[management,proxy] Rename the OIDC session code query parameter (#7981)

This commit is contained in:
Bethuel Mmbaga
2026-10-02 15:55:51 +03:00
committed by GitHub
parent f400f4bee8
commit 0712a5a5b9
9 changed files with 50 additions and 22 deletions
+5 -5
View File
@@ -583,7 +583,7 @@ func (mw *Middleware) authenticateWithSchemes(w http.ResponseWriter, r *http.Req
// handleAuthenticatedToken validates the token, handles denied access, and on
// success sets a session cookie and redirects to the original URL.
func (mw *Middleware) handleAuthenticatedToken(w http.ResponseWriter, r *http.Request, host, token string, config DomainConfig, scheme Scheme) {
isCode := scheme.Type() == auth.MethodOIDC && r.URL.Query().Get("session_code") != ""
isCode := scheme.Type() == auth.MethodOIDC && r.URL.Query().Get(auth.SessionCodeQueryParam) != ""
result, err := mw.validateSessionToken(r.Context(), host, token, isCode, config.SessionPublicKey, scheme.Type())
if err != nil {
if cd := proxy.CapturedDataFromContext(r.Context()); cd != nil {
@@ -661,7 +661,7 @@ func wasCredentialSubmitted(r *http.Request, method auth.Method) bool {
case auth.MethodPassword:
return credentialFormValue(r, passwordFormId) != ""
case auth.MethodOIDC:
return r.URL.Query().Get("session_token") != "" || r.URL.Query().Get("session_code") != ""
return r.URL.Query().Get(auth.SessionTokenQueryParam) != "" || r.URL.Query().Get(auth.SessionCodeQueryParam) != ""
}
return false
}
@@ -806,11 +806,11 @@ func sessionGroupsAllowed(allowed map[string]struct{}, method auth.Method, group
// or history.
func stripSessionTokenParam(u *url.URL) string {
q := u.Query()
if !q.Has("session_token") && !q.Has("session_code") {
if !q.Has(auth.SessionTokenQueryParam) && !q.Has(auth.SessionCodeQueryParam) {
return u.RequestURI()
}
q.Del("session_token")
q.Del("session_code")
q.Del(auth.SessionTokenQueryParam)
q.Del(auth.SessionCodeQueryParam)
clean := *u
clean.RawQuery = q.Encode()
return clean.RequestURI()