1
0
mirror of https://github.com/oauth2-proxy/oauth2-proxy.git synced 2025-01-24 05:26:55 +02:00
oauth2-proxy/contrib/oauth2_proxy.cfg.example

76 lines
2.7 KiB
Plaintext
Raw Normal View History

2015-05-26 09:18:03 -04:00
## OAuth2 Proxy Config File
## https://github.com/bitly/oauth2_proxy
2014-11-09 14:51:10 -05:00
2015-06-07 21:51:47 -04:00
## <addr>:<port> to listen on for HTTP/HTTPS clients
2014-11-09 14:51:10 -05:00
# http_address = "127.0.0.1:4180"
2015-06-07 21:51:47 -04:00
# https_address = ":443"
## TLS Settings
# tls_cert_file = ""
# tls_key_file = ""
2014-11-09 14:51:10 -05:00
## the OAuth Redirect URL.
2015-03-17 16:25:19 -04:00
# defaults to the "https://" + requested host header + "/oauth2/callback"
2014-11-09 14:51:10 -05:00
# redirect_url = "https://internalapp.yourcompany.com/oauth2/callback"
## the http url(s) of the upstream endpoint. If multiple, routing is based on path
# upstreams = [
# "http://127.0.0.1:8080/"
# ]
## Log requests to stdout
# request_logging = true
2014-11-09 14:51:10 -05:00
## pass HTTP Basic Auth, X-Forwarded-User and X-Forwarded-Email information to upstream
# pass_basic_auth = true
2015-03-17 15:15:15 -04:00
## pass the request Host Header to upstream
## when disabled the upstream Host is used as the Host Header
# pass_host_header = true
2014-11-09 14:51:10 -05:00
## Email Domains to allow authentication for (this authorizes any email on this domain)
## for more granular authorization use `authenticated_emails_file`
## To authorize any email addresses use "*"
# email_domains = [
2014-11-09 14:51:10 -05:00
# "yourcompany.com"
# ]
2015-05-26 09:18:03 -04:00
## The OAuth Client ID, Secret
2014-11-09 14:51:10 -05:00
# client_id = "123456.apps.googleusercontent.com"
# client_secret = ""
2015-05-26 09:18:03 -04:00
## Pass OAuth Access token to upstream via "X-Forwarded-Access-Token"
# pass_access_token = false
2014-11-09 14:51:10 -05:00
## Authenticated Email Addresses File (one email per line)
# authenticated_emails_file = ""
## Htpasswd File (optional)
## Additionally authenticate against a htpasswd file. Entries must be created with "htpasswd -s" for SHA encryption
## enabling exposes a username/login signin form
# htpasswd_file = ""
2015-03-17 18:06:06 -04:00
## Templates
## optional directory with custom sign_in.html and error.html
# custom_templates_dir = ""
2014-11-09 14:51:10 -05:00
## Cookie Settings
## Name - the cookie name
## Secret - the seed string for secure cookies; should be 16, 24, or 32 bytes
## for use with an AES cipher when cookie_refresh or pass_access_token
## is set
## Domain - (optional) cookie domain to force cookies to (ie: .yourcompany.com)
## Expire - (duration) expire timeframe for cookie
## Refresh - (duration) refresh the cookie when duration has elapsed after cookie was initially set.
## Should be less than cookie_expire; set to 0 to disable.
## On refresh, OAuth token is re-validated.
## (ie: 1h means tokens are refreshed on request 1hr+ after it was set)
## Secure - secure cookies are only sent by the browser of a HTTPS connection (recommended)
2015-05-26 09:18:03 -04:00
## HttpOnly - httponly cookies are not readable by javascript (recommended)
# cookie_name = "_oauth2_proxy"
2014-11-09 14:51:10 -05:00
# cookie_secret = ""
# cookie_domain = ""
# cookie_expire = "168h"
2015-05-26 09:18:03 -04:00
# cookie_refresh = ""
2015-03-17 23:13:45 -04:00
# cookie_secure = true
# cookie_httponly = true