fix(oidc): add CSRF state validation, PKCE S256, nonce, secure token delivery, registration guard

Security fixes for OIDC authentication flow:

1. CSRF state validation (High): State nonce is now stored server-side
   and validated on callback (single-use, 600s TTL)

2. PKCE S256 (Medium): code_challenge/code_verifier pair generated per
   RFC 9126, sent in authorize URL and token exchange

3. Nonce in ID token (Medium): Random nonce included in authorize URL,
   verified against ID token claims to prevent token replay

4. Secure token delivery (Medium): Tokens no longer in URL fragments.
   One-time exchange code redirected to frontend, tokens retrieved via
   POST /api/auth/oidc/exchange endpoint (60s TTL, single-use)

5. Registration guard (Low): POST /api/auth/register returns 403 when
   disable_password_login is active in OIDC-only mode
This commit is contained in:
Dionisio
2026-02-11 00:37:47 +01:00
parent f60c0df9f9
commit 1a1dee9179
5 changed files with 234 additions and 48 deletions
+6
View File
@@ -94,6 +94,12 @@ pub struct OidcCallbackQueryDto {
pub state: String,
}
/// Request body for the OIDC one-time code exchange endpoint
#[derive(Debug, Serialize, Deserialize)]
pub struct OidcExchangeDto {
pub code: String,
}
/// Information about available OIDC providers
#[derive(Debug, Serialize, Deserialize)]
pub struct OidcProviderInfoDto {