@geogirafe/lib-geoportal
Version:
GeoGirafe is a flexible application to build online geoportals.
53 lines (52 loc) • 3.28 kB
TypeScript
import IGirafeContext from '../context/icontext.js';
import AbstractConnectManager from './abstractconnectmanager.js';
import GMFManager from './gmfmanager.js';
/**
* For diverse reasons, this could NOT be done using the oAuth2 mechanisms of GMF:
* 1. There is no .well-know discovery endpoint
* 2. The token endpoint needs a client_secret, and for security reasons it has to be called from the backend itself.
* There is not custom backend for GeoGirafe and we cannot do this.
* 3. The redirect url is limited to exact matches, and we cannot pass the state of the application in the redirect_uri
* 4. Using GMF oAuth2 routes for authentification does not authenticate the user to the backend.
* It just tells the client that you have a correct user in GMF.
* But you do not get any valid cookie for the GMF Backend.
*
* For all those reasons, we cannot use the geomapfish oAuth process
* Instead we delegate the login to the backend, which is a Backend-For-Frontend (BFF) pattern:
* the frontend only ever holds a session cookie, and never needs any OIDC-specific configuration
* (no clientId, no issuer url) -- the identity provider is only known to the backend.
*
* Two `gmfauth.loginMode` flavors are supported, both delegating entirely to the backend:
* - 'form' (default): the backend's login.html page, a standard GMF username/password login form.
* There is no oAuth process at all in this mode.
* - 'oidc': the backend's oidc/login route (c2cgeoportal_geoportal's OpenID Connect integration).
* The browser is redirected to oidc/login, which itself redirects to the identity provider;
* after the user authenticates there, the backend's oidc/callback exchanges the code for tokens
* (server-side, using the client_secret) and redirects back here with the auth_tkt session cookie
* set. This is exactly how ngeo authenticates against a GMF backend with
* `authentication.openid_connect` enabled: the browser never talks to the identity provider
* directly, and gg-viewer needs no more configuration for this mode than for 'form'.
*
* Once the redirect comes back (either flavor), everything below is identical: we only ever
* trust the session cookie and poll the backend's loginuser endpoint to know who is logged in.
*
* NOTE: If the geogirafe client is not running on the same domain as the GMF backend,
* the GMF Backend needs to be configured with :
* - CORS with credentials for specific domain (this can be done for example with an lua script at the in the haproxy configuration)
* - The frontend domain has to be allowed as referer in the vars.yaml file.
* - The variable AUTHTKT_SAMESITE has to be set to None, to allow authentication cookies to be sent to the backend from another domain
* These constraints apply identically to both loginMode flavors.
*/
export default class GMFConnectManager extends AbstractConnectManager {
private readonly gmfManager;
constructor(context: IGirafeContext, gmfManager: GMFManager);
private get authConfig();
private isAuthentified;
initialize(): Promise<void>;
login(): Promise<void>;
silentLogin(): Promise<void>;
logout(): Promise<void>;
private redirectToIssuerLogin;
private handleLoggedInToIssuer;
private refreshToken;
}