feat: get-tokens-from-cookies

This commit is contained in:
Timothy Jaeryang Baek
2025-09-01 11:51:46 +04:00
parent 5336f1f41e
commit 526027e639
6 changed files with 181 additions and 0 deletions
@@ -0,0 +1,34 @@
# Include any files or directories that you don't want to be copied to your
# container here (e.g., local build artifacts, temporary files, etc.).
#
# For more help, visit the .dockerignore file reference guide at
# https://docs.docker.com/go/build-context-dockerignore/
**/.DS_Store
**/__pycache__
**/.venv
**/.classpath
**/.dockerignore
**/.env
**/.git
**/.gitignore
**/.project
**/.settings
**/.toolstarget
**/.vs
**/.vscode
**/*.*proj.user
**/*.dbmdl
**/*.jfm
**/bin
**/charts
**/docker-compose*
**/compose.y*ml
**/Dockerfile*
**/node_modules
**/npm-debug.log
**/obj
**/secrets.dev.yaml
**/values.dev.yaml
LICENSE
README.md
@@ -0,0 +1,51 @@
# syntax=docker/dockerfile:1
# Comments are provided throughout this file to help you get started.
# If you need more help, visit the Dockerfile reference guide at
# https://docs.docker.com/go/dockerfile-reference/
# Want to help us make this template better? Share your feedback here: https://forms.gle/ybq9Krt8jtBL3iCk7
ARG PYTHON_VERSION=3.10.12
FROM python:${PYTHON_VERSION}-slim as base
# Prevents Python from writing pyc files.
ENV PYTHONDONTWRITEBYTECODE=1
# Keeps Python from buffering stdout and stderr to avoid situations where
# the application crashes without emitting any logs due to buffering.
ENV PYTHONUNBUFFERED=1
WORKDIR /app
# Create a non-privileged user that the app will run under.
# See https://docs.docker.com/go/dockerfile-user-best-practices/
ARG UID=10001
RUN adduser \
--disabled-password \
--gecos "" \
--home "/nonexistent" \
--shell "/sbin/nologin" \
--no-create-home \
--uid "${UID}" \
appuser
# Download dependencies as a separate step to take advantage of Docker's caching.
# Leverage a cache mount to /root/.cache/pip to speed up subsequent builds.
# Leverage a bind mount to requirements.txt to avoid having to copy them into
# into this layer.
RUN --mount=type=cache,target=/root/.cache/pip \
--mount=type=bind,source=requirements.txt,target=requirements.txt \
python -m pip install -r requirements.txt
# Switch to the non-privileged user to run the application.
USER appuser
# Copy the source code into the container.
COPY . .
# Expose the port that the application listens on.
EXPOSE 8000
# Run the application.
CMD uvicorn 'main:app' --host=0.0.0.0 --port=8000
+44
View File
@@ -0,0 +1,44 @@
# 🔐 Token Extractor API
A simple FastAPI service that extracts `oauth_id_token` and `oauth_access_token` from cookies.
## 🚀 Features
- 🔑 Parses cookies for SSO tokens from Open WebUI
- 📤 Returns the extracted tokens as JSON
## 📦 Endpoint
### GET /tokens
Reads cookies and returns:
```json
{
"oauth_id_token": "string or null",
"oauth_access_token": "string or null"
}
```
## ⚙️ Setup
Make sure your SSO is configured in Open WebUI and the cookies `oauth_id_token` and `oauth_access_token` are set in the client.
Run the service:
```bash
uvicorn main:app --host 0.0.0.0 --reload
```
## 🍿 Example
```bash
curl --cookie "oauth_id_token=xxx; oauth_access_token=yyy" http://localhost:8000/tokens
```
## 🧪 Tech Stack
- Python 3.11+
- FastAPI ⚡
Made with ❤️ by Open WebUI team.
@@ -0,0 +1,7 @@
services:
server:
build:
context: .
ports:
- 8000:8000
+39
View File
@@ -0,0 +1,39 @@
from fastapi import FastAPI, HTTPException, Request
from fastapi.middleware.cors import CORSMiddleware
import os
app = FastAPI(
title="Token Extractor API",
version="1.0.0",
description="Extract oauth_id_token and oauth_access_token from cookies.",
)
app.add_middleware(
CORSMiddleware,
allow_origins=["*"], # You may restrict this to certain domains
allow_credentials=True,
allow_methods=["*"],
allow_headers=["*"],
)
@app.get(
"/tokens",
summary="Extract oauth tokens from cookies",
description="Parse cookies and return oauth_id_token and oauth_access_token.",
)
async def get_oauth_tokens(request: Request):
cookies = request.cookies
oauth_id_token = cookies.get("oauth_id_token")
oauth_access_token = cookies.get("oauth_access_token")
if oauth_id_token is None and oauth_access_token is None:
raise HTTPException(
status_code=401,
detail="Missing oauth_id_token and oauth_access_token cookies",
)
return {
"oauth_id_token": oauth_id_token,
"oauth_access_token": oauth_access_token,
}
@@ -0,0 +1,6 @@
fastapi
uvicorn[standard]
pydantic
python-multipart
aiohttp