From a8f61b862f0649e157d2cb91a9bb93a33f6b162c Mon Sep 17 00:00:00 2001 From: Timothy Jaeryang Baek Date: Mon, 8 Sep 2025 18:35:00 +0400 Subject: [PATCH] feat: get system oauth token --- servers/get-oauth-tokens/.dockerignore | 34 +++++++++++++++ servers/get-oauth-tokens/Dockerfile | 51 +++++++++++++++++++++++ servers/get-oauth-tokens/README.md | 44 +++++++++++++++++++ servers/get-oauth-tokens/compose.yaml | 7 ++++ servers/get-oauth-tokens/main.py | 48 +++++++++++++++++++++ servers/get-oauth-tokens/requirements.txt | 6 +++ 6 files changed, 190 insertions(+) create mode 100644 servers/get-oauth-tokens/.dockerignore create mode 100644 servers/get-oauth-tokens/Dockerfile create mode 100644 servers/get-oauth-tokens/README.md create mode 100644 servers/get-oauth-tokens/compose.yaml create mode 100644 servers/get-oauth-tokens/main.py create mode 100644 servers/get-oauth-tokens/requirements.txt diff --git a/servers/get-oauth-tokens/.dockerignore b/servers/get-oauth-tokens/.dockerignore new file mode 100644 index 0000000..03a268b --- /dev/null +++ b/servers/get-oauth-tokens/.dockerignore @@ -0,0 +1,34 @@ +# Include any files or directories that you don't want to be copied to your +# container here (e.g., local build artifacts, temporary files, etc.). +# +# For more help, visit the .dockerignore file reference guide at +# https://docs.docker.com/go/build-context-dockerignore/ + +**/.DS_Store +**/__pycache__ +**/.venv +**/.classpath +**/.dockerignore +**/.env +**/.git +**/.gitignore +**/.project +**/.settings +**/.toolstarget +**/.vs +**/.vscode +**/*.*proj.user +**/*.dbmdl +**/*.jfm +**/bin +**/charts +**/docker-compose* +**/compose.y*ml +**/Dockerfile* +**/node_modules +**/npm-debug.log +**/obj +**/secrets.dev.yaml +**/values.dev.yaml +LICENSE +README.md diff --git a/servers/get-oauth-tokens/Dockerfile b/servers/get-oauth-tokens/Dockerfile new file mode 100644 index 0000000..e91fca9 --- /dev/null +++ b/servers/get-oauth-tokens/Dockerfile @@ -0,0 +1,51 @@ +# syntax=docker/dockerfile:1 + +# Comments are provided throughout this file to help you get started. +# If you need more help, visit the Dockerfile reference guide at +# https://docs.docker.com/go/dockerfile-reference/ + +# Want to help us make this template better? Share your feedback here: https://forms.gle/ybq9Krt8jtBL3iCk7 + +ARG PYTHON_VERSION=3.10.12 +FROM python:${PYTHON_VERSION}-slim as base + +# Prevents Python from writing pyc files. +ENV PYTHONDONTWRITEBYTECODE=1 + +# Keeps Python from buffering stdout and stderr to avoid situations where +# the application crashes without emitting any logs due to buffering. +ENV PYTHONUNBUFFERED=1 + +WORKDIR /app + +# Create a non-privileged user that the app will run under. +# See https://docs.docker.com/go/dockerfile-user-best-practices/ +ARG UID=10001 +RUN adduser \ + --disabled-password \ + --gecos "" \ + --home "/nonexistent" \ + --shell "/sbin/nologin" \ + --no-create-home \ + --uid "${UID}" \ + appuser + +# Download dependencies as a separate step to take advantage of Docker's caching. +# Leverage a cache mount to /root/.cache/pip to speed up subsequent builds. +# Leverage a bind mount to requirements.txt to avoid having to copy them into +# into this layer. +RUN --mount=type=cache,target=/root/.cache/pip \ + --mount=type=bind,source=requirements.txt,target=requirements.txt \ + python -m pip install -r requirements.txt + +# Switch to the non-privileged user to run the application. +USER appuser + +# Copy the source code into the container. +COPY . . + +# Expose the port that the application listens on. +EXPOSE 8000 + +# Run the application. +CMD uvicorn 'main:app' --host=0.0.0.0 --port=8000 diff --git a/servers/get-oauth-tokens/README.md b/servers/get-oauth-tokens/README.md new file mode 100644 index 0000000..059ae78 --- /dev/null +++ b/servers/get-oauth-tokens/README.md @@ -0,0 +1,44 @@ +# ๐Ÿ” Token Extractor API + +A simple FastAPI service that extracts `oauth_id_token` and `oauth_access_token` from cookies. + +## ๐Ÿš€ Features + +- ๐Ÿ”‘ Parses cookies for SSO tokens from Open WebUI +- ๐Ÿ“ค Returns the extracted tokens as JSON + +## ๐Ÿ“ฆ Endpoint + +### GET /tokens + +Reads cookies and returns: + +```json +{ + "oauth_id_token": "string or null", + "oauth_access_token": "string or null" +} +``` + +## โš™๏ธ Setup + +Make sure your SSO is configured in Open WebUI and the cookies `oauth_id_token` and `oauth_access_token` are set in the client. + +Run the service: + +```bash +uvicorn main:app --host 0.0.0.0 --reload +``` + +## ๐Ÿฟ Example + +```bash +curl --cookie "oauth_id_token=xxx; oauth_access_token=yyy" http://localhost:8000/tokens +``` + +## ๐Ÿงช Tech Stack + +- Python 3.11+ +- FastAPI โšก + +Made with โค๏ธ by Open WebUI team. \ No newline at end of file diff --git a/servers/get-oauth-tokens/compose.yaml b/servers/get-oauth-tokens/compose.yaml new file mode 100644 index 0000000..9fc4d98 --- /dev/null +++ b/servers/get-oauth-tokens/compose.yaml @@ -0,0 +1,7 @@ +services: + server: + build: + context: . + ports: + - 8000:8000 + diff --git a/servers/get-oauth-tokens/main.py b/servers/get-oauth-tokens/main.py new file mode 100644 index 0000000..7552260 --- /dev/null +++ b/servers/get-oauth-tokens/main.py @@ -0,0 +1,48 @@ +from fastapi import FastAPI, HTTPException, Request +from fastapi.middleware.cors import CORSMiddleware +import os + +app = FastAPI( + title="Token Extractor API", + version="1.0.0", + description="Extract oauth_id_token and oauth_access_token from cookies.", +) + +app.add_middleware( + CORSMiddleware, + allow_origins=["*"], # You may restrict this to certain domains + allow_credentials=True, + allow_methods=["*"], + allow_headers=["*"], +) + + +@app.get( + "/tokens", + summary="Extract oauth tokens from cookies", + description="Parse cookies and return oauth_id_token and oauth_access_token.", +) +async def get_oauth_tokens(request: Request): + cookies = request.cookies + print(cookies) + + headers = request.headers + print(headers) + + oauth_id_token = cookies.get("oauth_id_token") + oauth_access_token = None + + auth_header = headers.get("Authorization") + if token := auth_header.split(" ")[1]: + oauth_access_token = token + + if oauth_id_token is None and oauth_access_token is None: + raise HTTPException( + status_code=401, + detail="Missing oauth_id_token cookie and oauth_access_token header", + ) + + return { + "oauth_id_token": oauth_id_token, + "oauth_access_token": oauth_access_token, + } diff --git a/servers/get-oauth-tokens/requirements.txt b/servers/get-oauth-tokens/requirements.txt new file mode 100644 index 0000000..4d03492 --- /dev/null +++ b/servers/get-oauth-tokens/requirements.txt @@ -0,0 +1,6 @@ +fastapi +uvicorn[standard] +pydantic +python-multipart + +aiohttp \ No newline at end of file