Skip to content

A contract for registering a client app behind the SSO gate #54

Description

@AE-EVKA

Feature description

ADR-0001 describes client projects building on SRDP. There is no supported mechanism for the final
step: placing a client app behind Traefik + oauth2-proxy + Zitadel. Client projects hand-write
Traefik labels against SRDP internals.

Use case

Adding the datavloot dashboard to the Compose stack required:

  • Traefik labels matching zitadel-auth@docker, zitadel-errors@docker, the srdp-app network and
    router naming conventions.
  • Replacing the entire oauth2-proxy command to add one scope
    (urn:zitadel:iam:org:projects:roles), needed so Zitadel asserts project roles in the token.
  • Overriding Traefik authResponseHeaders to forward X-Auth-Request-Access-Token.

The third item is the notable one. The default forwards X-Auth-Request-User and
X-Auth-Request-Email and withholds the access token. ADR-0008 says not to trust the former and to
validate the latter. A client app following ADR-0008 must reconfigure Traefik to do so.

Proposed solution

  1. A declarative way to register an app. Options, in preference order:
  2. scopes as configuration rather than a full command override.
  3. authResponseHeaders as configuration, with the access token included by default.

Alternatives considered

Alternative Why not
Hand-written labels (current) Couples every client to SRDP internals; breaks silently on rename
Fork the compose file Loses upstream changes
Run client apps outside the gate Defeats single sign-on; contradicts the client-project model
Wait for #42 Possibly correct. If srdp.toml is the intended home, close this and fold it in

Component

deploy/docker, services/traefik, services/oauth2-proxy

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions