{"repo":"nginxinc/nginx-openid-connect","free":true,"listed":false,"github":"https://github.com/nginxinc/nginx-openid-connect","clone":"git clone https://github.com/nginxinc/nginx-openid-connect.git","description":"Reference implementation of OpenID Connect integration for NGINX Plus","language":"Perl","stars":217,"topics":["nginx","openid-connect","openidconnect","oauth2","oauth","relying-party","javascript","jwt"],"license":null,"category":"auth-billing-email","readme_excerpt":"nginx-openid-connect Reference implementation of NGINX Plus as relying party for OpenID Connect authentication Description This repository describes how to enable OpenID Connect integration for NGINX Plus. The solution depends on NGINX Plus components (auth jwt module and key-value store) and as such is not suitable for open source NGINX. Figure 1. High level components of an OpenID Connect environment This implementation assumes the following environment: The identity provider (IdP) supports OpenID Connect 1.0 The authorization code flow is in use NGINX Plus is configured as a relying party The IdP knows NGINX Plus as a confidential client or a public client using PKCE With this environment, both the client and NGINX Plus communicate directly with the IdP at different stages during the initial authentication event. Figure 2. OpenID Connect authorization code flow protocol NGINX Plus is configured to perform OpenID Connect authentication. Upon a first visit to a protected resource, NGINX Plus initiates the OpenID Connect authorization code flow and redirects the client to the OpenID Connect provider (IdP). When the client returns to NGINX Plus with an authorization code, NGINX Plus exchanges that code for a set of tokens by communicating directly with the IdP. The ID Token received from the IdP is validated. NGINX Plus then stores the ID token in the key-value store, issues a session cookie to the client using a random string, (which becomes the key to obtain the ID token fro","default_branch":null,"files":null,"tree":[],"storefront":"/r/nginxinc","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/nginxinc/nginx-openid-connect/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}