mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-03 20:19:07 +02:00
[management,proxy] Rename the OIDC session code query parameter (#7981)
This commit is contained in:
@@ -583,7 +583,7 @@ func (mw *Middleware) authenticateWithSchemes(w http.ResponseWriter, r *http.Req
|
||||
// handleAuthenticatedToken validates the token, handles denied access, and on
|
||||
// success sets a session cookie and redirects to the original URL.
|
||||
func (mw *Middleware) handleAuthenticatedToken(w http.ResponseWriter, r *http.Request, host, token string, config DomainConfig, scheme Scheme) {
|
||||
isCode := scheme.Type() == auth.MethodOIDC && r.URL.Query().Get("session_code") != ""
|
||||
isCode := scheme.Type() == auth.MethodOIDC && r.URL.Query().Get(auth.SessionCodeQueryParam) != ""
|
||||
result, err := mw.validateSessionToken(r.Context(), host, token, isCode, config.SessionPublicKey, scheme.Type())
|
||||
if err != nil {
|
||||
if cd := proxy.CapturedDataFromContext(r.Context()); cd != nil {
|
||||
@@ -661,7 +661,7 @@ func wasCredentialSubmitted(r *http.Request, method auth.Method) bool {
|
||||
case auth.MethodPassword:
|
||||
return credentialFormValue(r, passwordFormId) != ""
|
||||
case auth.MethodOIDC:
|
||||
return r.URL.Query().Get("session_token") != "" || r.URL.Query().Get("session_code") != ""
|
||||
return r.URL.Query().Get(auth.SessionTokenQueryParam) != "" || r.URL.Query().Get(auth.SessionCodeQueryParam) != ""
|
||||
}
|
||||
return false
|
||||
}
|
||||
@@ -806,11 +806,11 @@ func sessionGroupsAllowed(allowed map[string]struct{}, method auth.Method, group
|
||||
// or history.
|
||||
func stripSessionTokenParam(u *url.URL) string {
|
||||
q := u.Query()
|
||||
if !q.Has("session_token") && !q.Has("session_code") {
|
||||
if !q.Has(auth.SessionTokenQueryParam) && !q.Has(auth.SessionCodeQueryParam) {
|
||||
return u.RequestURI()
|
||||
}
|
||||
q.Del("session_token")
|
||||
q.Del("session_code")
|
||||
q.Del(auth.SessionTokenQueryParam)
|
||||
q.Del(auth.SessionCodeQueryParam)
|
||||
clean := *u
|
||||
clean.RawQuery = q.Encode()
|
||||
return clean.RequestURI()
|
||||
|
||||
@@ -786,9 +786,15 @@ func TestWasCredentialSubmitted(t *testing.T) {
|
||||
{
|
||||
name: "OIDC code in query",
|
||||
method: auth.MethodOIDC,
|
||||
query: url.Values{"session_code": {"abc123"}},
|
||||
query: url.Values{"nb_session_code": {"abc123"}},
|
||||
expected: true,
|
||||
},
|
||||
{
|
||||
name: "OIDC backend session_code in query",
|
||||
method: auth.MethodOIDC,
|
||||
query: url.Values{"session_code": {"abc123"}},
|
||||
expected: false,
|
||||
},
|
||||
{
|
||||
name: "OIDC token not in query",
|
||||
method: auth.MethodOIDC,
|
||||
@@ -1585,8 +1591,9 @@ func TestStripSessionTokenParam(t *testing.T) {
|
||||
want string
|
||||
}{
|
||||
{"strips session_token", "https://ex.com/p?a=1&session_token=tok", "/p?a=1"},
|
||||
{"strips session_code", "https://ex.com/p?a=1&session_code=code", "/p?a=1"},
|
||||
{"strips both", "https://ex.com/p?session_token=tok&session_code=code&a=1", "/p?a=1"},
|
||||
{"strips nb_session_code", "https://ex.com/p?a=1&nb_session_code=code", "/p?a=1"},
|
||||
{"strips both", "https://ex.com/p?session_token=tok&nb_session_code=code&a=1", "/p?a=1"},
|
||||
{"keeps backend session_code", "https://ex.com/p?a=1&session_code=backend", "/p?a=1&session_code=backend"},
|
||||
{"no-op when absent", "https://ex.com/p?a=1", "/p?a=1"},
|
||||
}
|
||||
for _, tc := range cases {
|
||||
|
||||
@@ -43,12 +43,12 @@ func (o OIDC) Authenticate(r *http.Request) (string, string, error) {
|
||||
// Check for the session credential returned by the OIDC callback. The management
|
||||
// server passes it in the URL because it cannot set a cookie for the proxy's
|
||||
// domain (cookies are domain-scoped per RFC 6265). The current flow uses a
|
||||
// single-use session_code to keep the durable token out of the URL.
|
||||
// single-use session code to keep the durable token out of the URL.
|
||||
// session_token remains supported for backward compatibility.
|
||||
if code := r.URL.Query().Get("session_code"); code != "" {
|
||||
if code := r.URL.Query().Get(auth.SessionCodeQueryParam); code != "" {
|
||||
return code, "", nil
|
||||
}
|
||||
if token := r.URL.Query().Get("session_token"); token != "" {
|
||||
if token := r.URL.Query().Get(auth.SessionTokenQueryParam); token != "" {
|
||||
return token, "", nil
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user