-
Notifications
You must be signed in to change notification settings - Fork 2
/
oidc_server.js
74 lines (62 loc) · 2.16 KB
/
oidc_server.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
OIDC = {};
Accounts.oauth.registerService('oidc');
OAuth.registerService('oidc', 2, null, function(query) {
var accessToken = getAccessToken(query);
var identity = getIdentity(accessToken);
return {
serviceData: {
id: identity.email,
accessToken: accessToken
},
options: { profile: { name: identity.email } }
};
});
Accounts.addAutopublishFields({
forLoggedInUser: ['services.oidc'],
forOtherUsers: ['services.oidc.id']
});
var getAccessToken = function (query) {
var config = ServiceConfiguration.configurations.findOne({ service: 'oidc' });
if (!config) {
throw new ServiceConfiguration.ConfigError();
}
var response;
try {
response = HTTP.post(config.tokenEndpoint, {
params: {
code: query.code,
client_id: config.clientId,
client_secret: OAuth.openSecret(config.secret),
grant_type: 'authorization_code',
redirect_uri: OAuth._redirectUri('oidc', config),
state: query.state
}
});
} catch (err) {
throw _.extend(new Error("Failed to complete OpenID Connect handshake with your provider. " + err.message), { response: err.response });
}
if (response.data.error) {
throw new Error("Failed to complete OpenID Connect handshake with your provider. " + response.data.error);
} else {
return response.data.access_token;
}
};
var getIdentity = function (accessToken) {
var config = ServiceConfiguration.configurations.findOne({ service: 'oidc' });
if (!config) {
throw new ServiceConfiguration.ConfigError();
}
try {
var response = HTTP.get(config.userinfoEndpoint, {
params: {
access_token: accessToken
}
});
return response.data;
} catch (err) {
throw _.extend(new Error("Failed to fetch identity from your provider. " + err.message), { response: err.response });
}
};
OIDC.retrieveCredential = function(credentialToken, credentialSecret) {
return OAuth.retrieveCredential(credentialToken, credentialSecret);
};