feat(oauth): add support for Pushed Authorization Requests (RFC9126) (#1404)

Co-authored-by: Elias Schneider <login@eliasschneider.com>
This commit is contained in:
Thibault NORMAND
2026-06-02 14:02:12 +02:00
committed by GitHub
co-authored by Elias Schneider
parent 2eada149af
commit 68a5abdcca
27 changed files with 765 additions and 54 deletions
+34
View File
@@ -63,6 +63,40 @@ export async function exchangeCode(
.then((r) => r.json());
}
export async function pushAuthorizationRequest(
page: Page,
params: {
clientId: string;
clientSecret?: string;
scope?: string;
redirectUri?: string;
responseType?: string;
codeChallenge?: string;
codeChallengeMethod?: string;
nonce?: string;
state?: string;
}
): Promise<{ request_uri?: string; expires_in?: number; error?: string; error_description?: string }> {
const form: Record<string, string> = {
client_id: params.clientId,
response_type: params.responseType ?? 'code',
scope: params.scope ?? 'openid profile email'
};
if (params.redirectUri) form.redirect_uri = params.redirectUri;
if (params.clientSecret) form.client_secret = params.clientSecret;
if (params.codeChallenge) form.code_challenge = params.codeChallenge;
if (params.codeChallengeMethod) form.code_challenge_method = params.codeChallengeMethod;
if (params.nonce) form.nonce = params.nonce;
if (params.state) form.state = params.state;
return page.request
.post('/api/oidc/par', {
headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
form
})
.then((r) => r.json());
}
export async function getClientAssertion(
page: Page,
data: { issuer: string; audience: string; subject: string }