summaryrefslogtreecommitdiff
path: root/src/scm/webid-oidc/reverse-proxy.scm
blob: 4221fa505ff28af967ca66e4aee3b64265e2e980 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
;; disfluid, implementation of the Solid specification
;; Copyright (C) 2020, 2021  Vivien Kraus

;; This program is free software: you can redistribute it and/or modify
;; it under the terms of the GNU Affero General Public License as
;; published by the Free Software Foundation, either version 3 of the
;; License, or (at your option) any later version.

;; This program is distributed in the hope that it will be useful,
;; but WITHOUT ANY WARRANTY; without even the implied warranty of
;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
;; GNU Affero General Public License for more details.

;; You should have received a copy of the GNU Affero General Public License
;; along with this program.  If not, see <https://www.gnu.org/licenses/>.

(define-module (webid-oidc reverse-proxy)
  #:use-module (webid-oidc errors)
  #:use-module ((webid-oidc stubs) #:prefix stubs:)
  #:use-module (webid-oidc resource-server)
  #:use-module ((webid-oidc config) #:prefix cfg:)
  #:use-module ((webid-oidc parameters) #:prefix p:)
  #:use-module (ice-9 optargs)
  #:use-module (ice-9 receive)
  #:use-module (ice-9 i18n)
  #:use-module (ice-9 getopt-long)
  #:use-module (ice-9 suspendable-ports)
  #:use-module (srfi srfi-19)
  #:use-module (rnrs bytevectors)
  #:use-module (web uri)
  #:use-module (web client) ;; required to pass the request along
  #:use-module (web request)
  #:use-module (web response)
  #:use-module (webid-oidc cache)
  #:use-module (webid-oidc web-i18n)
  #:use-module (web server)
  #:use-module (webid-oidc server endpoint)
  #:use-module (webid-oidc server endpoint reverse-proxy)
  #:declarative? #t
  #:export
  (
   make-reverse-proxy
   ))

(define* (make-reverse-proxy
          #:key
          (server-uri #f)
          (endpoint #f)
          (auth-header 'XXX-Agent))
  (set! auth-header
        ;; We need to remove the lowercase version of auth-header from
        ;; all incoming requests!
        (string->symbol
         (string-downcase
          (symbol->string auth-header))))
  (define authenticate
    (make-authenticator
     #:server-uri server-uri))
  (unless (and endpoint (uri? endpoint))
    (fail (G_ "#:endpoint argument is not present or not an URI.")))
  (define backend
    (make <reverse-proxy>
      #:backend-uri endpoint
      #:authentication-header auth-header))
  (lambda (request request-body)
    (let ((agent
           (catch #t
             (lambda ()
               (authenticate request request-body))
             (lambda (key . args)
               (case key
                 ((invalid-access-token
                   invalid-proof
                   unconfirmed-issuer)
                  #f)
                 (else
                  (apply throw key args))))))
          (request-time ((p:current-date))))
      (parameterize ((p:current-date request-time)
                     (web-locale request))
        (set! request
              (build-request (request-uri request)
                             #:method (request-method request)
                             #:version (request-version request)
                             #:headers (request-headers request)
                             #:port (request-port request)
                             #:meta `((user . ,agent) ,@(request-meta request))))
        (receive (response response-body response-meta)
            (handle backend request request-body)
          (values response response-body))))))