内部服务接入 TinyAuth

2026/10/11 19:57:58Henry2 阅读1 点赞0 评论

对于一些没有认证功能的内部服务可以考虑使用 Nginx 接入 TinyAuth,配置简单,且 TinyAuth 支持多种便捷登录方式,甚至可以接入 OIDC,特别适合内网服务鉴权。

这样一来,特别是对于一些没有用户系统的轻量应用,不必再为其单独对接各类认证方式,可以通过 TinyAuth 当作桥梁最终接入到 OIDC 系统中,实现统一身份管理。

NGINX
# Auth Begin
location / {
    auth_request /auth;
    auth_request_set $redirect_url $upstream_http_x_tinyauth_location;

    # 授权成功后,从 Tinyauth 响应头中提取用户信息
    auth_request_set $user  $upstream_http_x_tinyauth_user;
    auth_request_set $email $upstream_http_x_tinyauth_email;
    proxy_set_header X-Tinyauth-User $user;
    proxy_set_header X-Tinyauth-Email $email;
    proxy_set_header remote-user $user;

    # 将 Tinyauth 续期 Cookie 传回浏览器
    auth_request_set $auth_cookie $upstream_http_set_cookie;
    add_header Set-Cookie $auth_cookie always;

    # (可选)不向代理服务转发 Fetch Metadata
    # 解决一些开启跨域防护的后端服务拦截问题,如思源笔记
    # proxy_set_header Sec-Fetch-Site "";

    # 反向代理相关
    proxy_set_header Host $http_host;
    proxy_set_header X-Real-IP $remote_addr; 
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; 
    proxy_set_header REMOTE-HOST $remote_addr; 
    proxy_set_header Upgrade $http_upgrade; 
    proxy_set_header Connection $http_connection; 
    proxy_set_header X-Forwarded-Proto $scheme; 
    proxy_set_header X-Forwarded-Port $server_port; 

    # 认证通过后,转发到服务端口(反向代理配置)
    proxy_pass http://127.0.0.1:<your_service_port>;
    proxy_set_header Accept-Encoding ""; 
    proxy_http_version 1.1;
    proxy_ssl_server_name off; 
    proxy_ssl_name $proxy_host; 
    add_header X-Cache $upstream_cache_status; 

    # 浏览器缓存
    if ( $uri ~* "\.(gif|png|jpg|css|js|woff|woff2|jpeg|svg|webp|avif)$" ) {
        expires 3d; 
    }

    # 未登录,无权限等错误处理
    error_page 401 403 =302 $redirect_url;
}

location = /auth {
    internal;
    # TinyAuth 服务验证地址
    proxy_pass http://127.0.0.1:3000/api/auth/nginx;

    proxy_pass_request_body off;
    proxy_set_header Content-Length "";

    proxy_set_header X-Original-URL $scheme://$host$request_uri;
    proxy_set_header X-Original-Method $request_method;

    # 覆盖客户端传来的代理头
    proxy_set_header X-Forwarded-Host $host;
    proxy_set_header X-Forwarded-Proto $scheme;
    proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    proxy_set_header X-Real-IP $remote_addr;
}
# Auth End

当然,一些本来就具备完善鉴权体系的应用就 dark 不必接入一层 TinyAuth 了,直接和统一身份认证中心对接即可。毕竟没人愿意对每一个服务都写这一大堆的 Nginx 配置 😂。


字节星球 261011

评论区