Skip to main content

Module auth_code_loopback

Module auth_code_loopback 

Source
Expand description

OIDC Authorization Code + PKCE via a loopback redirect (RFC 8252) — the interactive human login. The CLI opens the browser to the Okta sign-in page and self-hosts a 127.0.0.1 listener to catch the redirect; no callback page is hosted anywhere and the authorization code never leaves the machine.

Sequence:

  1. Bind a loopback port on 127.0.0.1 (the redirect target; no page is hosted anywhere).
  2. Build a PKCE S256 verifier/challenge + a random state (both from the oauth2 crate).
  3. Hand the /v1/authorize URL to the caller’s open_browser; the user signs in.
  4. Catch the browser’s redirect to 127.0.0.1/callback?code&state on the listener.
  5. Validate state (CSRF guard) and extract the code — before rendering any success page.
  6. Exchange the code (+ code_verifier) at /v1/token for a TokenSet.

Converges on the same TokenSet and the shared oidc plumbing as the device flow.

Structs§

LoopbackFlowClient
Authorization-code-with-PKCE client using a loopback redirect.