Public Access
Add configuration, OIDC auth wiring and discovery endpoints (M1)
Options, JWT bearer validation, the /meta and .well-known endpoints, and a dev compose stack with Keycloak. Verified end to end: compose up, migrate, run, both discovery endpoints return correct payloads, and readiness reports the schema current. Configuration: - Strongly-typed options for Server, Oidc, Relay and Sync, all ValidateOnStart. A self-hosted server that boots half-configured and fails later per-request is far harder to diagnose than one that refuses to start and names the bad setting. - Cross-field validation the annotations cannot express: relay needs a WebSocketUrl when enabled, idle timeout must be under max session duration, item payload cap under batch cap. - Startup warnings for combinations that are individually valid but dangerous together: RequireHttpsMetadata false outside Development, and AllowEmailLinking (which turns any token bearing a victim's email into account takeover, hence default false). Auth: - JwtBearer with ClockSkew cut to 30s from the 5-minute default; five minutes of slack on a credential granting vault ciphertext access is more than any clock needs. - IncludeErrorDetails off, and a FallbackPolicy so an endpoint without an explicit policy still requires a caller rather than silently being public. Discovery, per ADR 0002: - /api/v1/meta reports versions, features and push caps. - /.well-known/dodossh-configuration is the onboarding story: the user types one server URL and the client discovers OIDC authority, client id, scopes and relay endpoint. Two environment problems found by actually running the stack: - PostgreSQL 18 changed its data mount point. Mounting /var/lib/postgresql/data — correct through 17 — makes the image refuse to start; 18+ wants a single mount at /var/lib/postgresql with the cluster in a subdirectory. - Keycloak moved to host port 18080. An unrelated Apache Tomcat on this machine holds 127.0.0.1:8080, and a loopback-specific bind beats Docker's 0.0.0.0 publish for "localhost". It presents as Keycloak 404ing every realm while its own log says the import succeeded, which is a genuinely misleading failure. Also: CA1848 is enforced, not advisory — warnings are errors, so the .editorconfig comment claiming otherwise was wrong. Startup and health logging now uses [LoggerMessage]. And a clean rebuild is back to zero warnings; the incremental build had been hiding 40 in test projects (banned Guid.NewGuid, an obsolete Testcontainers constructor, and two analyzer families that are genuinely noise under a test host). Verified: 0 warnings on a clean rebuild, 122 tests pass, format clean.
This commit is contained in:
@@ -0,0 +1,67 @@
|
||||
using Microsoft.AspNetCore.Authentication.JwtBearer;
|
||||
using Microsoft.Extensions.Options;
|
||||
using Microsoft.IdentityModel.Tokens;
|
||||
|
||||
namespace DodoSSH.Api.Setup;
|
||||
|
||||
/// <summary>Authentication and authorization wiring.</summary>
|
||||
/// <remarks>
|
||||
/// The API validates bearer access tokens only. It never runs a browser flow itself: the desktop
|
||||
/// app is a public client using Authorization Code with PKCE and a loopback redirect, and it talks
|
||||
/// to the identity provider directly.
|
||||
/// </remarks>
|
||||
internal static class Auth
|
||||
{
|
||||
/// <summary>Policy requiring an authenticated caller.</summary>
|
||||
internal const string AuthenticatedPolicy = "Authenticated";
|
||||
|
||||
/// <summary>Policy requiring a caller who has completed key enrollment.</summary>
|
||||
internal const string EnrolledPolicy = "Enrolled";
|
||||
|
||||
internal static IServiceCollection AddDodoAuthentication(this IServiceCollection services)
|
||||
{
|
||||
services.AddAuthentication(JwtBearerDefaults.AuthenticationScheme)
|
||||
.AddJwtBearer(options =>
|
||||
{
|
||||
// Bound late so options validation has already run and the values are known good.
|
||||
var oidc = services.BuildServiceProvider().GetRequiredService<IOptions<OidcOptions>>().Value;
|
||||
|
||||
options.Authority = oidc.Authority;
|
||||
options.Audience = oidc.Audience;
|
||||
options.RequireHttpsMetadata = oidc.RequireHttpsMetadata;
|
||||
|
||||
options.TokenValidationParameters = new TokenValidationParameters
|
||||
{
|
||||
ValidateIssuer = true,
|
||||
ValidateAudience = true,
|
||||
ValidateLifetime = true,
|
||||
ValidateIssuerSigningKey = true,
|
||||
RequireSignedTokens = true,
|
||||
RequireExpirationTime = true,
|
||||
|
||||
// 30 seconds, not the 5-minute default. A five-minute grace period on a
|
||||
// credential that grants vault ciphertext access is far more slack than any
|
||||
// sane clock needs.
|
||||
ClockSkew = TimeSpan.FromSeconds(30),
|
||||
};
|
||||
|
||||
// Tokens are the one thing that must never reach a log or a trace.
|
||||
options.IncludeErrorDetails = false;
|
||||
});
|
||||
|
||||
services.AddAuthorization(options =>
|
||||
{
|
||||
options.AddPolicy(AuthenticatedPolicy, policy => policy.RequireAuthenticatedUser());
|
||||
|
||||
// Enrollment state lives in the database, so the real handler arrives with the
|
||||
// enrollment feature. Registered now so endpoint groups can reference the policy name
|
||||
// and the endpoint-inventory test has something to assert against.
|
||||
options.AddPolicy(EnrolledPolicy, policy => policy.RequireAuthenticatedUser());
|
||||
|
||||
// Deny by default: an endpoint without an explicit policy still requires a caller.
|
||||
options.FallbackPolicy = options.GetPolicy(AuthenticatedPolicy);
|
||||
});
|
||||
|
||||
return services;
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user