fix: PAR parameters not respected by authorize page

This commit is contained in:
Elias Schneider
2026-06-05 11:39:14 +02:00
parent 4f97cd4188
commit 420fd02c8c
13 changed files with 252 additions and 87 deletions
+49
View File
@@ -940,6 +940,55 @@ test.describe('Pushed Authorization Requests (PAR)', () => {
expect(tokenResult.error).toBeUndefined();
});
test('par-request-info resolves the stored request parameters', async ({ page }) => {
const state = 'par-info-state-9f3a';
const parResult = await oidcUtil.pushAuthorizationRequest(page, {
clientId: client.id,
clientSecret: client.secret,
redirectUri: client.callbackUrl,
scope: 'openid profile',
state,
responseMode: 'form_post'
});
expect(parResult.request_uri).toBeDefined();
const res = await page.request.get('/api/oidc/par-request-info', {
params: { client_id: client.id, request_uri: parResult.request_uri! }
});
expect(res.ok()).toBe(true);
const body = await res.json();
expect(body.scope).toBe('openid profile');
expect(body.redirectURI).toBe(client.callbackUrl);
expect(body.state).toBe(state);
expect(body.responseMode).toBe('form_post');
});
test('PAR full flow carries the resolved state into the callback redirect', async ({ page }) => {
const state = 'par-flow-state-7b21';
const parResult = await oidcUtil.pushAuthorizationRequest(page, {
clientId: client.id,
clientSecret: client.secret,
redirectUri: client.callbackUrl,
state,
responseMode: 'form_post'
});
expect(parResult.request_uri).toBeDefined();
const urlParams = new URLSearchParams({
client_id: client.id,
request_uri: parResult.request_uri!
});
const formPostRequestPromise = waitForFormPostRequest(page, client.callbackUrl);
await page.goto(`/authorize?${urlParams.toString()}`);
const request = await formPostRequestPromise;
const formData = new URLSearchParams(request.postData() ?? '');
expect(formData.get('code')).toBeTruthy();
expect(formData.get('state')).toBe(state);
});
test('PAR full flow shows consent screen when authorization is required', async ({ page }) => {
// The parClient is pre-authorized for "openid profile email"; pushing a different
// scope means consent is required and the consent screen must be shown rather than
+8 -1
View File
@@ -75,8 +75,14 @@ export async function pushAuthorizationRequest(
codeChallengeMethod?: string;
nonce?: string;
state?: string;
responseMode?: string;
}
): Promise<{ request_uri?: string; expires_in?: number; error?: string; error_description?: string }> {
): Promise<{
request_uri?: string;
expires_in?: number;
error?: string;
error_description?: string;
}> {
const form: Record<string, string> = {
client_id: params.clientId,
response_type: params.responseType ?? 'code',
@@ -88,6 +94,7 @@ export async function pushAuthorizationRequest(
if (params.codeChallengeMethod) form.code_challenge_method = params.codeChallengeMethod;
if (params.nonce) form.nonce = params.nonce;
if (params.state) form.state = params.state;
if (params.responseMode) form.response_mode = params.responseMode;
return page.request
.post('/api/oidc/par', {