diff --git a/GETTING_STARTED.md b/GETTING_STARTED.md index 872f16c7..dd3635c6 100644 --- a/GETTING_STARTED.md +++ b/GETTING_STARTED.md @@ -250,6 +250,18 @@ read it back with `server.ParseInteractionHandle` when the form is submitted, and protect that form with your usual CSRF defence. See `server.InteractionHandle`'s doc comment. +**Keep the interaction until the form comes back.** The submission +needs `a.Interaction` again: the scope, the requested claims and any +authorization details the user is approving. Encode it with +`a.Interaction.MarshalText()` and keep it with the handle, somewhere only +your application can write: a server-side session, or a cookie you +sign. Restore it with `server.ParseInteractionRequest`. Then any +instance can handle the submission, not only the one that began the +authorization. A modified copy can't widen the grant, since +`CompleteAuthorization` checks it against the request the server +stored. `examples/federated-union` keeps both in a signed cookie +(`union/interaction_cookie.go`). + `cmd/conformance-as/authorize.go` is a complete, working version of exactly this — read it for the full picture of the GET (render the form) and POST (handle the submission) halves of a real HTTP flow. Its diff --git a/conformance/server/oidf-config/README.md b/conformance/server/oidf-config/README.md index 170d0845..5858dfa6 100644 --- a/conformance/server/oidf-config/README.md +++ b/conformance/server/oidf-config/README.md @@ -874,7 +874,9 @@ its own `conformance-as-client-auth-mtls-and-mtls` container `expected-skips-client-auth-mtls-and-mtls.json` stay empty, matching every other clean profile above. -## Client Credentials Grant (`{baseline,mtls,client-auth-mtls,client-auth-mtls-and-mtls}-client-credentials.config.json`) +## Client Credentials Grant + +Configs: `{baseline,mtls,client-auth-mtls,client-auth-mtls-and-mtls}-client-credentials.config.json`. `server.RequestClientCredentialsToken` (RFC 6749 §4.4) has no PAR/authorize/redirect_uri/browser hop at all — a direct diff --git a/server/doc.go b/server/doc.go index 0c5441f2..22bd1674 100644 --- a/server/doc.go +++ b/server/doc.go @@ -5,7 +5,8 @@ // // The package exposes workflow methods — PushAuthorizationRequest, // BeginAuthorization, CompleteAuthorization, ExchangeAuthorizationCode, -// RefreshAccessToken, the CIBA trio BeginBackchannelAuthentication, +// RefreshAccessToken, the CIBA methods BeginBackchannelAuthentication, +// LookupBackchannelInteraction (which reads a pending request back), // CompleteBackchannelAuthentication and ExchangeBackchannelAuthentication, // RequestClientCredentialsToken, SignUserInfoResponse, Metadata, // PublicJWKS and (for OpenID Federation) EntityConfiguration — that