【发布时间】:2019-05-22 04:55:09
【问题描述】:
首先:我不是 nginx 专家。非常新手。
我正在尝试使用 nginx 进行身份验证来保护第 3 方软件(真的 - 只是验证请求具有有效的 OAuth2 Bearer 令牌)
HTTP 请求的身份验证标头中将包含一个 OAuth2 不记名令牌。
例如授权:承载 eyJhbGciOiJSUzI1NiIsImtpZ....H5w
我有一个 OAuth2 服务器 (UAA),它有一个 API,如果令牌有效,我可以在其中调用 http://myuaa/check_token?token=eyJhbGciOiJSUzI1NiIsImtpZ....H5w 来取回 2XX 或 4XX。一个复杂的问题是该服务器确实需要基本身份验证才能调用 /check_token 端点。
我尝试使用映射从授权标头中解析令牌,但没有成功。
只是有点不知所措。
也许这不适合 Nginx?
nginx.conf 的相关部分
# this map isnt working as I thought it might
http {
...
map $http_authorization $token {
~Bearer(?<token>abc) $token;
}
...
# test just to see if the authorization header is being parsed and passed - no luck
location /oauth {
proxy_set_header X-my-header $token;
proxy_set_header X-another-header value;
proxy_set_header Authorization "Basic basdasdfasdf";
proxy_pass http://localhost:8080;
}
对 nginx 正在保护的第 3 方服务器的预期请求:
<GET|POST|PUT|DELETE> /anyurl HTTP1/1.1
..
Authorization: Bearer eyJhbGciOiJSUzI1NiIsImtpZ....H5w
..
预期请求转发到 UAA 服务器以验证令牌
GET /check_token?token=eyJhbGciOiJSUzI1NiIsImtpZ....H5w
..
Authorization Basic asfasdfdf
..
【问题讨论】: