feat(DPoP): add verification + X-Forwarded-Host X-Forwarded-Proto

This commit is contained in:
Edouard Vanbelle
2026-08-08 15:08:35 +02:00
parent 514bbc35ab
commit 2e6789e506
12 changed files with 879 additions and 21 deletions
+1 -5
View File
@@ -479,11 +479,7 @@ pub trait SessionStoragePort: Send + Sync + 'static {
/// redemption). Fails with `AlreadyExists` if the session already
/// carries a thumbprint (anti-downgrade invariant, see
/// `docs/plan/dpop.md`).
async fn bind_dpop_jkt(
&self,
session_id: Uuid,
dpop_jkt: &str,
) -> Result<(), DomainError>;
async fn bind_dpop_jkt(&self, session_id: Uuid, dpop_jkt: &str) -> Result<(), DomainError>;
}
// ============================================================================
@@ -2263,7 +2263,11 @@ impl AuthApplicationService {
"dpop_jkt must be a 43-character base64url SHA-256 thumbprint (RFC 7638)",
)
})?;
match self.session_storage.bind_dpop_jkt(session_id, &validated).await {
match self
.session_storage
.bind_dpop_jkt(session_id, &validated)
.await
{
Ok(()) => {
tracing::info!(
target: "audit",