mirror of
https://github.com/coollabsio/coolify.git
synced 2026-09-28 02:06:37 -04:00
fix(auth): block OIDC token exchange without PKCE verifier
Throw a session-expired error when the PKCE verifier is missing and keep the settings component mount redirect-compatible.
This commit is contained in:
@@ -209,9 +209,11 @@ class OidcProvider extends AbstractProvider implements ProviderInterface
|
||||
$fields = $this->getTokenFields($code);
|
||||
if ($this->getConfig()->usePkce) {
|
||||
$verifier = $this->pullOidcFlowValue($this->verifierSessionKey((string) $this->request->input('state')));
|
||||
if ($verifier !== null) {
|
||||
$fields['code_verifier'] = $verifier;
|
||||
if ($verifier === null) {
|
||||
throw new OidcException('OIDC login session expired. Please try again.');
|
||||
}
|
||||
|
||||
$fields['code_verifier'] = $verifier;
|
||||
}
|
||||
|
||||
$response = $this->getHttpClient()->post($this->getTokenUrl(), [
|
||||
|
||||
@@ -5,6 +5,7 @@ namespace App\Livewire;
|
||||
use App\Models\InstanceSettings;
|
||||
use App\Models\OauthSetting;
|
||||
use Illuminate\Foundation\Auth\Access\AuthorizesRequests;
|
||||
use Illuminate\Http\RedirectResponse;
|
||||
use Illuminate\Validation\ValidationException;
|
||||
use Livewire\Component;
|
||||
|
||||
@@ -55,7 +56,7 @@ class SettingsOauth extends Component
|
||||
return $rules;
|
||||
}
|
||||
|
||||
public function mount(?string $provider = null)
|
||||
public function mount(?string $provider = null): ?RedirectResponse
|
||||
{
|
||||
if (! isInstanceAdmin()) {
|
||||
return redirect()->route('home');
|
||||
@@ -73,6 +74,8 @@ class SettingsOauth extends Component
|
||||
if ($this->selectedProvider !== null && ! array_key_exists($this->selectedProvider, $this->oauth_settings_map)) {
|
||||
abort(404);
|
||||
}
|
||||
|
||||
return null;
|
||||
}
|
||||
|
||||
private function updateOauthSettings(?string $provider = null): void
|
||||
|
||||
Reference in New Issue
Block a user