# Host nginx example. The auth service MUST authenticate every request and return only the # normalized X-Thoth-* identity/admin claims below. ThothII remains on 127.0.0.1:8080. server { listen 443 ssl; server_name thoth.example.test; ssl_certificate /etc/nginx/tls/fullchain.pem; ssl_certificate_key /etc/nginx/tls/privkey.pem; location = /_authenticate { internal; proxy_pass http://authentication-gateway/verify; proxy_pass_request_body off; proxy_set_header Content-Length ""; proxy_set_header X-Original-URI $request_uri; proxy_set_header X-Authenticated-User ""; proxy_set_header X-Thoth-Principal-Issuer ""; proxy_set_header X-Thoth-Principal-Subject ""; proxy_set_header X-Thoth-Principal-Display-Name ""; proxy_set_header X-Thoth-Is-Admin ""; proxy_set_header X-Thoth-Trusted-Principal-Issuer ""; proxy_set_header X-Thoth-Trusted-Principal-Subject ""; proxy_set_header X-Thoth-Trusted-Principal-Display-Name ""; proxy_set_header X-Thoth-Trusted-Is-Admin ""; } location / { auth_request /_authenticate; auth_request_set $thoth_principal_issuer $upstream_http_x_thoth_principal_issuer; auth_request_set $thoth_principal_subject $upstream_http_x_thoth_principal_subject; auth_request_set $thoth_principal_display_name $upstream_http_x_thoth_principal_display_name; auth_request_set $thoth_is_admin $upstream_http_x_thoth_is_admin; # Clear public normalized claims and carry auth_request results over the private hop. proxy_set_header X-Authenticated-User ""; proxy_set_header X-Thoth-Principal-Issuer ""; proxy_set_header X-Thoth-Principal-Subject ""; proxy_set_header X-Thoth-Principal-Display-Name ""; proxy_set_header X-Thoth-Is-Admin ""; proxy_set_header X-Thoth-Trusted-Principal-Issuer $thoth_principal_issuer; proxy_set_header X-Thoth-Trusted-Principal-Subject $thoth_principal_subject; proxy_set_header X-Thoth-Trusted-Principal-Display-Name $thoth_principal_display_name; proxy_set_header X-Thoth-Trusted-Is-Admin $thoth_is_admin; proxy_set_header X-Forwarded-Proto https; proxy_set_header Host $host; proxy_pass http://127.0.0.1:8080; } }