4 Commits
Author SHA1 Message Date
janishutz 0c4a463052 chore: add usage to readme 2026-09-19 17:15:47 +02:00
janishutz d744f68b12 fix: stylesheet 2026-09-19 17:10:47 +02:00
janishutz 133cbfd86c feat: improve templates 2026-09-19 17:04:11 +02:00
janishutz da7dd13e2a feat: add error handler 2026-09-19 16:49:36 +02:00
6 changed files with 134 additions and 12 deletions

No files matched your search

+34
View File
@@ -8,3 +8,37 @@ OIDC_CLIENT_SECRET=<client secret>
OIDC_ISSUE=<issuer url> OIDC_ISSUE=<issuer url>
``` ```
If these env vars are not present, then depending on configuration, stubs will be used for the endpoints or the program will crash If these env vars are not present, then depending on configuration, stubs will be used for the endpoints or the program will crash
## Usage
```go
package main
import (
"os"
"github.com/gin-contrib/sessions"
"github.com/gin-contrib/sessions/memstore"
"github.com/gin-gonic/gin"
"github.com/janishutz/oidclogin"
)
func main() {
r := gin.Default()
// TODO: Better secret
store := memstore.NewStore([]byte("secret"))
r.Use(sessions.Sessions("jhid", store))
oidclogin.Configure(r, os.Getenv("APP_BASE_URL"), "/account", false)
r.LoadHTMLGlob("public/*")
r.GET("/account", oidclogin.EnsureLogin(false), func(ctx *gin.Context) {
ctx.HTML(200, "main.tmpl", gin.H{})
})
r.Run()
}
```
This example further needs the environment variable `APP_BASE_URL` set to something like `https://app.example.org`.
Further, you should create a template file called `main.tmpl` and also copy over the template files in the `public` directory here and edit them.
+11 -7
View File
@@ -10,7 +10,7 @@ import (
"golang.org/x/oauth2" "golang.org/x/oauth2"
) )
func LoginHandler(c *gin.Context) { func loginHandler(c *gin.Context) {
// Set up user session // Set up user session
state := rand.Text() state := rand.Text()
nonce := rand.Text() nonce := rand.Text()
@@ -27,7 +27,7 @@ func LoginHandler(c *gin.Context) {
c.Redirect(301, config.AuthCodeURL(state, oidc.Nonce(nonce), oauth2.S256ChallengeOption(codeVerifier))) c.Redirect(301, config.AuthCodeURL(state, oidc.Nonce(nonce), oauth2.S256ChallengeOption(codeVerifier)))
} }
func CallbackHandler(c *gin.Context) { func callbackHandler(c *gin.Context) {
session := sessions.Default(c) session := sessions.Default(c)
state := session.Get("jhid_oauth_state") state := session.Get("jhid_oauth_state")
nonce := session.Get("jhid_oauth_nonce") nonce := session.Get("jhid_oauth_nonce")
@@ -83,14 +83,20 @@ func CallbackHandler(c *gin.Context) {
} }
if err := idToken.Claims(&claims); err != nil { if err := idToken.Claims(&claims); err != nil {
log.Println("Token claims generation failed", err) log.Println("Token claims generation failed", err)
c.AbortWithStatus(500) c.HTML(500, "oidcerror.tmpl", gin.H{
"error": "ERR_AUTH",
})
c.Abort()
return return
} }
// Verify NONCE // Verify NONCE
if nonce != claims.Nonce { if nonce != claims.Nonce {
log.Println("Token verificcation failed", err) log.Println("Token verificcation failed", err)
c.AbortWithStatus(500) c.HTML(500, "oidcerror.tmpl", gin.H{
"error": "ERR_AUTH",
})
c.Abort()
return return
} }
@@ -126,9 +132,7 @@ func EnsureLogin(redirectFail bool) func(c *gin.Context) {
c.Abort() c.Abort()
return return
} else { } else {
c.HTML(401, "autherror.tmpl", gin.H{ c.HTML(401, "autherror.tmpl", gin.H{})
"error": "ERR_AUTH",
})
c.Abort() c.Abort()
return return
} }
+17 -2
View File
@@ -27,6 +27,7 @@ var (
defaultRedirect string defaultRedirect string
) )
// Configure and set up the login SDK.
func Configure(r *gin.Engine, app_url string, default_redirect string, stubs_on_unconfigured bool) { func Configure(r *gin.Engine, app_url string, default_redirect string, stubs_on_unconfigured bool) {
issuer := os.Getenv("OIDC_ISSUER") issuer := os.Getenv("OIDC_ISSUER")
clientID := os.Getenv("OIDC_CLIENT_ID") clientID := os.Getenv("OIDC_CLIENT_ID")
@@ -58,8 +59,22 @@ func Configure(r *gin.Engine, app_url string, default_redirect string, stubs_on_
Scopes: []string{oidc.ScopeOpenID, "email", "profile"}, Scopes: []string{oidc.ScopeOpenID, "email", "profile"},
} }
r.GET("/auth/v2/login", LoginHandler) r.GET("/auth/v2/login", loginHandler)
r.GET("/auth/v2/verify", CallbackHandler) r.GET("/auth/v2/verify", callbackHandler)
log.Println("[JHID] Configured successfully") log.Println("[JHID] Configured successfully")
} }
func ErrorHandler() gin.HandlerFunc {
return func(c *gin.Context) {
c.Next()
if len(c.Errors) > 0 {
log.Println("Error during route:", c.Errors.Last().Err)
c.JSON(500, gin.H{
"error": "Internal Server Error",
})
}
}
}
+14
View File
@@ -0,0 +1,14 @@
<html>
<head>
<!-- NOTE: You should definitely host this yourself! (and you can adjust the style that way, too!) -->
<link rel="stylesheet" href="https://cdn.jsdelivr.net/gh/janishutz/oidclogin/public/style.css">
</head>
<body>
<div class="message-wrapper">
<h1>401</h1>
<p>Unauthorized</p>
</div>
<p>You are not authorized to view this page. Please log in</p>
<a href="/">Back Home</a>
</body>
</html>
+9 -3
View File
@@ -1,9 +1,15 @@
<html> <html>
<head> <head>
<!-- NOTE: You should definitely host this yourself! (and you can adjust the style that way, too!) -->
<link rel="stylesheet" href="https://cdn.jsdelivr.net/gh/janishutz/oidclogin/public/style.css">
</head> </head>
<body> <body>
<h1>Login Failed!</h1> <div class="message-wrapper">
<p>{{ .error }}</p> <h1>500</h1>
<p>Internal Server Error</p>
</div>
<p>There was an error logging you in. Please try again. We are sorry for the inconvenience</p>
<a href="/">Back Home</a>
<p class="error-msg">{{ .error }}</p>
</body> </body>
</html> </html>
+49
View File
@@ -0,0 +1,49 @@
html,
body {
background-color: #050505;
color: #FFFFFF;
width: 100vw;
height: 100vh;
margin: 0;
padding: 0;
}
body {
font-family: sans-serif;
display: flex;
justify-content: center;
align-items: center;
flex-direction: column;
}
.message-wrapper {
display: flex;
justify-content: center;
align-items: center;
}
.message-wrapper h1 {
font-size: 10rem;
}
.message-wrapper p {
font-size: 1.5rem;
}
a {
color: white;
background-color: #101066;
padding: 10px;
border-radius: 10px;
cursor: pointer;
}
.error-msg {
font-size: 0.8rem;
position: fixed;
bottom: 10px;
left: 0;
width: 100vw;
text-align: center;
color: #888888;
}