Authentication with Google
Prerequisites
Before configuring Catena to authenticate users with Google, you must register an application in the Google API console.
The authorization callback URL should be set to the PlatformUrl plus the RedirectUri for PROVIDER_GOOGLE_WEB. If there is a difference between the value configured in the Google API console and the one sent by Catena (from its configuration), then Google will display an error ("Error 400: redirect_uri_mismatch") instead of an authorization page.
You will need the "client_id" and "client_secret" from the API console to configure Catena.
Catena configuration
Open the appsettings for your environment and look for the Catena authentication service configuration section which contains a section for Google (PROVIDER_GOOGLE_WEB). If the section does not exist, you may need to create it.
Fill ClientID and ClientSecret with the values from the Google API console. Set the RedirectUri to the one shown in the example below as a starting point and make sure IsEnabled is set to true.
For example, in appsettings.Development.json:
{
"Catena": {
"Authentication": {
"Validators": {
"PROVIDER_GOOGLE_WEB": {
"ClientID": "<your client ID>",
"ClientSecret": "<your client secret>",
"RedirectUri": "/api/v1/authentication/PROVIDER_GOOGLE_WEB/callback",
"IsEnabled": true
}
}
}
}
}Make sure your appsettings.Development.json is added to .gitignore
ClientID/ClientSecret values to version of appsettings.json or appsettings.Production.json — these files are part of your deployed source and shouldn't hold production secrets. Use appsettings.Development.json for local testing only. Setting secrets in production
For a live production deployment, you don't want to expose your secrets in the appsettings file.
Catena provides 2 potential solutions for this.
- Inline Encryption - This allows you to encrypt values in your
appsettings.jsonso it can be commited and shared across the team with only one shared password stored offline. - Configuring Dokku Secrets - Using dokku, setup environment variables that are read in by the app
When using Dokku secrets, you can map the nested JSON values to a new environment variable.
For example, ClientID maps too:
Catena__Authentication__Validators__PROVIDER_GOOGLE_WEB__ClientIDThen Client Secret maps too:
Catena__Authentication__Validators__PROVIDER_GOOGLE_WEB__ClientSecretIf deploying via the AWS deployment guide, add these to your dokku-secrets.env file and run ./set-dokku-secrets.sh. For more details and instructions on how to rotate secrets, view the Secrets management page.