Created March 26, 2021 11:05
(ns app.keycloak
[app.config :as config]
[clj-http.client :as client]
[taoensso.timbre :refer [info debugf infof]]
[expiring-map.core :as em]
[buddy.auth.protocols :as proto]
[buddy.auth.http :as http]
[buddy.auth :refer [authenticated?]]
[buddy.core.codecs :as codecs]
[buddy.core.nonce :refer [random-nonce]]
[buddy.auth.middleware :as buddy-auth-middleware]
[ring.util.request :refer [request-url]]
[ring.util.http-response :as resp]
[keycloak.deployment :as kc-deploy])
(:import [org.keycloak.adapters KeycloakDeployment]
[org.keycloak.representations AccessToken]
[org.keycloak RSATokenVerifier]
[org.keycloak.common.util KeycloakUriBuilder]
[org.keycloak.constants ServiceUrlConstants]
[ URLEncoder]))
(def kc-token "X-Authorization-Token")
(defn token-from-cookie
(get-in req [:cookies kc-token :value]))
(defn token-from-headers
(get-in req [:headers kc-token]))
(defn request-token
(or (token-from-headers req)
(token-from-cookie req)))
(def kc-cfg
(get-in config/config [:auth :api]))
(def kc-deployment
(kc-deploy/client-conf kc-cfg)))
(defn verify
(verify kc-deployment token))
([^KeycloakDeployment deployment ^String token]
(let [kid (get-in config/config [:auth :kid])
public-key (.getPublicKey (.getPublicKeyLocator deployment) kid deployment)]
(RSATokenVerifier/verifyToken token public-key (.getRealmInfoUrl deployment)))))
(defn unexceptional-verify
(verify token)
(catch Exception _ nil)))
(defn extract
"return a map with keys with values extracted from the Keycloak access token"
[^AccessToken access-token]
{:username (.getPreferredUsername access-token)
:id (.getId access-token)
:email (.getEmail access-token)
:roles (set (map keyword (.getRoles (.getRealmAccess access-token))))})
(defn kc-backend
[& [{:keys [unauthorized-handler authfn] :or {authfn identity}}]]
(-parse [_ request]
(request-token request))
(-authenticate [_ request data]
(authfn data))
(-handle-unauthorized [_ request metadata]
(if unauthorized-handler
(unauthorized-handler request metadata)
(if (authenticated? request)
(http/response "Permission denied" 403)
(http/response "Unauthorized" 401))))))
(defn ->obj-array
(into-array Object [val]))
(defn nonce
(codecs/bytes->hex (random-nonce 32)))
(defn login-redirect-uri
[state redirect]
(let [base-auth-url (.getAuthServerBaseUrl ^KeycloakDeployment kc-deployment)
auth-url (-> (KeycloakUriBuilder/fromUri ^String base-auth-url)
(.path ServiceUrlConstants/AUTH_PATH)
(.build (->obj-array (.getRealm ^KeycloakDeployment kc-deployment)))
query-string (client/generate-query-string
{:client_id (:client-id kc-cfg)
:response_type "code"
:redirect_uri redirect
:state state
:nonce (nonce)})]
(str auth-url "?" query-string)))
(defn callback-url
(str (-> request :scheme name)
(get-in request [:headers "host"])
"?origin=" (URLEncoder/encode (request-url request) "UTF-8")))
(def redirect-state (em/expiring-map 30))
(defn redirect-unauthorized
(fn [request]
(let [redirect-to (callback-url request)
token (request-token request)
state (nonce)]
(em/assoc! redirect-state state redirect-to)
(if (and token (unexceptional-verify token))
(handler request)
(http/redirect (login-redirect-uri state redirect-to))))))
(defn get-token
[session_state code redirect-uri]
(let [params {:headers {"Content-Type" "application/x-www-form-urlencoded"}
:basic-auth [(:client-id kc-cfg) (:client-secret kc-cfg)]
:as :json
{:grant_type "authorization_code"
:code code
:state session_state
:redirect_uri redirect-uri
:client_id (:client-id kc-cfg)}}
url (.getTokenUrl ^KeycloakDeployment kc-deployment)]
(client/post url params)))
(defn exchange-token
(let [{:strs [code state session_state origin]} (:query-params request)
redirect (get redirect-state state)
token (get-token session_state code redirect)]
(if-let [access-token (get-in token [:body :access_token])]
{:status 302
:body ""
:headers {"Location" origin}
:cookies {kc-token
{:path "/"
:max-age 3600
:value access-token}}}
(resp/unauthorized {:error "Not authorized"}))))
;; Middleware
(defn authentication
"Middleware used on routes requiring authentication."
(kc-backend {:authfn unexceptional-verify})))
(defn authorization
"Middleware used on routes requiring authorization.
Adds user info to the request"
(fn [request]
(if (authenticated? request)
(let [access-token (verify (request-token request))
user-info (extract access-token)]
(handler (-> request (assoc :user-info user-info))))
(catch Exception _ (resp/unauthorized {:error "Not authorized"})))
(resp/unauthorized {:error "Not authorized"}))))
