diff --git a/volumes/conf.d/validate.vouch.armos.zinomedia.de.conf b/volumes/conf.d/validate.vouch.armos.zinomedia.de.conf index 64d93ce..9b24423 100644 --- a/volumes/conf.d/validate.vouch.armos.zinomedia.de.conf +++ b/volumes/conf.d/validate.vouch.armos.zinomedia.de.conf @@ -19,13 +19,33 @@ server { add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always; - location / { - return 301 https://google.com; + location = /auth { + # forward the /validate request to Vouch Proxy + proxy_pass http://vouch:9090/validate; + + # be sure to pass the original host header + proxy_set_header Host $http_host; + + # Vouch Proxy only acts on the request headers + proxy_pass_request_body off; + proxy_set_header Content-Length ""; + + # optionally add X-Vouch-User as returned by Vouch Proxy along with the request + auth_request_set $auth_resp_x_vouch_user $upstream_http_x_vouch_user; + + # these return values are used by the @error401 call + auth_request_set $auth_resp_jwt $upstream_http_x_vouch_jwt; + auth_request_set $auth_resp_err $upstream_http_x_vouch_err; + auth_request_set $auth_resp_failcount $upstream_http_x_vouch_failcount; } - location /auth { - return 302 https://google.com; - } + # location / { + # return 301 https://google.com; + # } + + # location /auth { + # return 302 https://google.com; + # } # location / { # # forward the /validate request to Vouch Proxy