-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Erstatt token provider med forenklet versjon (#10)
* Erstatt token provider med forenklet versjon * Bruk bedre navn på exception * Bruk korrekt ktlint-versjon i workflow * Legg til tester * Legg til dokumentasjon
- Loading branch information
Showing
20 changed files
with
286 additions
and
253 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1 +1,26 @@ | ||
# helsearbeidsgiver-tokenprovider | ||
# helsearbeidsgiver-tokenprovider | ||
|
||
Denne pakken inneholder hjelpemetoder for å hente OAuth2-token for tilgang mellom apper (med grant type "client_credentials"). | ||
|
||
Verdiene som er påkrevd i `OAuth2Environment` finnes typisk som systemvaribler. | ||
Systemvariablene stammer fra en Kubernetes-secret som automatisk legges til Nais-apper som har aktivert Azure AD | ||
([se hvordan her](https://doc.nav.cloud.nais.io/reference/application-spec/?h=azure#azureapplicationenabled)). | ||
Kubernetes-secreten vil hete `azure-<appnavn>-<id>` og inneholde systemvariablene som leses i eksempelet nedenfor. | ||
|
||
```kt | ||
import no.nav.helsearbeidsgiver.tokenprovider.OAuth2Environment | ||
import no.nav.helsearbeidsgiver.tokenprovider.oauth2ClientCredentialsTokenGetter | ||
|
||
val oauth2Environment = OAuth2Environment( | ||
scope = "api://dev-gcp.eksempel-scope/.default", | ||
wellKnownUrl = "AZURE_APP_WELL_KNOWN_URL".let(System::getenv), | ||
tokenEndpointUrl = "AZURE_OPENID_CONFIG_TOKEN_ENDPOINT".let(System::getenv), | ||
clientId = "AZURE_APP_CLIENT_ID".let(System::getenv), | ||
clientSecret = "AZURE_APP_CLIENT_SECRET".let(System::getenv), | ||
clientJwk = "AZURE_APP_JWK".let(System::getenv) | ||
) | ||
|
||
val tokenGetter = oauth2ClientCredentialsTokenGetter(oauth2Environment) | ||
|
||
val accessToken = tokenGetter() | ||
``` |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
5 changes: 0 additions & 5 deletions
5
src/main/kotlin/no/nav/helsearbeidsgiver/tokenprovider/AccessTokenProvider.kt
This file was deleted.
Oops, something went wrong.
40 changes: 0 additions & 40 deletions
40
src/main/kotlin/no/nav/helsearbeidsgiver/tokenprovider/DefaultOAuth2HttpClient.kt
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
22 changes: 22 additions & 0 deletions
22
src/main/kotlin/no/nav/helsearbeidsgiver/tokenprovider/OAuth2ClientCredentialsTokenGetter.kt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,22 @@ | ||
package no.nav.helsearbeidsgiver.tokenprovider | ||
|
||
import io.ktor.client.HttpClient | ||
import no.nav.security.token.support.client.core.oauth2.ClientCredentialsGrantRequest | ||
import no.nav.security.token.support.client.core.oauth2.ClientCredentialsTokenClient | ||
|
||
/** @param httpClient Dersom egendefinert klient brukes så kan gal konfigurasjon føre til feil. */ | ||
fun oauth2ClientCredentialsTokenGetter( | ||
env: OAuth2Environment, | ||
httpClient: HttpClient = createHttpClient(), | ||
): () -> String { | ||
val tokenClient = TokenClient(httpClient).let(::ClientCredentialsTokenClient) | ||
|
||
val request = env.toClientCredentialsProperties().let(::ClientCredentialsGrantRequest) | ||
|
||
return { | ||
tokenClient.getTokenResponse(request).accessToken | ||
?: throw MissingAccessTokenException() | ||
} | ||
} | ||
|
||
class MissingAccessTokenException : Exception() |
33 changes: 33 additions & 0 deletions
33
src/main/kotlin/no/nav/helsearbeidsgiver/tokenprovider/OAuth2Environment.kt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,33 @@ | ||
package no.nav.helsearbeidsgiver.tokenprovider | ||
|
||
import com.nimbusds.oauth2.sdk.GrantType | ||
import com.nimbusds.oauth2.sdk.auth.ClientAuthenticationMethod | ||
import no.nav.security.token.support.client.core.ClientAuthenticationProperties | ||
import no.nav.security.token.support.client.core.ClientProperties | ||
import java.net.URI | ||
|
||
data class OAuth2Environment( | ||
val scope: String, | ||
val wellKnownUrl: String, | ||
val tokenEndpointUrl: String, | ||
val clientId: String, | ||
val clientSecret: String, | ||
val clientJwk: String, | ||
) { | ||
internal fun toClientCredentialsProperties(): ClientProperties = | ||
ClientProperties( | ||
tokenEndpointUrl = tokenEndpointUrl.let(::URI), | ||
wellKnownUrl = wellKnownUrl.let(::URI), | ||
grantType = GrantType.CLIENT_CREDENTIALS, | ||
scope = scope.split(","), | ||
authentication = | ||
ClientAuthenticationProperties( | ||
clientId = clientId, | ||
clientAuthMethod = ClientAuthenticationMethod.CLIENT_SECRET_POST, | ||
clientSecret = clientSecret, | ||
clientJwk = clientJwk, | ||
), | ||
resourceUrl = null, | ||
tokenExchange = null, | ||
) | ||
} |
16 changes: 0 additions & 16 deletions
16
src/main/kotlin/no/nav/helsearbeidsgiver/tokenprovider/OAuth2TokenProvider.kt
This file was deleted.
Oops, something went wrong.
83 changes: 0 additions & 83 deletions
83
src/main/kotlin/no/nav/helsearbeidsgiver/tokenprovider/RestSTSAccessTokenProvider.kt
This file was deleted.
Oops, something went wrong.
41 changes: 41 additions & 0 deletions
41
src/main/kotlin/no/nav/helsearbeidsgiver/tokenprovider/TokenClient.kt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,41 @@ | ||
package no.nav.helsearbeidsgiver.tokenprovider | ||
|
||
import io.ktor.client.HttpClient | ||
import io.ktor.client.call.body | ||
import io.ktor.client.plugins.ClientRequestException | ||
import io.ktor.client.request.forms.submitForm | ||
import io.ktor.http.parametersOf | ||
import kotlinx.coroutines.runBlocking | ||
import no.nav.helsearbeidsgiver.utils.log.logger | ||
import no.nav.helsearbeidsgiver.utils.log.sikkerLogger | ||
import no.nav.security.token.support.client.core.http.OAuth2HttpClient | ||
import no.nav.security.token.support.client.core.http.OAuth2HttpRequest | ||
import no.nav.security.token.support.client.core.oauth2.OAuth2AccessTokenResponse | ||
|
||
internal class TokenClient( | ||
private val httpClient: HttpClient, | ||
) : OAuth2HttpClient { | ||
private val logger = logger() | ||
private val sikkerLogger = sikkerLogger() | ||
|
||
override fun post(req: OAuth2HttpRequest): OAuth2AccessTokenResponse = | ||
runBlocking { | ||
try { | ||
httpClient.submitForm( | ||
url = req.tokenEndpointUrl.toString(), | ||
formParameters = | ||
req.formParameters | ||
.mapValues { listOf(it.value) } | ||
.let(::parametersOf), | ||
).body<OAuth2AccessTokenResponse>() | ||
} catch (e: Exception) { | ||
if (e is ClientRequestException) { | ||
"Noe gikk galt under henting av av OAuth2-token.".also { | ||
logger.error(it) | ||
sikkerLogger.error("$it. Error response: ${e.response.body<String>()}") | ||
} | ||
} | ||
throw e | ||
} | ||
} | ||
} |
13 changes: 0 additions & 13 deletions
13
src/main/kotlin/no/nav/helsearbeidsgiver/tokenprovider/TokenResolver.kt
This file was deleted.
Oops, something went wrong.
Oops, something went wrong.