This Spring Boot application is set up to use Google OAuth as it's authentication scheme.
Setting this up on localhost requires the first two steps below; getting this to work on Dokku requires an additional third step.
- Obtaining a Google client id and client secret, which is done at the Google Developer Console.
- Configuring the
.envfile with these values. - Copying the
.envvalues to the dokku app's configuration values.
If this is your first time setting up a Google OAuth application in this course, you may need to do three steps. Later in the course, you'll only need to do the last of these, three, since the first two are typically "one-time" only steps.
- One time only: Set up a project in the Google Developer Console:
- One time only: Set up an OAuth Consent Screen for your project:
- Once for each application: Create a set of OAuth credentials (
GOOGLE_CLIENT_IDandGOOGLE_CLIENT_SECRETvalues):
Once you have created the OAuth Credentials, you'll need to configure your application with these values.
- For
localhost, those values go in the.envfile (as explained below) - For Dokku, those values are set using
dokku config:set ...(as explained below)
-
The
.envfile is created by copying it from.env.SAMPLEand then editing it, e.g.cp .env.SAMPLE .env -
Recall that
.envand.env.SAMPLEwill not show up in regular directory listings; files starting with.are considered hidden files. Usels -a, or configure your Mac finder/Windows explorer to show hidden files. -
As explained below, put your client-id and client-secret into
.env, NOT in.env.SAMPLE -
.envis never committed to the GitHub repo -
There is more information about
.envvs..env.SAMPLEon this page if you are interested: docs/environment-variables.
In the top level directory, use this command to copy .env.SAMPLE to .env. Recall that you
may need to use ls -a to get the files to show up, since they are hidden files on Unix-like systems.
cp .env.SAMPLE .env
The file .env.SAMPLE should not be edited; it is intended to
be a template for creating a file called .env that contains
your repository secrets.
The .env is in the .gitignore because **a file containing secrets should NOT be committed to GitHub, not even in a private repo.
After copying, the file .env looks like this:
GOOGLE_CLIENT_ID=see-instructions
GOOGLE_CLIENT_SECRET=see-instructions
ADMIN_EMAILS=phtcon@ucsb.edu
Replace see-instructions with the appropriate values.
The ADMIN_EMAILS value is used to determine which users have access to administrative features in the app. One of those
is the ability to list the users that have logged in.
For ADMIN_EMAILS, add your own email and any teammates you are collaborating with after phtcon.ucsb.edu; you can separate multiple emails with commas, e.g.
`ADMIN_EMAILS=phtcon@ucsb.edu,cgaucho@ucsb.edu,ldelplaya@ucsb.edu`
Do not separate emails with spaces; only commas:
-
❌ WRONG:
ADMIN_EMAILS=phtcon@ucsb.edu, cgaucho@ucsb.edu, ldelplaya@ucsb.edu -
✅ Correct:
ADMIN_EMAILS=phtcon@ucsb.edu,cgaucho@ucsb.edu,ldelplaya@ucsb.edu -
Add your own UCSB email address
-
Add
phtcon@ucsb.edu(your instructor) -
Add the mentor for your team (look up the mentor's name on the course team listing, then ask them in your channel)
-
Add everyone else on your team
I suggest that, as a team, you collaborate in your team slack channel on getting a standard list of these, and then that you pin that post in your team slack channel for easy reference.
With this done, you should be all set to run on localhost.
There are two ways to set up your .env values on Dokku.
- One variable at a time (recommended if this is your first time doing this)
- All at once with a file
To copy the values to Dokku one at a time, do this
for each line in the .env file:
On the dokku server command line, type:
dokku config:set --no-restart app-name VARIABLE=VALUE, where
- app-name is your app name such as
jpa03-cgaucho. It needs to match what you see when you typedokku apps:list - VARIABLE=VALUE is one of the lines in your .env. file
Note that on Dokku, you also typically need to set this value (this typically does not go in your .env)
dokku config:set --no-restart app-name PRODUCTION=true
The idea of this step is to copy/paste the values
from from your .env file into a file in your Dokku account
and then load the values all at once.
You could use file transfer, but because of various firewall settings, it may be easier to just copy/paste like this:
-
On the system where you are doing development, use
cat .envto list out the contents, e.g.pconrad@Phillips-MacBook-Air STARTER-jpa03 % cat .env GOOGLE_CLIENT_ID=26622685272-ofq4729s9nt8loednuuv5c0opja1vaeb.apps.googleusercontent.com GOOGLE_CLIENT_SECRET=GOCSPX-fakeCredentials99_fakefake-_fake ADMIN_EMAILS=phtcon@ucsb.edu JDBC_DATABASE_URL=jdbc:postgresql://example.org:5432/starter_jpa03_db JDBC_DATABASE_USERNAME=postgres JDBC_DATABASE_PASSWORD=password pconrad@Phillips-MacBook-Air STARTER-jpa03 % -
At the shell prompt on your dokku server (e.g. dokku-07.cs.ucsb.edu), type this, where
jpa03-cgauchois the name of your app:cat > jpa03-gaucho.envThen, copy paste the contents of the
.envfile into the window, followed by hitting enter, and then Control-D.If you then do an
lsyou should see that you have a file calledjpa03-gaucho.envcontaining the values you want to set. -
Now type the following (assuming that
jpa03-cgauchois your Dokku app name).dokku config:set --no-restart jpa03-cgaucho `cat jpa03-gaucho.env`In this command, the part in backticks (`cat jpa03-gaucho.env`) specfies that the output of that command should be placed on the command line.
Accordingly, this sets all of the environment variables at once.
Note that on Dokku, you also typically need to set this value (this typically does not go in your .env)
dokku config:set --no-restart app-name PRODUCTION=true
Your next step is likely to configure the application for using the Postgres database; instructions for that can be found here:
If you want to restart the application you can either
- Leave off the
--no-restartpart, or - Type
dokku ps:restart jpa03-cgauchoas the next command
- Leave off the
For troubleshooting advice with OAuth, this page may help: