2016-06-23 08:29:44 -04:00
|
|
|
package providers
|
|
|
|
|
|
|
|
import (
|
2020-05-06 00:53:33 +09:00
|
|
|
"context"
|
2016-06-23 08:29:44 -04:00
|
|
|
"errors"
|
|
|
|
"net/url"
|
|
|
|
|
2020-03-29 14:54:36 +01:00
|
|
|
"github.com/oauth2-proxy/oauth2-proxy/pkg/apis/sessions"
|
|
|
|
"github.com/oauth2-proxy/oauth2-proxy/pkg/requests"
|
2016-06-23 08:29:44 -04:00
|
|
|
)
|
|
|
|
|
2018-12-20 10:37:59 +00:00
|
|
|
// FacebookProvider represents an Facebook based Identity Provider
|
2016-06-23 08:29:44 -04:00
|
|
|
type FacebookProvider struct {
|
|
|
|
*ProviderData
|
|
|
|
}
|
|
|
|
|
2020-05-06 00:53:33 +09:00
|
|
|
var _ Provider = (*FacebookProvider)(nil)
|
|
|
|
|
2020-05-25 13:08:04 +01:00
|
|
|
const (
|
|
|
|
facebookProviderName = "Facebook"
|
|
|
|
facebookDefaultScope = "public_profile email"
|
|
|
|
)
|
|
|
|
|
|
|
|
var (
|
|
|
|
// Default Login URL for Facebook.
|
|
|
|
// Pre-parsed URL of https://www.facebook.com/v2.5/dialog/oauth.
|
|
|
|
facebookDefaultLoginURL = &url.URL{
|
|
|
|
Scheme: "https",
|
|
|
|
Host: "www.facebook.com",
|
|
|
|
Path: "/v2.5/dialog/oauth",
|
|
|
|
// ?granted_scopes=true
|
2016-06-23 08:29:44 -04:00
|
|
|
}
|
2020-05-25 13:08:04 +01:00
|
|
|
|
|
|
|
// Default Redeem URL for Facebook.
|
|
|
|
// Pre-parsed URL of https://graph.facebook.com/v2.5/oauth/access_token.
|
|
|
|
facebookDefaultRedeemURL = &url.URL{
|
|
|
|
Scheme: "https",
|
|
|
|
Host: "graph.facebook.com",
|
|
|
|
Path: "/v2.5/oauth/access_token",
|
2016-06-23 08:29:44 -04:00
|
|
|
}
|
2020-05-25 13:08:04 +01:00
|
|
|
|
|
|
|
// Default Profile URL for Facebook.
|
|
|
|
// Pre-parsed URL of https://graph.facebook.com/v2.5/me.
|
|
|
|
facebookDefaultProfileURL = &url.URL{
|
|
|
|
Scheme: "https",
|
|
|
|
Host: "graph.facebook.com",
|
|
|
|
Path: "/v2.5/me",
|
2016-06-23 08:29:44 -04:00
|
|
|
}
|
2020-05-25 13:08:04 +01:00
|
|
|
)
|
|
|
|
|
|
|
|
// NewFacebookProvider initiates a new FacebookProvider
|
|
|
|
func NewFacebookProvider(p *ProviderData) *FacebookProvider {
|
|
|
|
p.setProviderDefaults(providerDefaults{
|
|
|
|
name: facebookProviderName,
|
|
|
|
loginURL: facebookDefaultLoginURL,
|
|
|
|
redeemURL: facebookDefaultRedeemURL,
|
|
|
|
profileURL: facebookDefaultProfileURL,
|
|
|
|
validateURL: facebookDefaultProfileURL,
|
|
|
|
scope: facebookDefaultScope,
|
|
|
|
})
|
2016-06-23 08:29:44 -04:00
|
|
|
return &FacebookProvider{ProviderData: p}
|
|
|
|
}
|
|
|
|
|
2018-12-20 10:37:59 +00:00
|
|
|
// GetEmailAddress returns the Account email address
|
2020-05-06 00:53:33 +09:00
|
|
|
func (p *FacebookProvider) GetEmailAddress(ctx context.Context, s *sessions.SessionState) (string, error) {
|
2016-06-23 08:29:44 -04:00
|
|
|
if s.AccessToken == "" {
|
|
|
|
return "", errors.New("missing access token")
|
|
|
|
}
|
|
|
|
|
|
|
|
type result struct {
|
|
|
|
Email string
|
|
|
|
}
|
|
|
|
var r result
|
2020-07-03 19:27:25 +01:00
|
|
|
|
|
|
|
requestURL := p.ProfileURL.String() + "?fields=name,email"
|
|
|
|
err := requests.New(requestURL).
|
|
|
|
WithContext(ctx).
|
2020-05-17 16:34:09 +01:00
|
|
|
WithHeaders(makeOIDCHeader(s.AccessToken)).
|
2020-07-06 17:42:26 +01:00
|
|
|
Do().
|
2020-07-03 19:27:25 +01:00
|
|
|
UnmarshalInto(&r)
|
2016-06-23 08:29:44 -04:00
|
|
|
if err != nil {
|
|
|
|
return "", err
|
|
|
|
}
|
2020-07-03 19:27:25 +01:00
|
|
|
|
2016-06-23 08:29:44 -04:00
|
|
|
if r.Email == "" {
|
|
|
|
return "", errors.New("no email")
|
|
|
|
}
|
|
|
|
return r.Email, nil
|
|
|
|
}
|
|
|
|
|
2018-12-20 10:37:59 +00:00
|
|
|
// ValidateSessionState validates the AccessToken
|
2020-05-06 00:53:33 +09:00
|
|
|
func (p *FacebookProvider) ValidateSessionState(ctx context.Context, s *sessions.SessionState) bool {
|
2020-05-17 16:34:09 +01:00
|
|
|
return validateToken(ctx, p, s.AccessToken, makeOIDCHeader(s.AccessToken))
|
2016-06-23 08:29:44 -04:00
|
|
|
}
|