内部服务接入 TinyAuth
对于一些没有认证功能的内部服务可以考虑使用 Nginx 接入 TinyAuth,配置简单,且 TinyAuth 支持多种便捷登录方式,甚至可以接入 OIDC,特别适合内网服务鉴权。
这样一来,特别是对于一些没有用户系统的轻量应用,不必再为其单独对接各类认证方式,可以通过 TinyAuth 当作桥梁最终接入到 OIDC 系统中,实现统一身份管理。
# Auth Begin
location / {
auth_request /auth;
auth_request_set $redirect_url $upstream_http_x_tinyauth_location;
# 授权成功后,从 Tinyauth 响应头中提取用户信息
auth_request_set $user $upstream_http_x_tinyauth_user;
auth_request_set $email $upstream_http_x_tinyauth_email;
proxy_set_header X-Tinyauth-User $user;
proxy_set_header X-Tinyauth-Email $email;
proxy_set_header remote-user $user;
# 将 Tinyauth 续期 Cookie 传回浏览器
auth_request_set $auth_cookie $upstream_http_set_cookie;
add_header Set-Cookie $auth_cookie always;
# (可选)不向代理服务转发 Fetch Metadata
# 解决一些开启跨域防护的后端服务拦截问题,如思源笔记
# proxy_set_header Sec-Fetch-Site "";
# 反向代理相关
proxy_set_header Host $http_host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header REMOTE-HOST $remote_addr;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $http_connection;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Port $server_port;
# 认证通过后,转发到服务端口(反向代理配置)
proxy_pass http://127.0.0.1:<your_service_port>;
proxy_set_header Accept-Encoding "";
proxy_http_version 1.1;
proxy_ssl_server_name off;
proxy_ssl_name $proxy_host;
add_header X-Cache $upstream_cache_status;
# 浏览器缓存
if ( $uri ~* "\.(gif|png|jpg|css|js|woff|woff2|jpeg|svg|webp|avif)$" ) {
expires 3d;
}
# 未登录,无权限等错误处理
error_page 401 403 =302 $redirect_url;
}
location = /auth {
internal;
# TinyAuth 服务验证地址
proxy_pass http://127.0.0.1:3000/api/auth/nginx;
proxy_pass_request_body off;
proxy_set_header Content-Length "";
proxy_set_header X-Original-URL $scheme://$host$request_uri;
proxy_set_header X-Original-Method $request_method;
# 覆盖客户端传来的代理头
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Real-IP $remote_addr;
}
# Auth End
当然,一些本来就具备完善鉴权体系的应用就 dark 不必接入一层 TinyAuth 了,直接和统一身份认证中心对接即可。毕竟没人愿意对每一个服务都写这一大堆的 Nginx 配置 😂。
字节星球 261011
评论区