feat(DPoP): add verification + X-Forwarded-Host X-Forwarded-Proto
This commit is contained in:
@@ -479,11 +479,7 @@ pub trait SessionStoragePort: Send + Sync + 'static {
|
||||
/// redemption). Fails with `AlreadyExists` if the session already
|
||||
/// carries a thumbprint (anti-downgrade invariant, see
|
||||
/// `docs/plan/dpop.md`).
|
||||
async fn bind_dpop_jkt(
|
||||
&self,
|
||||
session_id: Uuid,
|
||||
dpop_jkt: &str,
|
||||
) -> Result<(), DomainError>;
|
||||
async fn bind_dpop_jkt(&self, session_id: Uuid, dpop_jkt: &str) -> Result<(), DomainError>;
|
||||
}
|
||||
|
||||
// ============================================================================
|
||||
|
||||
@@ -2263,7 +2263,11 @@ impl AuthApplicationService {
|
||||
"dpop_jkt must be a 43-character base64url SHA-256 thumbprint (RFC 7638)",
|
||||
)
|
||||
})?;
|
||||
match self.session_storage.bind_dpop_jkt(session_id, &validated).await {
|
||||
match self
|
||||
.session_storage
|
||||
.bind_dpop_jkt(session_id, &validated)
|
||||
.await
|
||||
{
|
||||
Ok(()) => {
|
||||
tracing::info!(
|
||||
target: "audit",
|
||||
|
||||
Reference in New Issue
Block a user