Add public-client (CIMD) OAuth support
Public clients authenticate with PKCE and no client secret, using a hosted Client ID Metadata Document (CIMD) as the client_id. Add a no-secret token-endpoint mode, derive the state-token salt and the PKCE verifier from a server-side key so the verifier never appears in the signed-but-unencrypted state, and expose Registration.PublicClient, Registry.PublicClients and the CIMD metadata path for provider wiring. Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
@@ -115,6 +115,25 @@ func (r *Registry) All() []*Registration {
|
||||
return out
|
||||
}
|
||||
|
||||
// PublicClients returns every Registration flagged PublicClient (CIMD,
|
||||
// no client_secret). probod uses this to auto-register their OAuth2
|
||||
// connectors with a deployment-derived client_id and state-signing key.
|
||||
// Order is not stable.
|
||||
func (r *Registry) PublicClients() []*Registration {
|
||||
r.mu.RLock()
|
||||
defer r.mu.RUnlock()
|
||||
|
||||
var out []*Registration
|
||||
|
||||
for _, reg := range r.providers {
|
||||
if reg.PublicClient {
|
||||
out = append(out, reg)
|
||||
}
|
||||
}
|
||||
|
||||
return out
|
||||
}
|
||||
|
||||
// ProviderDisplayName returns the human-readable label for the
|
||||
// provider, falling back to the raw constant string when no display
|
||||
// name is registered.
|
||||
|
||||
Reference in New Issue
Block a user