Skip to main content

Module store

Module store 

Source
Expand description

Persistence for in-flight logins, authenticated sessions, and DPoP nonces.

Two properties here are security-relevant and neither is obvious from the SQL:

  • state is consumed atomically. A SELECT followed by a DELETE lets two concurrent callbacks both pass and both exchange the same code — and the authorization server is entitled to revoke “any outstanding sessions and tokens associated with the earlier use of the code”, so the loser destroys the winner’s session. One statement, RETURNING, zero rows means rejected.

  • Secrets are AAD-bound to their row, column, AND destinations. Binding only the secrets is not enough: the declared adversary is anything able to write the database, and against that adversary a plain unauthenticated aud or issuer column defeats the scheme without touching a ciphertext at all — repoint the PDS and a live DPoP-bound token is sent to the attacker’s host, with everything still decrypting perfectly. So the AAD covers the destinations too, and is length-prefixed rather than delimiter-joined so no rearrangement of fields can collide. See super::crypto; the unbound enc.v1 form is rejected outright here.

Structs§

OAuthSession
An authenticated account’s tokens.
PendingAuth
An in-flight login.

Functions§

delete_session
Delete a session. true if one existed.
get_nonce
The stored DPoP nonce for an origin, if any.
get_session
Read a session by subject DID.
init_schema
Create the OAuth tables.
put_nonce
Record the latest DPoP nonce for an origin. Servers rotate nonces, so a later value replaces the earlier one. now is passed in rather than read here, matching the rest of this module — and so the sweeper’s age rule can be tested without waiting for a clock.
put_pending
Record an in-flight login.
put_session
Store or REPLACE a session.
sweep_expired_pending
Delete every pending login that has expired. Returns how many went.
sweep_stale_nonces
Delete DPoP nonces untouched since cutoff. Returns how many went.
take_pending
Consume an in-flight login: return it and delete it, atomically.