5 Commits
Author SHA1 Message Date
janishutz a9245fd20f feat: check endpoint for CORS applications 2026-09-20 11:04:48 +02:00
janishutz 996f4959fb feat: stubs also call user function on login 2026-09-20 10:59:57 +02:00
janishutz 6fb820d6af feat: store UID in session 2026-09-19 18:00:17 +02:00
janishutz 0c4a463052 chore: add usage to readme 2026-09-19 17:15:47 +02:00
janishutz d744f68b12 fix: stylesheet 2026-09-19 17:10:47 +02:00
7 changed files with 84 additions and 20 deletions

No files matched your search

+34
View File
@@ -8,3 +8,37 @@ OIDC_CLIENT_SECRET=<client secret>
OIDC_ISSUE=<issuer url> OIDC_ISSUE=<issuer url>
``` ```
If these env vars are not present, then depending on configuration, stubs will be used for the endpoints or the program will crash If these env vars are not present, then depending on configuration, stubs will be used for the endpoints or the program will crash
## Usage
```go
package main
import (
"os"
"github.com/gin-contrib/sessions"
"github.com/gin-contrib/sessions/memstore"
"github.com/gin-gonic/gin"
"github.com/janishutz/oidclogin"
)
func main() {
r := gin.Default()
// TODO: Better secret
store := memstore.NewStore([]byte("secret"))
r.Use(sessions.Sessions("jhid", store))
oidclogin.Configure(r, os.Getenv("APP_BASE_URL"), "/account", false)
r.LoadHTMLGlob("public/*")
r.GET("/account", oidclogin.EnsureLogin(false), func(ctx *gin.Context) {
ctx.HTML(200, "main.tmpl", gin.H{})
})
r.Run()
}
```
This example further needs the environment variable `APP_BASE_URL` set to something like `https://app.example.org`.
Further, you should create a template file called `main.tmpl` and also copy over the template files in the `public` directory here and edit them.
+3
View File
@@ -112,6 +112,7 @@ func callbackHandler(c *gin.Context) {
session.Delete("redirect") session.Delete("redirect")
session.Set("jhid_auth", true) session.Set("jhid_auth", true)
session.Set("jhid_uid", claims.Uid)
session.Save() session.Save()
if redir != nil { if redir != nil {
@@ -125,6 +126,8 @@ func EnsureLogin(redirectFail bool) func(c *gin.Context) {
return (func(c *gin.Context) { return (func(c *gin.Context) {
session := sessions.Default(c) session := sessions.Default(c)
if session.Get("jhid_auth") == true { if session.Get("jhid_auth") == true {
// Set the UID on the context
c.Set("uid", session.Get("jhid_uid").(string))
c.Next() c.Next()
} else { } else {
if redirectFail { if redirectFail {
+1
View File
@@ -61,6 +61,7 @@ func Configure(r *gin.Engine, app_url string, default_redirect string, stubs_on_
r.GET("/auth/v2/login", loginHandler) r.GET("/auth/v2/login", loginHandler)
r.GET("/auth/v2/verify", callbackHandler) r.GET("/auth/v2/verify", callbackHandler)
r.GET("/auth/v2/check", EnsureLogin(false), func(ctx *gin.Context) { ctx.JSON(200, gin.H{"success": "true"}) })
log.Println("[JHID] Configured successfully") log.Println("[JHID] Configured successfully")
} }
+4 -1
View File
@@ -1,10 +1,13 @@
<html> <html>
<head> <head>
<!-- NOTE: You should definitely host this yourself! (and you can adjust the style that way, too!) --> <!-- NOTE: You should definitely host this yourself! (and you can adjust the style that way, too!) -->
<link rel="stylesheet" href="https://cdn.jsdelir.net/gh/janishutz/oidclogin/public/style.css"> <link rel="stylesheet" href="https://cdn.jsdelivr.net/gh/janishutz/oidclogin/public/style.css">
</head> </head>
<body> <body>
<div class="message-wrapper">
<h1>401</h1> <h1>401</h1>
<p>Unauthorized</p>
</div>
<p>You are not authorized to view this page. Please log in</p> <p>You are not authorized to view this page. Please log in</p>
<a href="/">Back Home</a> <a href="/">Back Home</a>
</body> </body>
+5 -2
View File
@@ -1,11 +1,14 @@
<html> <html>
<head> <head>
<!-- NOTE: You should definitely host this yourself! (and you can adjust the style that way, too!) --> <!-- NOTE: You should definitely host this yourself! (and you can adjust the style that way, too!) -->
<link rel="stylesheet" href="https://cdn.jsdelir.net/gh/janishutz/oidclogin/public/style.css"> <link rel="stylesheet" href="https://cdn.jsdelivr.net/gh/janishutz/oidclogin/public/style.css">
</head> </head>
<body> <body>
<div class="message-wrapper">
<h1>500</h1> <h1>500</h1>
<p>Login Failed!</p> <p>Internal Server Error</p>
</div>
<p>There was an error logging you in. Please try again. We are sorry for the inconvenience</p>
<a href="/">Back Home</a> <a href="/">Back Home</a>
<p class="error-msg">{{ .error }}</p> <p class="error-msg">{{ .error }}</p>
</body> </body>
+19 -3
View File
@@ -1,4 +1,5 @@
html, body { html,
body {
background-color: #050505; background-color: #050505;
color: #FFFFFF; color: #FFFFFF;
width: 100vw; width: 100vw;
@@ -12,16 +13,31 @@ body {
display: flex; display: flex;
justify-content: center; justify-content: center;
align-items: center; align-items: center;
flex-direction: column;
} }
h1 { .message-wrapper {
display: flex;
justify-content: center;
align-items: center;
}
.message-wrapper h1 {
font-size: 10rem; font-size: 10rem;
} }
p { .message-wrapper p {
font-size: 1.5rem; font-size: 1.5rem;
} }
a {
color: white;
background-color: #101066;
padding: 10px;
border-radius: 10px;
cursor: pointer;
}
.error-msg { .error-msg {
font-size: 0.8rem; font-size: 0.8rem;
position: fixed; position: fixed;
+18 -14
View File
@@ -1,22 +1,26 @@
package oidclogin package oidclogin
import "github.com/gin-gonic/gin" import (
"github.com/gin-contrib/sessions"
"github.com/gin-gonic/gin"
)
func startStubs(r *gin.Engine) { func startStubs(r *gin.Engine) {
r.GET("/auth/v2/login", func(ctx *gin.Context) { r.GET("/auth/v2/login", stubsHandler)
redir := ctx.Query("returnTo") r.GET("/auth/v2/verify", stubsHandler)
r.GET("/auth/v2/check", EnsureLogin(false), func(ctx *gin.Context) { ctx.JSON(200, gin.H{"success": "true"}) })
}
func stubsHandler(c *gin.Context) {
redir := c.Query("returnTo")
session := sessions.Default(c)
userFunc("stubs", "Stubs User", "example@example.com")
session.Set("jhid_auth", true)
session.Set("jhid_uid", "stubs")
session.Save()
if redir != "" { if redir != "" {
ctx.Redirect(307, redir) c.Redirect(307, redir)
} else { } else {
ctx.Redirect(307, defaultRedirect) c.Redirect(307, defaultRedirect)
} }
})
r.GET("/auth/v2/verify", func(ctx *gin.Context) {
redir := ctx.Query("returnTo")
if redir != "" {
ctx.Redirect(307, redir)
} else {
ctx.Redirect(307, defaultRedirect)
}
})
} }