Business
Jobs
  • About Us
  • Solutions
    • Job Postings
      Post your job and receive qualified candidates in 48h.
    • Candidate Assessments
      500+ technical and psychological tests, plus anti-fraud.
    • Headhunting
      Tailor-made executive search from start to finish.
    • Payroll + EOR
      Payroll dispersal and EOR across 15+ LATAM countries.
  • Pricing
  • Jobs

0

263
Views
Nginx Ingress pasa la URL completa al proxy Oauth como redirección

Estoy ejecutando un Kubernetes Cluster con un par de aplicaciones web de Nginx-ingress. Debido a que Nginx no es compatible con SSO/OIDC de forma predeterminada, utilizo un oauth_proxy para la autenticación.

En detalle, uso oauth2_proxy ( https://github.com/pusher/oauth2_proxy ) con Azure AD.

 apiVersion: extensions/v1beta1 kind: Ingress metadata: name: nginx-ingress-internal namespace: ingress-nginx annotations: nginx.ingress.kubernetes.io/rewrite-target: /$2 nginx.ingress.kubernetes.io/auth-url: "https://example.com/oauth2/auth" nginx.ingress.kubernetes.io/auth-signin: "https://example.com/oauth2/start?rd=$escaped_request_uri" nginx.ingress.kubernetes.io/auth-response-headers: "authorization, x-auth-request-user, x-auth-request-email, x_auth_request_access_token" spec: rules: - host: example.com http: paths: - path: /home(/|$)(.*) backend: serviceName: app-homepage-frontend-service servicePort: 80 - path: /homepage-backend(/|$)(.*) backend: serviceName: app-homepage-backend-service servicePort: 80

Me salté algunos detalles como tls. Entonces, en general, todo funciona, solo los usuarios verificados pueden acceder a las páginas web.

El problema es que mi interfaz está escrita en Angular que usa enrutamiento hash. Y si intenta entrar en una ruta profunda como

https://example.com/home/#/page1/subpage2

solo la ruta base (/ home) se pasa como URL de redirección. Entonces, cuando estoy autorizado con éxito, me redirigen a https://example.com/home .

¿Hay algún veriable en lugar de $ escaped_request_uri, que pase la URL completa?

over 4 years ago · Santiago Trujillo
1 answers
Answer question

0

¡Intente con el siguiente proceso, podría ser útil!

  • Agregar parámetro de estado ayudará a oauth2_proxy

Parámetro de estado

El parámetro de estado reservará el estado anterior a la solicitud de autenticación y pasará el valor de estado generado aleatoriamente en la solicitud de autenticación y en la solicitud de devolución de llamada agregarán el estado, es decir, la identificación generada por Oauth2_Proxy. Luego, Oauth2_Proxy leerá esa ID y proporcionará la URL y responderá.

Use el siguiente enlace

https://dev.bitly.com/v4_documentation.html

Bitly Oauth2_Proxy agregó lo mismo en el código.

https://github.com/bitly/oauth2_proxy/blob/master/providers/provider_default.go#L87-L89

over 4 years ago · Santiago Trujillo Report
Answer question
Find remote jobs

Discover the new way to find a job!

Top jobs
Top job categories
Business
Post vacancy Pricing Sales
Legal
Terms and conditions Privacy policy
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Show me some job opportunities
There's an error!