Skip to content

Commit 099c00e

Browse files
author
lijianguo
committed
chore(oauth): using passport authentication
1 parent 8f9bef7 commit 099c00e

3 files changed

Lines changed: 11 additions & 9 deletions

File tree

charts/controller/templates/_helpers.tpl

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -156,8 +156,10 @@ env:
156156
{{- end }}
157157
{{- if eq .Values.global.passport_location "on-cluster"}}
158158
- name: "DRYCC_PASSPORT_DOMAIN"
159-
value: drycc-passport.{{ .Values.global.platform_domain }}
159+
value: http://drycc-passport.{{ .Values.global.platform_domain }}
160160
- name: "SOCIAL_AUTH_DRYCC_AUTHORIZATION_URL"
161+
value: "$(DRYCC_PASSPORT_DOMAIN)/oauth/authorize/"
162+
- name: "SOCIAL_AUTH_DRYCC_ACCESS_TOKEN_URL"
161163
value: "$(DRYCC_PASSPORT_DOMAIN)/oauth/token/"
162164
- name: "SOCIAL_AUTH_DRYCC_ACCESS_API_URL"
163165
value: "$(DRYCC_PASSPORT_DOMAIN)/users/"
@@ -167,6 +169,8 @@ env:
167169
value: "$(DRYCC_PASSPORT_DOMAIN)/oauth/.well-known/jwks.json"
168170
- name: "SOCIAL_AUTH_DRYCC_OIDC_ENDPOINT"
169171
value: "$(DRYCC_PASSPORT_DOMAIN)/oauth"
172+
- name: "LOGIN_REDIRECT_URL"
173+
value: "$(DRYCC_PASSPORT_DOMAIN)/login/done/"
170174
- name: SOCIAL_AUTH_DRYCC_CONTROLLER_KEY
171175
valueFrom:
172176
secretKeyRef:

charts/controller/templates/controller-cronjob-hourly.yaml

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
apiVersion: batch/v1beta1
22
kind: CronJob
33
metadata:
4-
name: drycc-controller-cronjob-daily
4+
name: drycc-controller-cronjob-hourly
55
labels:
66
heritage: drycc
77
annotations:
@@ -27,5 +27,3 @@ spec:
2727
args:
2828
- python -u /app/manage.py measure_app
2929
{{- include "controller.envs" . | indent 12 }}
30-
{{- include "controller.volumeMounts" . | indent 12 }}
31-
{{- include "controller.volumes" . | indent 10 }}

rootfs/api/settings/production.py

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -81,7 +81,7 @@
8181
'corsheaders.middleware.CorsMiddleware',
8282
'django.middleware.security.SecurityMiddleware',
8383
'django.middleware.clickjacking.XFrameOptionsMiddleware',
84-
'django.middleware.csrf.CsrfViewMiddleware',
84+
# 'django.middleware.csrf.CsrfViewMiddleware',
8585
'django.contrib.sessions.middleware.SessionMiddleware',
8686
'django.middleware.common.CommonMiddleware',
8787
'django.contrib.auth.middleware.AuthenticationMiddleware',
@@ -430,11 +430,11 @@
430430
SOCIAL_AUTH_DRYCC_AUTHORIZATION_URL = os.environ.get('SOCIAL_AUTH_DRYCC_AUTHORIZATION_URL')
431431
SOCIAL_AUTH_DRYCC_ACCESS_TOKEN_URL = os.environ.get('SOCIAL_AUTH_DRYCC_ACCESS_TOKEN_URL')
432432
SOCIAL_AUTH_DRYCC_ACCESS_API_URL = os.environ.get('SOCIAL_AUTH_DRYCC_ACCESS_API_URL')
433-
SOCIAL_AUTH_DRYCC_USERINFO_URL = os.environ.get('SOCIAL_AUTH_DRYCC_ACCESS_TOKEN_URL')
434-
SOCIAL_AUTH_DRYCC_JWKS_URI = os.environ.get('SOCIAL_AUTH_DRYCC_ACCESS_API_URL')
433+
SOCIAL_AUTH_DRYCC_USERINFO_URL = os.environ.get('SOCIAL_AUTH_DRYCC_USERINFO_URL')
434+
SOCIAL_AUTH_DRYCC_JWKS_URI = os.environ.get('SOCIAL_AUTH_DRYCC_JWKS_URI')
435435
SOCIAL_AUTH_DRYCC_OIDC_ENDPOINT = os.environ.get('SOCIAL_AUTH_DRYCC_OIDC_ENDPOINT')
436-
SOCIAL_AUTH_DRYCC_KEY = os.environ.get('SOCIAL_AUTH_DRYCC_KEY')
437-
SOCIAL_AUTH_DRYCC_SECRET = os.environ.get('SOCIAL_AUTH_DRYCC_SECRET')
436+
SOCIAL_AUTH_DRYCC_KEY = os.environ.get('SOCIAL_AUTH_DRYCC_CONTROLLER_KEY')
437+
SOCIAL_AUTH_DRYCC_SECRET = os.environ.get('SOCIAL_AUTH_DRYCC_CONTROLLER_SECRET')
438438
SOCIAL_AUTH_POSTGRES_JSONFIELD = True
439439
SOCIAL_AUTH_PIPELINE = (
440440
'social_core.pipeline.social_auth.social_details',

0 commit comments

Comments
 (0)