Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions GETTING_STARTED.md
Original file line number Diff line number Diff line change
Expand Up @@ -250,6 +250,18 @@ read it back with `server.ParseInteractionHandle` when the form is
submitted, and protect that form with your usual CSRF defence. See
`server.InteractionHandle`'s doc comment.

**Keep the interaction until the form comes back.** The submission
needs `a.Interaction` again: the scope, the requested claims and any
authorization details the user is approving. Encode it with
`a.Interaction.MarshalText()` and keep it with the handle, somewhere only
your application can write: a server-side session, or a cookie you
sign. Restore it with `server.ParseInteractionRequest`. Then any
instance can handle the submission, not only the one that began the
authorization. A modified copy can't widen the grant, since
`CompleteAuthorization` checks it against the request the server
stored. `examples/federated-union` keeps both in a signed cookie
(`union/interaction_cookie.go`).

`cmd/conformance-as/authorize.go` is a complete, working version of
exactly this — read it for the full picture of the GET (render the
form) and POST (handle the submission) halves of a real HTTP flow. Its
Expand Down
4 changes: 3 additions & 1 deletion conformance/server/oidf-config/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -874,7 +874,9 @@ its own `conformance-as-client-auth-mtls-and-mtls` container
`expected-skips-client-auth-mtls-and-mtls.json` stay empty, matching
every other clean profile above.

## Client Credentials Grant (`{baseline,mtls,client-auth-mtls,client-auth-mtls-and-mtls}-client-credentials.config.json`)
## Client Credentials Grant

Configs: `{baseline,mtls,client-auth-mtls,client-auth-mtls-and-mtls}-client-credentials.config.json`.

`server.RequestClientCredentialsToken` (RFC 6749 §4.4) has no
PAR/authorize/redirect_uri/browser hop at all — a direct
Expand Down
3 changes: 2 additions & 1 deletion server/doc.go
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,8 @@
//
// The package exposes workflow methods — PushAuthorizationRequest,
// BeginAuthorization, CompleteAuthorization, ExchangeAuthorizationCode,
// RefreshAccessToken, the CIBA trio BeginBackchannelAuthentication,
// RefreshAccessToken, the CIBA methods BeginBackchannelAuthentication,
// LookupBackchannelInteraction (which reads a pending request back),
// CompleteBackchannelAuthentication and ExchangeBackchannelAuthentication,
// RequestClientCredentialsToken, SignUserInfoResponse, Metadata,
// PublicJWKS and (for OpenID Federation) EntityConfiguration — that
Expand Down
Loading