); } + + public class PublicFacingUrlMiddleware + { + private readonly RequestDelegate _next; + private readonly string _publicFacingUri; + + public PublicFacingUrlMiddleware(RequestDelegate next, string publicFacingUri) + { + _publicFacingUri = publicFacingUri; + _next = next; + } + + public async Task Invoke(HttpContext context) + { + var request = context.Request; + + context.SetIdentityServerOrigin(_publicFacingUri); + // context.SetIdentityServerBasePath(request.PathBase.Value.TrimEnd('/')); + + await _next(context); + } + } } } diff --git a/samples/voting/results/Pages/_Host.cshtml b/samples/voting/results/Pages/_Host.cshtml index 5b384afb..59a9327d 100644 --- a/samples/voting/results/Pages/_Host.cshtml +++ b/samples/voting/results/Pages/_Host.cshtml @@ -14,7 +14,6 @@ Results - diff --git a/samples/voting/results/Startup.cs b/samples/voting/results/Startup.cs index de50e6a6..1dcff5cd 100644 --- a/samples/voting/results/Startup.cs +++ b/samples/voting/results/Startup.cs @@ -4,6 +4,7 @@ using Microsoft.Extensions.Configuration; using Microsoft.Extensions.DependencyInjection; using Microsoft.Extensions.Hosting; using System.IdentityModel.Tokens.Jwt; +using System.Threading.Tasks; namespace Results { @@ -24,6 +25,7 @@ namespace Results services.AddRazorPages(); services.AddServerSideBlazor(); + JwtSecurityTokenHandler.DefaultMapInboundClaims = false; services.AddAuthentication(options => @@ -34,12 +36,18 @@ namespace Results .AddCookie("Cookies") .AddOpenIdConnect("oidc", options => { - options.Authority = $"{Configuration["public-ip"]}/identityserver"; + options.Authority = $"{Configuration["public-ip"]}/identityserver/"; options.ClientId = "interactive"; options.ClientSecret = "49C1A7E1-0C79-4A89-A3D6-A37998FB86B0"; options.ResponseType = "code"; options.SaveTokens = true; options.RequireHttpsMetadata = false; + options.ReturnUrlParameter = $"{Configuration["public-ip"]}/results"; + options.Events.OnRedirectToIdentityProvider = n => + { + n.ProtocolMessage.RedirectUri = $"{Configuration["public-ip"]}/results/signin-oidc"; + return Task.CompletedTask; + }; }); } diff --git a/samples/voting/results/appsettings.json b/samples/voting/results/appsettings.json index d9d9a9bf..2197218d 100644 --- a/samples/voting/results/appsettings.json +++ b/samples/voting/results/appsettings.json @@ -1,9 +1,9 @@ { "Logging": { "LogLevel": { - "Default": "Information", - "Microsoft": "Warning", - "Microsoft.Hosting.Lifetime": "Information" + "Default": "Trace", + "Microsoft": "Trace", + "Microsoft.Hosting.Lifetime": "Trace" } }, "AllowedHosts": "*" diff --git a/samples/voting/tye.yaml b/samples/voting/tye.yaml index 09321039..2945bf6c 100644 --- a/samples/voting/tye.yaml +++ b/samples/voting/tye.yaml @@ -24,8 +24,8 @@ services: protocol: http env: - name: public-ip - # value: http://52.159.20.103 - value: http://localhost:8080 + value: http://52.159.20.103 + # value: http://localhost:8080 - name: identityserver project: IdentityServer/IdentityServer.csproj bindings: @@ -33,8 +33,8 @@ services: protocol: http env: - name: public-ip - # value: http://52.159.20.103 - value: http://localhost:8080 + value: http://52.159.20.103 + # value: http://localhost:8080 ingress: - name: ingress bindings: