[management,proxy] Rename the OIDC session code query parameter (#7981)

This commit is contained in:
Bethuel Mmbaga
2026-10-02 15:55:51 +03:00
committed by GitHub
parent f400f4bee8
commit 0712a5a5b9
9 changed files with 50 additions and 22 deletions
+5 -5
View File
@@ -583,7 +583,7 @@ func (mw *Middleware) authenticateWithSchemes(w http.ResponseWriter, r *http.Req
// handleAuthenticatedToken validates the token, handles denied access, and on
// success sets a session cookie and redirects to the original URL.
func (mw *Middleware) handleAuthenticatedToken(w http.ResponseWriter, r *http.Request, host, token string, config DomainConfig, scheme Scheme) {
isCode := scheme.Type() == auth.MethodOIDC && r.URL.Query().Get("session_code") != ""
isCode := scheme.Type() == auth.MethodOIDC && r.URL.Query().Get(auth.SessionCodeQueryParam) != ""
result, err := mw.validateSessionToken(r.Context(), host, token, isCode, config.SessionPublicKey, scheme.Type())
if err != nil {
if cd := proxy.CapturedDataFromContext(r.Context()); cd != nil {
@@ -661,7 +661,7 @@ func wasCredentialSubmitted(r *http.Request, method auth.Method) bool {
case auth.MethodPassword:
return credentialFormValue(r, passwordFormId) != ""
case auth.MethodOIDC:
return r.URL.Query().Get("session_token") != "" || r.URL.Query().Get("session_code") != ""
return r.URL.Query().Get(auth.SessionTokenQueryParam) != "" || r.URL.Query().Get(auth.SessionCodeQueryParam) != ""
}
return false
}
@@ -806,11 +806,11 @@ func sessionGroupsAllowed(allowed map[string]struct{}, method auth.Method, group
// or history.
func stripSessionTokenParam(u *url.URL) string {
q := u.Query()
if !q.Has("session_token") && !q.Has("session_code") {
if !q.Has(auth.SessionTokenQueryParam) && !q.Has(auth.SessionCodeQueryParam) {
return u.RequestURI()
}
q.Del("session_token")
q.Del("session_code")
q.Del(auth.SessionTokenQueryParam)
q.Del(auth.SessionCodeQueryParam)
clean := *u
clean.RawQuery = q.Encode()
return clean.RequestURI()
+10 -3
View File
@@ -786,9 +786,15 @@ func TestWasCredentialSubmitted(t *testing.T) {
{
name: "OIDC code in query",
method: auth.MethodOIDC,
query: url.Values{"session_code": {"abc123"}},
query: url.Values{"nb_session_code": {"abc123"}},
expected: true,
},
{
name: "OIDC backend session_code in query",
method: auth.MethodOIDC,
query: url.Values{"session_code": {"abc123"}},
expected: false,
},
{
name: "OIDC token not in query",
method: auth.MethodOIDC,
@@ -1585,8 +1591,9 @@ func TestStripSessionTokenParam(t *testing.T) {
want string
}{
{"strips session_token", "https://ex.com/p?a=1&session_token=tok", "/p?a=1"},
{"strips session_code", "https://ex.com/p?a=1&session_code=code", "/p?a=1"},
{"strips both", "https://ex.com/p?session_token=tok&session_code=code&a=1", "/p?a=1"},
{"strips nb_session_code", "https://ex.com/p?a=1&nb_session_code=code", "/p?a=1"},
{"strips both", "https://ex.com/p?session_token=tok&nb_session_code=code&a=1", "/p?a=1"},
{"keeps backend session_code", "https://ex.com/p?a=1&session_code=backend", "/p?a=1&session_code=backend"},
{"no-op when absent", "https://ex.com/p?a=1", "/p?a=1"},
}
for _, tc := range cases {
+3 -3
View File
@@ -43,12 +43,12 @@ func (o OIDC) Authenticate(r *http.Request) (string, string, error) {
// Check for the session credential returned by the OIDC callback. The management
// server passes it in the URL because it cannot set a cookie for the proxy's
// domain (cookies are domain-scoped per RFC 6265). The current flow uses a
// single-use session_code to keep the durable token out of the URL.
// single-use session code to keep the durable token out of the URL.
// session_token remains supported for backward compatibility.
if code := r.URL.Query().Get("session_code"); code != "" {
if code := r.URL.Query().Get(auth.SessionCodeQueryParam); code != "" {
return code, "", nil
}
if token := r.URL.Query().Get("session_token"); token != "" {
if token := r.URL.Query().Get(auth.SessionTokenQueryParam); token != "" {
return token, "", nil
}