{"id":950,"date":"2022-12-17T12:43:26","date_gmt":"2022-12-17T12:43:26","guid":{"rendered":"http:\/\/wp.chaoyu.nl\/?p=950"},"modified":"2024-03-19T21:26:24","modified_gmt":"2024-03-19T20:26:24","slug":"nginx-configuration-for-customs-ords-for-apex-feature-google-authentication","status":"publish","type":"post","link":"https:\/\/chaoyu.nl\/?p=950","title":{"rendered":"Nginx Configuration for Custom ORDs with APEX features Google Authentication [updates on Nginx Proxy Manager]"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">There are three things needed<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Google Developer console API <\/li>\n\n\n\n<li>APEX Social sign in Authentication method<\/li>\n\n\n\n<li>Nginx Configuration<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Google Settings, couple of things to watch out here<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Search APIs &amp; Services<\/li>\n\n\n\n<li>Authorized redirect URIs (https:\/\/apex.chaoyu.nl\/ords\/apex_authentication_callback )<\/li>\n\n\n\n<li>Client ID ( needed In APEX )<\/li>\n\n\n\n<li>Client secret  (needed In APEX)<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"2058\" height=\"1055\" src=\"http:\/\/wp.chaoyu.nl\/wp-content\/uploads\/2022\/12\/Screenshot-2022-12-17-140812.png\" alt=\"\" class=\"wp-image-955\" style=\"width:840px;height:430px\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>APEX Social sign in Authentication method<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Enable Google Authentication and Put in Client ID and secret<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"2478\" height=\"1232\" src=\"http:\/\/wp.chaoyu.nl\/wp-content\/uploads\/2022\/12\/Screenshot-2022-12-17-141849.png\" alt=\"\" class=\"wp-image-959\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Make sure you have a user created in APEX with the same email as the username.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"2233\" height=\"473\" src=\"http:\/\/wp.chaoyu.nl\/wp-content\/uploads\/2022\/12\/Screenshot_20221217_022226.png\" alt=\"\" class=\"wp-image-960\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Nginx Configuration<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Two settings here are important , they are needed for enable Google Oauth. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>error_page 497 https:\/\/$host:$server_port$request_uri;<\/em><\/strong>  <a rel=\"noreferrer noopener\" href=\"https:\/\/stackoverflow.com\/questions\/55027582\/nginx-http-not-redirecting-to-https-400-bad-request-the-plain-http-request-was\" target=\"_blank\">link to read more<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>proxy_set_header Host $host:$server_port;<\/em><\/strong> <a rel=\"noreferrer noopener\" href=\"https:\/\/serverfault.com\/questions\/1060408\/redirect-uri-mismatch-in-nginx-proxy-pass\" target=\"_blank\">link to read more<\/a> <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code lang=\"bash\" class=\"language-bash line-numbers\">user nginx;\nworker_processes auto;\nerror_log \/var\/log\/nginx\/error.log;\n#pid \/run\/nginx.pid;\nevents {\n    worker_connections 1024;\n}\n\nhttp {\n   # docker container ORDs servers\n   upstream backend {\n      server 192.168.178.68:8080;\n      server 192.168.178.68:8081;\n      server 192.168.178.68:8082;\n   }\n   # apex.chaoyu.nl\n   server {\n         listen 80;\n         server_name apex.chaoyu.nl;\n         return 301 https:\/\/$server_name$request_uri;\n   }\n   # Settings for a TLS enabled server.\n    server {\n        listen       443 ssl;\n        server_name  apex.chaoyu.nl;\n        error_page 497 https:\/\/$host:$server_port$request_uri;\n        #root         \/usr\/share\/nginx\/html;\n        ssl_certificate \"\/etc\/letsencrypt\/live\/chaoyu.nl\/fullchain.pem\";\n        ssl_certificate_key \"\/etc\/letsencrypt\/live\/chaoyu.nl\/privkey.pem\";\n        ssl_session_cache shared:SSL:1m;\n        ssl_session_timeout  10m;\n        ssl_ciphers PROFILE=SYSTEM;\n        ssl_prefer_server_ciphers on;\n\n        location \/ {\n            client_max_body_size 15M;\n            proxy_pass http:\/\/backend; # docker container backends\n            proxy_set_header Origin \"\" ;\n            proxy_set_header X-Forwarded-Host $host:$server_port;\n            proxy_set_header X-Real-IP $remote_addr;\n            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;\n            proxy_set_header X-Forwarded-Proto $scheme;\n            proxy_set_header Host $host:$server_port;\n        }\n    }\n}<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Try here https:\/\/apex.chaoyu.nl\/<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Recently I started to play around with Nginx Proxy Manager, it adds a UI on top of Nginx settings.<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here is the setting for my oci.chaoyu.nl settings. This is an apex domain running with a custom ORDs docker server (in an always free ARM docker server) and an always free ATP. Hier is the settings for apex with google authentication <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"> <\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1306\" height=\"431\" src=\"http:\/\/wp.chaoyu.nl\/wp-content\/uploads\/2023\/07\/image.png\" alt=\"\" class=\"wp-image-1479\" style=\"width:843px;height:278px\"\/><figcaption class=\"wp-element-caption\">Creates a redirect host<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1284\" height=\"541\" src=\"http:\/\/wp.chaoyu.nl\/wp-content\/uploads\/2023\/07\/image-1.png\" alt=\"\" class=\"wp-image-1480\"\/><figcaption class=\"wp-element-caption\">what it basically does is that it takes in 80 traffic and forward to 443 with a 301 response before it redirects<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1295\" height=\"515\" src=\"http:\/\/wp.chaoyu.nl\/wp-content\/uploads\/2023\/07\/image-2.png\" alt=\"\" class=\"wp-image-1481\"\/><figcaption class=\"wp-element-caption\">Nothing much to say here<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1251\" height=\"582\" src=\"http:\/\/wp.chaoyu.nl\/wp-content\/uploads\/2023\/07\/image-4.png\" alt=\"\" class=\"wp-image-1483\"\/><figcaption class=\"wp-element-caption\">syntax are almost the same as what you would do without ui, onlything I do differently is removing the server {}, ofc, dont forge to change to your ip address for the redirect<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">ORDs version 23<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">create a Proxy Host<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"167\" src=\"https:\/\/chaoyu.nl\/wp-content\/uploads\/2024\/03\/Screenshot-2024-03-19-at-21.24.24-1024x167.png\" alt=\"\" class=\"wp-image-1726\" srcset=\"https:\/\/chaoyu.nl\/wp-content\/uploads\/2024\/03\/Screenshot-2024-03-19-at-21.24.24-1024x167.png 1024w, https:\/\/chaoyu.nl\/wp-content\/uploads\/2024\/03\/Screenshot-2024-03-19-at-21.24.24-300x49.png 300w, https:\/\/chaoyu.nl\/wp-content\/uploads\/2024\/03\/Screenshot-2024-03-19-at-21.24.24-768x125.png 768w, https:\/\/chaoyu.nl\/wp-content\/uploads\/2024\/03\/Screenshot-2024-03-19-at-21.24.24-850x138.png 850w, https:\/\/chaoyu.nl\/wp-content\/uploads\/2024\/03\/Screenshot-2024-03-19-at-21.24.24.png 1396w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<pre class=\"wp-block-code\"><code lang=\"nginx\" class=\"language-nginx line-numbers\"># under Advanced Tab\n# new orders has a now a new landing page... \n# this works directly with google authentication \n\nlocation \/ {\n\trewrite ^\/(.*)$ \/ords\/f?p=4500 last;\n}\nlocation \/ords\/ {\n            proxy_pass http:\/\/192.168.178.70:8088\/ords\/;\n            proxy_set_header Origin \"\" ;\n            proxy_set_header X-Forwarded-Host $host:$server_port;\n            proxy_set_header X-Real-IP $remote_addr;\n            proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;\n            proxy_set_header X-Forwarded-Proto $scheme;\n            proxy_set_header Host test003.chaoyu.nl:443;\n}<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>There are three things needed Google Settings, couple of things to watch out here APEX Social sign in Authentication method Make sure you have a user created in APEX with the same email as the username. Nginx Configuration Two settings here are important , they are needed for enable Google Oauth. error_page 497 https:\/\/$host:$server_port$request_uri; link&#8230;<\/p>\n","protected":false},"author":1,"featured_media":967,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17,53],"tags":[19,44,22],"class_list":["post-950","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux","category-nginx","tag-apex","tag-nginx","tag-ords"],"_links":{"self":[{"href":"https:\/\/chaoyu.nl\/index.php?rest_route=\/wp\/v2\/posts\/950","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/chaoyu.nl\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/chaoyu.nl\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/chaoyu.nl\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/chaoyu.nl\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=950"}],"version-history":[{"count":20,"href":"https:\/\/chaoyu.nl\/index.php?rest_route=\/wp\/v2\/posts\/950\/revisions"}],"predecessor-version":[{"id":1729,"href":"https:\/\/chaoyu.nl\/index.php?rest_route=\/wp\/v2\/posts\/950\/revisions\/1729"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/chaoyu.nl\/index.php?rest_route=\/wp\/v2\/media\/967"}],"wp:attachment":[{"href":"https:\/\/chaoyu.nl\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=950"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/chaoyu.nl\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=950"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/chaoyu.nl\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=950"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}