Git Product home page Git Product logo

Comments (4)

parttimer777 avatar parttimer777 commented on June 18, 2024

For testing i implemented something in nginx to achieve this:

map $email $conditional_access {
    default "/forbidden";
    "[email protected]" "@proxy";
}


    location /forbidden {
        return 403;
    }


    location / {
       # oauth-proxy stuff here

        try_files "" $conditional_access;
    }

    location @proxy {
        include /config/nginx/proxy.conf;
        include /config/nginx/resolver.conf;

        set $upstream_app backend_server;
        set $upstream_port 8080;
        set $upstream_proto http;
        proxy_pass $upstream_proto://$upstream_app:$upstream_port;
    }

from oauth2-proxy.

tuunit avatar tuunit commented on June 18, 2024

No this is not possible. You will have to deploy multiple instances of oauth2-proxy. Each with another email file. It would be a huge security risk exposing this functionality, this way a malicious user could overwrite which email auth file to use just by setting it in the query parameters.

from oauth2-proxy.

tuunit avatar tuunit commented on June 18, 2024

If you have so many users and roles that you even need to think about separating them into different files on a path / endpoint level. I would recommend to you to start using keycloak or something similar with user federation to Google and do user grouping / mapping with a proper identity management tool.

from oauth2-proxy.

parttimer777 avatar parttimer777 commented on June 18, 2024

Thanks. Currently have a couple of users only. Might look into keycloak in the future, looks more scalable and interesting to learn.

from oauth2-proxy.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.