fix(oidc): add CSRF state validation, PKCE S256, nonce, secure token delivery, registration guard
Security fixes for OIDC authentication flow: 1. CSRF state validation (High): State nonce is now stored server-side and validated on callback (single-use, 600s TTL) 2. PKCE S256 (Medium): code_challenge/code_verifier pair generated per RFC 9126, sent in authorize URL and token exchange 3. Nonce in ID token (Medium): Random nonce included in authorize URL, verified against ID token claims to prevent token replay 4. Secure token delivery (Medium): Tokens no longer in URL fragments. One-time exchange code redirected to frontend, tokens retrieved via POST /api/auth/oidc/exchange endpoint (60s TTL, single-use) 5. Registration guard (Low): POST /api/auth/register returns 403 when disable_password_login is active in OIDC-only mode
This commit is contained in:
@@ -94,6 +94,12 @@ pub struct OidcCallbackQueryDto {
|
||||
pub state: String,
|
||||
}
|
||||
|
||||
/// Request body for the OIDC one-time code exchange endpoint
|
||||
#[derive(Debug, Serialize, Deserialize)]
|
||||
pub struct OidcExchangeDto {
|
||||
pub code: String,
|
||||
}
|
||||
|
||||
/// Information about available OIDC providers
|
||||
#[derive(Debug, Serialize, Deserialize)]
|
||||
pub struct OidcProviderInfoDto {
|
||||
|
||||
Reference in New Issue
Block a user