Skip to main content

verify_callback

Function verify_callback 

Source
pub fn verify_callback(
    params: &CallbackParams,
    expected_issuer: &str,
) -> Result<String>
Expand description

Validate a callback and return the authorization code.

iss is required, not merely checked when present. atproto mandates authorization_response_iss_parameter_supported: true, so a conformant server always sends it — which means accepting a response without one lets an attacker bypass the check by simply omitting the parameter. That is the mix-up attack RFC 9207 exists to stop.

This does NOT check state or the browser binding: those need the stored row, and the row must be consumed atomically first. See super::store::take_pending and binding_matches.