Expand description
Persistence for in-flight logins, authenticated sessions, and DPoP nonces.
Two properties here are security-relevant and neither is obvious from the SQL:
-
stateis consumed atomically. ASELECTfollowed by aDELETElets two concurrent callbacks both pass and both exchange the samecode— and the authorization server is entitled to revoke “any outstanding sessions and tokens associated with the earlier use of thecode”, so the loser destroys the winner’s session. One statement,RETURNING, zero rows means rejected. -
Secrets are AAD-bound to their row, column, AND destinations. Binding only the secrets is not enough: the declared adversary is anything able to write the database, and against that adversary a plain unauthenticated
audorissuercolumn defeats the scheme without touching a ciphertext at all — repoint the PDS and a live DPoP-bound token is sent to the attacker’s host, with everything still decrypting perfectly. So the AAD covers the destinations too, and is length-prefixed rather than delimiter-joined so no rearrangement of fields can collide. Seesuper::crypto; the unboundenc.v1form is rejected outright here.
Structs§
- OAuth
Session - An authenticated account’s tokens.
- Pending
Auth - An in-flight login.
Functions§
- delete_
session - Delete a session.
trueif one existed. - get_
nonce - The stored DPoP nonce for an origin, if any.
- get_
session - Read a session by subject DID.
- init_
schema - Create the OAuth tables.
- put_
nonce - Record the latest DPoP nonce for an origin. Servers rotate nonces, so a
later value replaces the earlier one.
nowis passed in rather than read here, matching the rest of this module — and so the sweeper’s age rule can be tested without waiting for a clock. - put_
pending - Record an in-flight login.
- put_
session - Store or REPLACE a session.
- sweep_
expired_ pending - Delete every pending login that has expired. Returns how many went.
- sweep_
stale_ nonces - Delete DPoP nonces untouched since
cutoff. Returns how many went. - take_
pending - Consume an in-flight login: return it and delete it, atomically.