Justin Palpant 7d910c0ae8 Check Google group membership with hasMember and get. (#224)
* Check Google group membership with hasMember and get.

This PR is an enhancement built on
https://github.com/pusher/oauth2_proxy/pull/160. That PR reduces the
number of calls to the Google Admin API and simplifies the code by
using the hasMember method. It also supports checking membership in
nested groups.

However, the above message doesn't handle members who are not a part
of the domain. The hasMember API returns a 400 for that case. As a
fallback, when the API returns a 400, this change will try using the
`get` API which works as expected for members who aren't a part of the
domain. Supporting members who belong to the Google group but aren't
part of the domain is a requested feature from
https://github.com/pusher/oauth2_proxy/issues/95.

https://developers.google.com/admin-sdk/directory/v1/reference/members/get

Note that nested members who are not a part of the domain will not be
correctly detected with this change.

* Update CHANGELOG.

* Fix incorrect JSON and stop escaping strings.

* Add comments for each scenario.
2019-08-06 10:38:24 +01:00
2019-07-24 09:21:08 +01:00
2019-06-01 05:36:28 +03:00
2019-01-22 02:54:17 +09:00
2019-07-15 21:38:55 +01:00
2019-07-13 21:54:45 +01:00
2019-07-13 21:54:45 +01:00
2019-06-15 11:33:58 +02:00
2019-06-23 21:39:13 +01:00
2019-06-15 11:33:58 +02:00
2014-06-09 16:25:26 -04:00
2019-07-16 13:32:57 +01:00
2019-07-13 21:54:45 +01:00
2019-07-19 22:11:53 +12:00
2019-05-10 12:25:05 +01:00
2019-06-15 11:33:58 +02:00
2019-06-15 11:33:58 +02:00
2019-01-04 10:58:30 +00:00
2019-06-15 11:33:58 +02:00

oauth2_proxy

A reverse proxy and static file server that provides authentication using Providers (Google, GitHub, and others) to validate accounts by email, domain or group.

Note: This repository was forked from bitly/OAuth2_Proxy on 27/11/2018. Versions v3.0.0 and up are from this fork and will have diverged from any changes in the original fork. A list of changes can be seen in the CHANGELOG.

Build Status

Sign In Page

Installation

  1. Choose how to deploy:

    a. Download Prebuilt Binary (current release is v3.2.0)

    b. Build with $ go get github.com/pusher/oauth2_proxy which will put the binary in $GOROOT/bin

    c. Using the prebuilt docker image quay.io/pusher/oauth2_proxy (AMD64, ARMv6 and ARM64 tags available)

Prebuilt binaries can be validated by extracting the file and verifying it against the sha256sum.txt checksum file provided for each release starting with version v3.0.0.

sha256sum -c sha256sum.txt 2>&1 | grep OK
oauth2_proxy-3.2.0.linux-amd64: OK
  1. Select a Provider and Register an OAuth Application with a Provider
  2. Configure OAuth2 Proxy using config file, command line options, or environment variables
  3. Configure SSL or Deploy behind a SSL endpoint (example provided for Nginx)

Docs

Read the docs on our Docs site.

OAuth2 Proxy Architecture

Contributing

Please see our Contributing guidelines.

Description
Fork https://github.com/pusher/oauth2_proxy.git Adding gitea provider
Readme 1.8 MiB
Languages
Go 98%
Makefile 1.3%
Shell 0.4%
Dockerfile 0.3%