feat: access token & new endpoints (/login, /userinfo, /v2/logout) #14
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Issue Item:
Description:
1. access token
access_tokensent by the IdP.access_tokenin the k/v store as same as we storeid_tokenandrefresh_token2. new endpoints
Add
/userinfoendpoint:$oidc_userinfo_endpointas same as authz and token endpoints here (openid_connect_configuration.conf) ./userinfoendpoint here(openid_connect.server_conf) in a location block of NGINX Plus to interact with IdP'suserinfo_endpointwhich is defined in the endpoint ofwell-known/openid-configuration.userinfo_endpointby addingaccess_tokenas a bearer token.Expose
/loginendpoint:/loginendpoint as a location block here (openid_connect.server_conf)authorization_endpointconfigured in the map variable of$oidc_authz_endpointin (openid_connect_configuration.conf).Expose
/v2/logoutendpoint:/v2/logoutendpoint as a location block here (openid_connect.server_conf)$oidc_end_session_endpointas same as authz and token endpoints here (openid_connect_configuration.conf) .end_session_endpointto finish the session by IdP.Expose
/v2/_logoutendpoint:/v2/_logoutendpoint which is a callback from IdP as a location block here (openid_connect.server_conf) to handle the following sequences.$post_logout_return_uri: After the successful logout from the IdP, NGINX Plus calls this URI to redirect to either the original page or a custom logout page. The default is original page based on the configuration of$redirect_base.3. add endpoints in
configure.shCompatibility: