mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat!: support PKCE in the oauth2 client's auth/exchange flow (#21215)
**Breaking Change:** Existing oauth apps might now use PKCE. If an unknown IdP type was being used, and it does not support PKCE, it will break. To fix, set the PKCE methods on the external auth to `none` ``` export CODER_EXTERNAL_AUTH_1_PKCE_METHODS=none ```
This commit is contained in:
@@ -770,6 +770,10 @@ type GithubOAuth2Config struct {
|
||||
DefaultProviderConfigured bool
|
||||
}
|
||||
|
||||
func (*GithubOAuth2Config) PKCESupported() []promoauth.Oauth2PKCEChallengeMethod {
|
||||
return []promoauth.Oauth2PKCEChallengeMethod{promoauth.PKCEChallengeMethodSha256}
|
||||
}
|
||||
|
||||
func (c *GithubOAuth2Config) Exchange(ctx context.Context, code string, opts ...oauth2.AuthCodeOption) (*oauth2.Token, error) {
|
||||
if !c.DeviceFlowEnabled {
|
||||
return c.OAuth2Config.Exchange(ctx, code, opts...)
|
||||
@@ -1172,6 +1176,15 @@ type OIDCConfig struct {
|
||||
IconURL string
|
||||
// SignupsDisabledText is the text do display on the static error page.
|
||||
SignupsDisabledText string
|
||||
PKCEMethods []promoauth.Oauth2PKCEChallengeMethod
|
||||
}
|
||||
|
||||
// PKCESupported is to prevent nil pointer dereference.
|
||||
func (o *OIDCConfig) PKCESupported() []promoauth.Oauth2PKCEChallengeMethod {
|
||||
if o == nil {
|
||||
return nil
|
||||
}
|
||||
return o.PKCEMethods
|
||||
}
|
||||
|
||||
// @Summary OpenID Connect Callback
|
||||
|
||||
Reference in New Issue
Block a user