feat: get system oauth token
This commit is contained in:
@@ -0,0 +1,34 @@
|
|||||||
|
# Include any files or directories that you don't want to be copied to your
|
||||||
|
# container here (e.g., local build artifacts, temporary files, etc.).
|
||||||
|
#
|
||||||
|
# For more help, visit the .dockerignore file reference guide at
|
||||||
|
# https://docs.docker.com/go/build-context-dockerignore/
|
||||||
|
|
||||||
|
**/.DS_Store
|
||||||
|
**/__pycache__
|
||||||
|
**/.venv
|
||||||
|
**/.classpath
|
||||||
|
**/.dockerignore
|
||||||
|
**/.env
|
||||||
|
**/.git
|
||||||
|
**/.gitignore
|
||||||
|
**/.project
|
||||||
|
**/.settings
|
||||||
|
**/.toolstarget
|
||||||
|
**/.vs
|
||||||
|
**/.vscode
|
||||||
|
**/*.*proj.user
|
||||||
|
**/*.dbmdl
|
||||||
|
**/*.jfm
|
||||||
|
**/bin
|
||||||
|
**/charts
|
||||||
|
**/docker-compose*
|
||||||
|
**/compose.y*ml
|
||||||
|
**/Dockerfile*
|
||||||
|
**/node_modules
|
||||||
|
**/npm-debug.log
|
||||||
|
**/obj
|
||||||
|
**/secrets.dev.yaml
|
||||||
|
**/values.dev.yaml
|
||||||
|
LICENSE
|
||||||
|
README.md
|
||||||
@@ -0,0 +1,51 @@
|
|||||||
|
# syntax=docker/dockerfile:1
|
||||||
|
|
||||||
|
# Comments are provided throughout this file to help you get started.
|
||||||
|
# If you need more help, visit the Dockerfile reference guide at
|
||||||
|
# https://docs.docker.com/go/dockerfile-reference/
|
||||||
|
|
||||||
|
# Want to help us make this template better? Share your feedback here: https://forms.gle/ybq9Krt8jtBL3iCk7
|
||||||
|
|
||||||
|
ARG PYTHON_VERSION=3.10.12
|
||||||
|
FROM python:${PYTHON_VERSION}-slim as base
|
||||||
|
|
||||||
|
# Prevents Python from writing pyc files.
|
||||||
|
ENV PYTHONDONTWRITEBYTECODE=1
|
||||||
|
|
||||||
|
# Keeps Python from buffering stdout and stderr to avoid situations where
|
||||||
|
# the application crashes without emitting any logs due to buffering.
|
||||||
|
ENV PYTHONUNBUFFERED=1
|
||||||
|
|
||||||
|
WORKDIR /app
|
||||||
|
|
||||||
|
# Create a non-privileged user that the app will run under.
|
||||||
|
# See https://docs.docker.com/go/dockerfile-user-best-practices/
|
||||||
|
ARG UID=10001
|
||||||
|
RUN adduser \
|
||||||
|
--disabled-password \
|
||||||
|
--gecos "" \
|
||||||
|
--home "/nonexistent" \
|
||||||
|
--shell "/sbin/nologin" \
|
||||||
|
--no-create-home \
|
||||||
|
--uid "${UID}" \
|
||||||
|
appuser
|
||||||
|
|
||||||
|
# Download dependencies as a separate step to take advantage of Docker's caching.
|
||||||
|
# Leverage a cache mount to /root/.cache/pip to speed up subsequent builds.
|
||||||
|
# Leverage a bind mount to requirements.txt to avoid having to copy them into
|
||||||
|
# into this layer.
|
||||||
|
RUN --mount=type=cache,target=/root/.cache/pip \
|
||||||
|
--mount=type=bind,source=requirements.txt,target=requirements.txt \
|
||||||
|
python -m pip install -r requirements.txt
|
||||||
|
|
||||||
|
# Switch to the non-privileged user to run the application.
|
||||||
|
USER appuser
|
||||||
|
|
||||||
|
# Copy the source code into the container.
|
||||||
|
COPY . .
|
||||||
|
|
||||||
|
# Expose the port that the application listens on.
|
||||||
|
EXPOSE 8000
|
||||||
|
|
||||||
|
# Run the application.
|
||||||
|
CMD uvicorn 'main:app' --host=0.0.0.0 --port=8000
|
||||||
@@ -0,0 +1,44 @@
|
|||||||
|
# 🔐 Token Extractor API
|
||||||
|
|
||||||
|
A simple FastAPI service that extracts `oauth_id_token` and `oauth_access_token` from cookies.
|
||||||
|
|
||||||
|
## 🚀 Features
|
||||||
|
|
||||||
|
- 🔑 Parses cookies for SSO tokens from Open WebUI
|
||||||
|
- 📤 Returns the extracted tokens as JSON
|
||||||
|
|
||||||
|
## 📦 Endpoint
|
||||||
|
|
||||||
|
### GET /tokens
|
||||||
|
|
||||||
|
Reads cookies and returns:
|
||||||
|
|
||||||
|
```json
|
||||||
|
{
|
||||||
|
"oauth_id_token": "string or null",
|
||||||
|
"oauth_access_token": "string or null"
|
||||||
|
}
|
||||||
|
```
|
||||||
|
|
||||||
|
## ⚙️ Setup
|
||||||
|
|
||||||
|
Make sure your SSO is configured in Open WebUI and the cookies `oauth_id_token` and `oauth_access_token` are set in the client.
|
||||||
|
|
||||||
|
Run the service:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
uvicorn main:app --host 0.0.0.0 --reload
|
||||||
|
```
|
||||||
|
|
||||||
|
## 🍿 Example
|
||||||
|
|
||||||
|
```bash
|
||||||
|
curl --cookie "oauth_id_token=xxx; oauth_access_token=yyy" http://localhost:8000/tokens
|
||||||
|
```
|
||||||
|
|
||||||
|
## 🧪 Tech Stack
|
||||||
|
|
||||||
|
- Python 3.11+
|
||||||
|
- FastAPI ⚡
|
||||||
|
|
||||||
|
Made with ❤️ by Open WebUI team.
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
services:
|
||||||
|
server:
|
||||||
|
build:
|
||||||
|
context: .
|
||||||
|
ports:
|
||||||
|
- 8000:8000
|
||||||
|
|
||||||
@@ -0,0 +1,48 @@
|
|||||||
|
from fastapi import FastAPI, HTTPException, Request
|
||||||
|
from fastapi.middleware.cors import CORSMiddleware
|
||||||
|
import os
|
||||||
|
|
||||||
|
app = FastAPI(
|
||||||
|
title="Token Extractor API",
|
||||||
|
version="1.0.0",
|
||||||
|
description="Extract oauth_id_token and oauth_access_token from cookies.",
|
||||||
|
)
|
||||||
|
|
||||||
|
app.add_middleware(
|
||||||
|
CORSMiddleware,
|
||||||
|
allow_origins=["*"], # You may restrict this to certain domains
|
||||||
|
allow_credentials=True,
|
||||||
|
allow_methods=["*"],
|
||||||
|
allow_headers=["*"],
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
|
@app.get(
|
||||||
|
"/tokens",
|
||||||
|
summary="Extract oauth tokens from cookies",
|
||||||
|
description="Parse cookies and return oauth_id_token and oauth_access_token.",
|
||||||
|
)
|
||||||
|
async def get_oauth_tokens(request: Request):
|
||||||
|
cookies = request.cookies
|
||||||
|
print(cookies)
|
||||||
|
|
||||||
|
headers = request.headers
|
||||||
|
print(headers)
|
||||||
|
|
||||||
|
oauth_id_token = cookies.get("oauth_id_token")
|
||||||
|
oauth_access_token = None
|
||||||
|
|
||||||
|
auth_header = headers.get("Authorization")
|
||||||
|
if token := auth_header.split(" ")[1]:
|
||||||
|
oauth_access_token = token
|
||||||
|
|
||||||
|
if oauth_id_token is None and oauth_access_token is None:
|
||||||
|
raise HTTPException(
|
||||||
|
status_code=401,
|
||||||
|
detail="Missing oauth_id_token cookie and oauth_access_token header",
|
||||||
|
)
|
||||||
|
|
||||||
|
return {
|
||||||
|
"oauth_id_token": oauth_id_token,
|
||||||
|
"oauth_access_token": oauth_access_token,
|
||||||
|
}
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
fastapi
|
||||||
|
uvicorn[standard]
|
||||||
|
pydantic
|
||||||
|
python-multipart
|
||||||
|
|
||||||
|
aiohttp
|
||||||
Reference in New Issue
Block a user