Skip to main content

Module flow

Module flow 

Source
Expand description

The login flow’s decisions: PKCE, browser binding, PAR, and the callback.

Everything here is pure — parameters in, parameters out — so it can be tested without a network. The SSRF guard forbids pointing any of this at a loopback test server, so decisions that live inside an HTTP round trip are effectively untestable; keeping them out here is deliberate.

The security-critical piece is complete_callback. A server-side client stores state in a table that is global to the process, not per-browser, so an unguessable single-use state is not sufficient on its own: an attacker can start a login with their own account and induce a victim’s browser to fetch the resulting callback URL, and the victim ends up holding a session for the attacker’s account — reading their feeds, writing into their repo. The browser-binding cookie is what closes that, and complete_callback exists so the check cannot be left out — it consumes the pending row, verifies the binding, and validates the response as one operation, rather than three functions a caller must remember to chain.

Structs§

CallbackParams
What the authorization server sent back to the redirect URI.
ParRequest
The inputs to a pushed authorization request.
ParResponse
A validated PAR response.

Functions§

authorize_url
The URL to send the browser to after a successful PAR.
binding_hash
The value stored in the state row: the hash, never the token itself.
binding_matches
Whether the cookie presented at the callback is the one this flow issued.
complete_callback
Consume the pending login, check the browser binding, and validate the callback — in that order, as one operation.
new_binding_token
A fresh browser-binding token, to be set as a cookie before the redirect.
new_pkce_verifier
A fresh PKCE code verifier.
new_state
A fresh state.
par_params
The non-credential half of a PAR body. Client credentials are appended by super::client_auth::credential_params, since they depend on the negotiated method.
parse_par_response
Validate a PAR response before building an authorize URL from it.
pkce_challenge
The S256 challenge for a verifier: base64url(sha256(ascii(verifier))).
verify_callback
Validate a callback and return the authorization code.