|
| 1 | +// file: cie_oidc_deno.ts |
| 2 | + |
| 3 | +// Configurazione (usa Deno.env per produzione) |
| 4 | +const CLIENT_ID = Deno.env.get("CIE_CLIENT_ID") ?? "INSERISCI_CLIENT_ID"; |
| 5 | +const CLIENT_SECRET = Deno.env.get("CIE_CLIENT_SECRET") ?? "INSERISCI_CLIENT_SECRET"; |
| 6 | +const REDIRECT_URI = Deno.env.get("CIE_REDIRECT_URI") ?? "https://tuo-portale.it/callback"; |
| 7 | + |
| 8 | +// Endpoint OIDC CIE |
| 9 | +const CIE_AUTH_ENDPOINT = |
| 10 | + "https://idserver.servizicie.interno.gov.it/auth/realms/cie/protocol/openid-connect/auth"; |
| 11 | +const CIE_TOKEN_ENDPOINT = |
| 12 | + "https://idserver.servizicie.interno.gov.it/auth/realms/cie/protocol/openid-connect/token"; |
| 13 | +const CIE_USERINFO_ENDPOINT = |
| 14 | + "https://idserver.servizicie.interno.gov.it/auth/realms/cie/protocol/openid-connect/userinfo"; |
| 15 | + |
| 16 | +// Handler /login → redirect verso CIE |
| 17 | +function loginHandler(_req: Request): Response { |
| 18 | + const state = crypto.randomUUID(); |
| 19 | + const nonce = crypto.randomUUID(); |
| 20 | + |
| 21 | + // In produzione salva state/nonce in sessione (cookie, redis, ecc.) |
| 22 | + const params = new URLSearchParams({ |
| 23 | + client_id: CLIENT_ID, |
| 24 | + redirect_uri: REDIRECT_URI, |
| 25 | + response_type: "code", |
| 26 | + scope: "openid profile", |
| 27 | + state, |
| 28 | + nonce, |
| 29 | + }); |
| 30 | + |
| 31 | + const url = `${CIE_AUTH_ENDPOINT}?${params.toString()}`; |
| 32 | + return Response.redirect(url, 302); |
| 33 | +} |
| 34 | + |
| 35 | +// Handler /callback → scambia code, chiama /userinfo, estrae CF |
| 36 | +async function callbackHandler(req: Request): Promise<Response> { |
| 37 | + const url = new URL(req.url); |
| 38 | + const code = url.searchParams.get("code"); |
| 39 | + const error = url.searchParams.get("error"); |
| 40 | + |
| 41 | + if (error) { |
| 42 | + return new Response(`Errore da CIE: ${error}`, { status: 400 }); |
| 43 | + } |
| 44 | + if (!code) { |
| 45 | + return new Response("Manca il parametro 'code'", { status: 400 }); |
| 46 | + } |
| 47 | + |
| 48 | + // Scambio code → token |
| 49 | + const tokenRes = await fetch(CIE_TOKEN_ENDPOINT, { |
| 50 | + method: "POST", |
| 51 | + headers: { |
| 52 | + "Content-Type": "application/x-www-form-urlencoded", |
| 53 | + }, |
| 54 | + body: new URLSearchParams({ |
| 55 | + grant_type: "authorization_code", |
| 56 | + code, |
| 57 | + redirect_uri: REDIRECT_URI, |
| 58 | + client_id: CLIENT_ID, |
| 59 | + client_secret: CLIENT_SECRET, |
| 60 | + }), |
| 61 | + }); |
| 62 | + |
| 63 | + if (!tokenRes.ok) { |
| 64 | + const text = await tokenRes.text(); |
| 65 | + return new Response(`Errore token endpoint: ${tokenRes.status} - ${text}`, { |
| 66 | + status: 500, |
| 67 | + }); |
| 68 | + } |
| 69 | + |
| 70 | + const tokenData = await tokenRes.json(); |
| 71 | + const accessToken = tokenData.access_token; |
| 72 | + if (!accessToken) { |
| 73 | + return new Response("Access token mancante nella risposta CIE", { |
| 74 | + status: 500, |
| 75 | + }); |
| 76 | + } |
| 77 | + |
| 78 | + // Chiamata allo UserInfo endpoint |
| 79 | + const userInfoRes = await fetch(CIE_USERINFO_ENDPOINT, { |
| 80 | + headers: { |
| 81 | + Authorization: `Bearer ${accessToken}`, |
| 82 | + }, |
| 83 | + }); |
| 84 | + |
| 85 | + if (!userInfoRes.ok) { |
| 86 | + const text = await userInfoRes.text(); |
| 87 | + return new Response(`Errore userinfo endpoint: ${userInfoRes.status} - ${text}`, { |
| 88 | + status: 500, |
| 89 | + }); |
| 90 | + } |
| 91 | + |
| 92 | + const user = await userInfoRes.json() as Record<string, unknown>; |
| 93 | + |
| 94 | + // Estrazione codice fiscale |
| 95 | + const fiscalNumber = typeof user["fiscal_number"] === "string" |
| 96 | + ? (user["fiscal_number"] as string) |
| 97 | + : undefined; |
| 98 | + |
| 99 | + const codiceFiscale = fiscalNumber?.startsWith("TINIT-") |
| 100 | + ? fiscalNumber.substring("TINIT-".length) |
| 101 | + : fiscalNumber; |
| 102 | + |
| 103 | + const payload = { |
| 104 | + rawUserInfo: user, |
| 105 | + fiscal_number: fiscalNumber, |
| 106 | + codice_fiscale: codiceFiscale, |
| 107 | + }; |
| 108 | + |
| 109 | + return new Response(JSON.stringify(payload, null, 2), { |
| 110 | + headers: { "Content-Type": "application/json; charset=utf-8" }, |
| 111 | + }); |
| 112 | +} |
| 113 | + |
| 114 | +// Server Deno minimale |
| 115 | +Deno.serve((req) => { |
| 116 | + const url = new URL(req.url); |
| 117 | + |
| 118 | + if (url.pathname === "/login") { |
| 119 | + return loginHandler(req); |
| 120 | + } |
| 121 | + |
| 122 | + if (url.pathname === "/callback") { |
| 123 | + return callbackHandler(req); |
| 124 | + } |
| 125 | + |
| 126 | + return new Response( |
| 127 | + `CIE OIDC demo attiva.\n\n- /login → redirect a "Entra con CIE"\n- /callback → endpoint di ritorno`, |
| 128 | + { headers: { "Content-Type": "text/plain; charset=utf-8" } }, |
| 129 | + ); |
| 130 | +}); |
0 commit comments