[management,proxy] Use single-use codes for OIDC session handoff (#7635)

* Generalize PKCE verifier store into SingleUseStore

* Generalize PKCE verifier store into SingleUseStore

* Extend single-use store to generate one-time retrieval codes

* Hand off proxy OIDC session via one-time code instead of URL token

* Use the single-use store in integration tests

* Read active proxy versions by cluster

* Detect proxy clusters that support session codes

* Bind OIDC session handoff mode to signed state

* Deprecate legacy OIDC session token handoff

* Remove unrelated session code test stub

* fix tests

* fix merge

* Fix session code compatibility detection

* Isolate proxy session codes in shared cache

* bump min session version
This commit is contained in:
Bethuel Mmbaga
2026-09-29 18:29:55 +03:00
committed by GitHub
parent 7ff709f565
commit 30dd076b36
22 changed files with 676 additions and 281 deletions
+26
View File
@@ -783,6 +783,12 @@ func TestWasCredentialSubmitted(t *testing.T) {
query: url.Values{"session_token": {"abc123"}},
expected: true,
},
{
name: "OIDC code in query",
method: auth.MethodOIDC,
query: url.Values{"session_code": {"abc123"}},
expected: true,
},
{
name: "OIDC token not in query",
method: auth.MethodOIDC,
@@ -1571,3 +1577,23 @@ func TestProtect_TunnelPeerFastPath_TakesPathWithInboundMarker(t *testing.T) {
assert.Equal(t, http.StatusOK, rec.Code,
"a successful tunnel-peer validation must forward to the next handler")
}
func TestStripSessionTokenParam(t *testing.T) {
cases := []struct {
name string
in string
want string
}{
{"strips session_token", "https://ex.com/p?a=1&session_token=tok", "/p?a=1"},
{"strips session_code", "https://ex.com/p?a=1&session_code=code", "/p?a=1"},
{"strips both", "https://ex.com/p?session_token=tok&session_code=code&a=1", "/p?a=1"},
{"no-op when absent", "https://ex.com/p?a=1", "/p?a=1"},
}
for _, tc := range cases {
t.Run(tc.name, func(t *testing.T) {
u, err := url.Parse(tc.in)
require.NoError(t, err)
assert.Equal(t, tc.want, stripSessionTokenParam(u))
})
}
}