fix(auth): block OIDC token exchange without PKCE verifier

Throw a session-expired error when the PKCE verifier is missing and keep
the settings component mount redirect-compatible.
This commit is contained in:
Andras Bacsai
2026-06-15 17:05:52 +02:00
parent c656892738
commit a1dbde3412
3 changed files with 11 additions and 10 deletions
+4 -2
View File
@@ -209,9 +209,11 @@ class OidcProvider extends AbstractProvider implements ProviderInterface
$fields = $this->getTokenFields($code);
if ($this->getConfig()->usePkce) {
$verifier = $this->pullOidcFlowValue($this->verifierSessionKey((string) $this->request->input('state')));
if ($verifier !== null) {
$fields['code_verifier'] = $verifier;
if ($verifier === null) {
throw new OidcException('OIDC login session expired. Please try again.');
}
$fields['code_verifier'] = $verifier;
}
$response = $this->getHttpClient()->post($this->getTokenUrl(), [
+4 -1
View File
@@ -5,6 +5,7 @@ namespace App\Livewire;
use App\Models\InstanceSettings;
use App\Models\OauthSetting;
use Illuminate\Foundation\Auth\Access\AuthorizesRequests;
use Illuminate\Http\RedirectResponse;
use Illuminate\Validation\ValidationException;
use Livewire\Component;
@@ -55,7 +56,7 @@ class SettingsOauth extends Component
return $rules;
}
public function mount(?string $provider = null)
public function mount(?string $provider = null): ?RedirectResponse
{
if (! isInstanceAdmin()) {
return redirect()->route('home');
@@ -73,6 +74,8 @@ class SettingsOauth extends Component
if ($this->selectedProvider !== null && ! array_key_exists($this->selectedProvider, $this->oauth_settings_map)) {
abort(404);
}
return null;
}
private function updateOauthSettings(?string $provider = null): void