curl cookie - use access token to login on prometheus via oauth2-proxy

Viewed 513

I've configured oauth2-proxy to login on my prometheus backend via sso and I want to use the API call in order to get some metrics but the authentication web is working well, when I try to authenticate via API Curl doesn't work at all.

I'm getting the Access Token with the curl below:

[root@root]#  curl --location --request POST 'https://oidc.provider.com/oauth2/token?lmAuth=3_M2M' --header 'Content-Type: application/x-www-form-urlencoded' --data-urlencode 'username=user' --data-urlencode 'password=xxxxx' --data-urlencode 'client_id=xxxxx' --data-urlencode 'client_secret=xxxxxx' --data-urlencode 'grant_type=password' --data-urlencode 'scope=profile'

When I try to use the access token provided by the oidc.provider.com doesn't authenticate me to prometheus:

[root@root]# curl -k -H 'Accept: application/json' -H "Authorization: Bearer ${ACCESS_TOKEN} https://tool.domain.com/prometheus 

  <form method="GET" action="/oauth2/start">
        <input type="hidden" name="rd" value="/prometheus/alerts">
          
          <button type="submit" class="button block is-primary">Sign in with SSO Connect</button>
      </form>

      
    </div>
  </section>

  <script>
    if (window.location.hash) {
      (function() {
        var inputs = document.getElementsByName('rd');
        for (var i = 0; i < inputs.length; i++) {
          
          var idx = inputs[i].value.indexOf('#');
          if (idx >= 0) {
            
            inputs[i].value = inputs[i].value.substr(0, idx);
          }
          inputs[i].value += window.location.hash;
        }
      })();
    }
  </script>

  <footer class="footer has-text-grey has-background-light is-size-7">
    <div class="content has-text-centered">
        
        <p>Secured with <a href="https://github.com/oauth2-proxy/oauth2-proxy#oauth2_proxy" class="has-text-grey">OAuth2 Proxy</a> version v7.2.1</p>

Logs from oauth2-proxy

127.0.0.1:53436 - dbe8796c-f4e2-465a-bef1-080058fa462f - - [2022/03/04 09:08:11] tool.domain.com GET - "/oauth2/auth" HTTP/1.0 "curl/7.29.0" 401 13 0.000
127.0.0.1:53438 - d1c11a87-ef87-495a-bbe9-e7c6fd5c80bd - - [2022/03/04 09:08:11] tool.domain.com GET - "/oauth2/sign_in" HTTP/1.0 "curl/7.29.0" 200 8047 0.000

If I use the curl from the chrome with the cookie generated, it works very well as an API.

curl 'https://tool.domaine.com/prometheus/api/v1/query?query=cpf_tuya_connector%3Adatabase_queries&time=1646382609.806' \
  -H 'Connection: keep-alive' \
  -H 'sec-ch-ua: " Not A;Brand";v="99", "Chromium";v="98", "Google Chrome";v="98"' \
  -H 'sec-ch-ua-mobile: ?0' \
  -H 'User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102 Safari/537.36' \
  -H 'sec-ch-ua-platform: "Windows"' \
  -H 'Accept: */*' \
  -H 'Sec-Fetch-Site: same-origin' \
  -H 'Sec-Fetch-Mode: cors' \
  -H 'Sec-Fetch-Dest: empty' \
  -H 'Referer: https://tool.domain.com/prometheus/graph?g0.expr=cpf_tuya_connector%3Adatabase_queries&g0.tab=1&g0.stacked=0&g0.show_exemplars=0&g0.range_input=1h' \
  -H 'Accept-Language: en-US,en;q=0.9' \
  -H 'Cookie: _oauth2_proxy= ${COOKIE}' \
  --compressed \
  --insecure

enter image description here

0 Answers
Related