Class CookieOAuth2AuthorizationRequestRepository
- All Implemented Interfaces:
AuthorizationRequestRepository
Keeps the request in a cookie of its own, for a provider that answers with
a form the browser posts (ClientRegistration.FORM_POST): Sign in with
Apple.
That answer is a POST from the provider's page, and a browser does not
send a SameSite=Lax cookie with one -- so the session, and a request kept
in it, are not there when the answer arrives. This cookie is
SameSite=None; Secure; HttpOnly, lasts five minutes, and uses a __Host-
name with Path=/ and no Domain. Browsers therefore reject a sibling
subdomain's attempt to plant this cookie for the parent domain. It is
signed with HMAC-SHA256: a value this server did not
write, or wrote more than five minutes ago, is no request at all. Its
state is what ties the posted answer to this browser.
The cookie is signed, not encrypted. It holds the PKCE verifier, which the
user's own browser may read; what protects the exchange from that browser's
user is the client secret a form_post provider also requires.
Every process that may receive the answer needs the same key: set
cn1.security.oauth2.client.cookie-secret. Without it each process makes a
key of its own when it starts.
-
Field Summary
Fields -
Constructor Summary
ConstructorsConstructorDescriptionCookieOAuth2AuthorizationRequestRepository(byte[] secret, String callbackPath) -
Method Summary
Modifier and TypeMethodDescriptionThe signer; for tests that move the clock.Takes back what was kept for this browser, so that it answers one callback and no more; null when nothing was.voidsaveAuthorizationRequest(OAuth2AuthorizationRequest authorizationRequest, HttpServer.Request request) KeepsauthorizationRequestfor the browser that maderequest.
-
Field Details
-
SECRET
The setting that holds the key, as at least 32 characters of text.- See Also:
-
COOKIE
-
-
Constructor Details
-
CookieOAuth2AuthorizationRequestRepository
- Parameters:
secret- at least 32 bytescallbackPath- the callback route, beginning with/; the cookie always usesPath=/, as required for browser-enforced host binding
-
-
Method Details
-
getSignedTokens
The signer; for tests that move the clock. -
saveAuthorizationRequest
public void saveAuthorizationRequest(OAuth2AuthorizationRequest authorizationRequest, HttpServer.Request request) Description copied from interface:AuthorizationRequestRepositoryKeepsauthorizationRequestfor the browser that maderequest.- Specified by:
saveAuthorizationRequestin interfaceAuthorizationRequestRepository
-
removeAuthorizationRequest
Description copied from interface:AuthorizationRequestRepositoryTakes back what was kept for this browser, so that it answers one callback and no more; null when nothing was.- Specified by:
removeAuthorizationRequestin interfaceAuthorizationRequestRepository
-