Expand description
The login flow’s decisions: PKCE, browser binding, PAR, and the callback.
Everything here is pure — parameters in, parameters out — so it can be tested without a network. The SSRF guard forbids pointing any of this at a loopback test server, so decisions that live inside an HTTP round trip are effectively untestable; keeping them out here is deliberate.
The security-critical piece is complete_callback. A server-side client
stores state in a table that is global to the process, not per-browser, so
an unguessable single-use state is not sufficient on its own: an
attacker can start a login with their own account and induce a victim’s
browser to fetch the resulting callback URL, and the victim ends up holding a
session for the attacker’s account — reading their feeds, writing into their
repo. The browser-binding cookie is what closes that, and
complete_callback exists so the check cannot be left out — it consumes
the pending row, verifies the binding, and validates the response as one
operation, rather than three functions a caller must remember to chain.
Structs§
- Callback
Params - What the authorization server sent back to the redirect URI.
- ParRequest
- The inputs to a pushed authorization request.
- ParResponse
- A validated PAR response.
Functions§
- authorize_
url - The URL to send the browser to after a successful PAR.
- binding_
hash - The value stored in the state row: the hash, never the token itself.
- binding_
matches - Whether the cookie presented at the callback is the one this flow issued.
- complete_
callback - Consume the pending login, check the browser binding, and validate the callback — in that order, as one operation.
- new_
binding_ token - A fresh browser-binding token, to be set as a cookie before the redirect.
- new_
pkce_ verifier - A fresh PKCE code verifier.
- new_
state - A fresh
state. - par_
params - The non-credential half of a PAR body. Client credentials are appended by
super::client_auth::credential_params, since they depend on the negotiated method. - parse_
par_ response - Validate a PAR response before building an authorize URL from it.
- pkce_
challenge - The S256 challenge for a verifier:
base64url(sha256(ascii(verifier))). - verify_
callback - Validate a callback and return the authorization code.