2020-04-14 22:29:11 +02:00
|
|
|
/* eslint-disable import/no-extraneous-dependencies */
|
|
|
|
|
2018-01-04 15:48:48 +01:00
|
|
|
'use strict';
|
|
|
|
|
|
|
|
/**
|
2020-03-17 17:05:18 +01:00
|
|
|
* Google OAuth 2.0
|
2018-01-04 15:48:48 +01:00
|
|
|
*
|
|
|
|
* You should read Using OAuth 2.0 to Access Google APIs:
|
|
|
|
* https://developers.google.com/identity/protocols/OAuth2
|
|
|
|
*
|
|
|
|
* This example assumes that all users authenticating via
|
2020-03-17 17:05:18 +01:00
|
|
|
* google should have access. You would probably limit access
|
2018-01-04 15:48:48 +01:00
|
|
|
* to users you trust.
|
|
|
|
*
|
2020-03-17 17:05:18 +01:00
|
|
|
* The implementation assumes the following environment variables:
|
2018-01-04 15:48:48 +01:00
|
|
|
*
|
|
|
|
* - GOOGLE_CLIENT_ID
|
|
|
|
* - GOOGLE_CLIENT_SECRET
|
|
|
|
* - GOOGLE_CALLBACK_URL
|
|
|
|
*/
|
|
|
|
|
2019-02-01 16:13:16 +01:00
|
|
|
const passport = require('@passport-next/passport');
|
|
|
|
const GoogleOAuth2Strategy = require('@passport-next/passport-google-oauth2')
|
|
|
|
.Strategy;
|
2018-01-04 15:48:48 +01:00
|
|
|
|
2020-04-14 22:29:11 +02:00
|
|
|
// const { User, AuthenticationRequired } = require('unleash-server');
|
2021-02-12 11:42:00 +01:00
|
|
|
const { User, AuthenticationRequired } = require('../dist/lib/server-impl.js');
|
2020-04-14 22:29:11 +02:00
|
|
|
|
2018-01-04 15:48:48 +01:00
|
|
|
passport.use(
|
|
|
|
new GoogleOAuth2Strategy(
|
|
|
|
{
|
2019-02-01 16:13:16 +01:00
|
|
|
clientID: process.env.GOOGLE_CLIENT_ID,
|
2018-01-04 15:48:48 +01:00
|
|
|
clientSecret: process.env.GOOGLE_CLIENT_SECRET,
|
|
|
|
callbackURL: process.env.GOOGLE_CALLBACK_URL,
|
|
|
|
},
|
|
|
|
|
|
|
|
(accessToken, refreshToken, profile, done) => {
|
|
|
|
done(
|
|
|
|
null,
|
|
|
|
new User({
|
|
|
|
name: profile.displayName,
|
|
|
|
email: profile.emails[0].value,
|
2020-04-14 22:29:11 +02:00
|
|
|
}),
|
2018-01-04 15:48:48 +01:00
|
|
|
);
|
2020-04-14 22:29:11 +02:00
|
|
|
},
|
|
|
|
),
|
2018-01-04 15:48:48 +01:00
|
|
|
);
|
|
|
|
|
|
|
|
function enableGoogleOauth(app) {
|
|
|
|
app.use(passport.initialize());
|
|
|
|
app.use(passport.session());
|
|
|
|
|
|
|
|
passport.serializeUser((user, done) => done(null, user));
|
|
|
|
passport.deserializeUser((user, done) => done(null, user));
|
2019-02-01 16:13:16 +01:00
|
|
|
app.get(
|
|
|
|
'/api/admin/login',
|
2020-04-14 22:29:11 +02:00
|
|
|
passport.authenticate('google', { scope: ['email'] }),
|
2019-02-01 16:13:16 +01:00
|
|
|
);
|
2018-01-04 15:48:48 +01:00
|
|
|
|
|
|
|
app.get(
|
|
|
|
'/api/auth/callback',
|
|
|
|
passport.authenticate('google', {
|
|
|
|
failureRedirect: '/api/admin/error-login',
|
|
|
|
}),
|
|
|
|
(req, res) => {
|
|
|
|
// Successful authentication, redirect to your app.
|
|
|
|
res.redirect('/');
|
2020-04-14 22:29:11 +02:00
|
|
|
},
|
2018-01-04 15:48:48 +01:00
|
|
|
);
|
|
|
|
|
|
|
|
app.use('/api/admin/', (req, res, next) => {
|
|
|
|
if (req.user) {
|
2020-04-14 22:29:11 +02:00
|
|
|
return next();
|
2018-01-04 15:48:48 +01:00
|
|
|
}
|
2020-04-14 22:29:11 +02:00
|
|
|
// Instruct unleash-frontend to pop-up auth dialog
|
|
|
|
return res
|
|
|
|
.status('401')
|
|
|
|
.json(
|
|
|
|
new AuthenticationRequired({
|
|
|
|
path: '/api/admin/login',
|
|
|
|
type: 'custom',
|
|
|
|
message: `You have to identify yourself in order to use Unleash.
|
|
|
|
Click the button and follow the instructions.`,
|
|
|
|
}),
|
|
|
|
)
|
|
|
|
.end();
|
2018-01-04 15:48:48 +01:00
|
|
|
});
|
|
|
|
}
|
|
|
|
|
|
|
|
module.exports = enableGoogleOauth;
|