pub async fn complete_callback(
pool: &SqlitePool,
codec: &Codec,
params: &CallbackParams,
presented_cookie: Option<&str>,
now: i64,
) -> Result<(PendingAuth, String)>Expand description
Consume the pending login, check the browser binding, and validate the callback — in that order, as one operation.
These three steps were previously three free functions with nothing forcing
the middle one to happen. That matters more than it sounds: the binding check
is the single control standing between a server-global state table and a
login-CSRF that hands a victim a session for the attacker’s account. A caller
that forgot it would still compile, still pass every test, and still work
perfectly for every non-malicious login. Returning the code only from here
makes the omission unrepresentable rather than merely discouraged.
The row is consumed whatever happens next, including a binding failure — so a mismatched cookie cannot simply be retried.