Expand description
OIDC Authorization Code + PKCE via a loopback redirect (RFC 8252) — the interactive
human login. The CLI opens the browser to the Okta sign-in page and self-hosts a
127.0.0.1 listener to catch the redirect; no callback page is hosted anywhere and the
authorization code never leaves the machine.
Sequence:
- Bind a loopback port on 127.0.0.1 (the redirect target; no page is hosted anywhere).
- Build a PKCE S256 verifier/challenge + a random
state(both from theoauth2crate). - Hand the
/v1/authorizeURL to the caller’sopen_browser; the user signs in. - Catch the browser’s redirect to
127.0.0.1/callback?code&stateon the listener. - Validate
state(CSRF guard) and extract the code — before rendering any success page. - Exchange the code (+
code_verifier) at/v1/tokenfor aTokenSet.
Converges on the same TokenSet and the shared oidc plumbing as the device flow.
Structs§
- Loopback
Flow Client - Authorization-code-with-PKCE client using a loopback redirect.