Official upstream source mirror. Do not make UH changes here.
  • Ruby 98.5%
  • Dockerfile 1.4%
  • Procfile 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-22 09:45:51 +01:00
.github Bump ruby/setup-ruby from 1.321.0 to 1.324.0 2026-09-22 07:03:16 +00:00
app/models Use Rails 7.1 default_column_serializer 2023-10-20 16:37:53 +01:00
bin Add binstubs 2026-04-13 12:14:07 +01:00
config Use Rails 8.1 defaults 2026-04-07 21:05:25 +01:00
db Update database schema for Rails 8 2025-01-27 13:02:03 +00:00
docs BAU - Update README 2026-04-10 10:01:41 +01:00
lib Put response body in array 2024-09-17 08:34:04 +01:00
log Blank rails 4.2.1 app 2015-06-10 12:22:57 +01:00
spec Fix rubocop violations after bumping rubocop-govuk 2024-06-26 17:52:03 +01:00
vendor/assets Blank rails 4.2.1 app 2015-06-10 12:22:57 +01:00
.dockerignore Remove obsolete Jenkinsfile. 2024-01-31 16:20:47 +00:00
.gitignore Generate coverage report using simplecov 2015-06-12 10:13:09 +01:00
.govuk_dependabot_merger.yml Upgrade govuk_dependabot_merger config to use v2 2024-04-30 10:47:22 +01:00
.rspec Initial rspec configuration 2015-06-10 12:30:27 +01:00
.rubocop.yml Add standard header to protect .rubocop.yml 2021-11-10 09:31:35 +00:00
.ruby-version Update ruby to version 4.0.6 2026-07-21 13:34:03 +01:00
config.ru Update Rails defaults to 6.1 2021-06-16 08:50:51 +01:00
Dockerfile Bump Ruby from 3.4.4 to 4.0.2 2026-04-13 10:31:29 +01:00
Gemfile Update and version lock rack-proxy to 1.0.2 2026-09-09 16:47:40 +01:00
Gemfile.lock Bump simplecov from 1.2.0 to 1.3.0 in the test group 2026-09-22 07:02:34 +00:00
LICENCE Add MIT license 2018-10-08 09:11:36 +01:00
Procfile Add basic Dockerfile to integrate app in GOV.UK ECS 2021-05-06 15:34:21 +01:00
Rakefile Run linting as part of default rake task 2020-10-12 11:44:31 +01:00
README.md BAU - Update README 2026-04-10 10:01:41 +01:00

GOV.UK Authenticating Proxy

App to add authentication to the draft version of GOV.UK, so that only users with a signon account - or a valid JSON web token (JWT) - can access it.

This is a Rails application that proxies requests to an upstream service, first performing authentication using gds-sso to ensure that only authenticated users are able to view the site. It sets a X-GOVUK-AUTHENTICATED-USER header and a X_GOVUK_AUTHENTICATED_USER_ORGANISATION header so that the upstream service can identify the user.

It also removes the Host header and replaces it with a X-Forwarded-Host header.

The application also supports bypassing authentication via a valid JWT token. If the URL being requested includes a token querystring containing a valid token encoded with the value in the JWT_AUTH_SECRET environment variable, and that token contains a sub key, the value of that key is passed upstream in the GOVUK_AUTH_BYPASS_ID header. NB, the sub (or "subject") key is one of the reserved claims of a JWT.

If a user is authenticated using gds-sso and a JWT token is also provided, both sets of information are passed upstream. It is up to the upstream application how to handle these cases.

See the request flow with draft router.

Some of the thinking behind this is documented in RFC 13.

Technical documentation

The proxy works by subclassing rack-proxy methods (e.g. call to perform the request)

Running the app

In GOV.UK Docker, GOVUK_UPSTREAM_URI defaults to frontend. This means that, when you request authenticating-proxy.dev.gov.uk, it should behave the same as requesting frontend.dev.gov.uk.

Generating a token

See generating a token

Running the test suite

bundle exec rake

Further documentation

Check the docs/ directory.

Licence

MIT License