BareProxy Auth Gate Plugin: A Password, OAuth or SSO Login in Front of Any App
Status: planned, number 17 of 21 in BareProxy’s build order. The plugins are built easiest first, and this one is about three or four days of coding: a password login is quick; OAuth and SSO flows take the time. It comes after the Analytics without JavaScript plugin. This post describes what it will do, and it will be updated as it is built.
Plenty of useful software ships with no login at all. An internal dashboard, a staging copy of a site, a metrics page, an admin tool somebody wrote in an afternoon. The usual fixes are a VPN, which is heavy, or a password bolted into each app, which is copied badly from app to app. An auth gate at the proxy puts one login in front of anything, and the app behind it never has to know.
What It Will Do
- A password. The simplest case: a shared password, or a short list of users, with a login page and a signed session cookie. Basic auth too, for tools and scripts.
- OAuth and SSO. Sign in with Google, GitHub, Microsoft or any OpenID Connect provider, and let in only certain addresses or domains, such as everyone with an
@example.comaccount. The plugin talks to the provider through outgoing calls its config allows, and to nothing else. - API keys. A header with a key from a list, for machine clients.
- Pass who it is on. After a login, the app gets the user’s name and email in request headers, so it can show who is signed in without doing any auth itself.
A config will look something like this:
plugin login /etc/bareproxy/plugins/auth-gate.wasm
config /etc/bareproxy/plugins/login.json
allow-http accounts.google.com:443 oauth2.googleapis.com:443
on-error closed
site admin.example.com
use login
route /* -> dashboard
on-error closed is the point here. If the plugin fails for any reason, the gate stays shut and the app answers 502, rather than opening the door.
Why at the Proxy
Login code is security code, and every copy of it is another place to get it wrong. One gate, written once, tested once and run in a sandbox, is easier to trust than ten homemade ones. The secret that signs sessions lives in the plugin’s config, never in the app.
Every request the gate turns away carries a note in its record, and why will say why it was refused: no session, an expired one, or an account outside the allowed domain.
This plugin replaces the “Auth” module of BareProxy’s earlier plan. The whole program is on the plugins page.