pub fn verify_callback(
params: &CallbackParams,
expected_issuer: &str,
) -> Result<String>Expand description
Validate a callback and return the authorization code.
iss is required, not merely checked when present. atproto mandates
authorization_response_iss_parameter_supported: true, so a conformant
server always sends it — which means accepting a response without one lets an
attacker bypass the check by simply omitting the parameter. That is the
mix-up attack RFC 9207 exists to stop.
This does NOT check state or the browser binding: those need the stored row,
and the row must be consumed atomically first. See
super::store::take_pending and binding_matches.