Add public-client (CIMD) OAuth support
Public clients authenticate with PKCE and no client secret, using a hosted Client ID Metadata Document (CIMD) as the client_id. Add a no-secret token-endpoint mode, derive the state-token salt and the PKCE verifier from a server-side key so the verifier never appears in the signed-but-unencrypted state, and expose Registration.PublicClient, Registry.PublicClients and the CIMD metadata path for provider wiring. Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
@@ -16,3 +16,12 @@ package connector
|
||||
|
||||
// CallbackPath is the HTTP path for the OAuth2 callback endpoint.
|
||||
const CallbackPath = "/api/console/v1/connectors/complete"
|
||||
|
||||
// CIMDMetadataPath is the HTTP path serving the public OAuth Client ID
|
||||
// Metadata Document (CIMD). For public clients, the deployment's
|
||||
// (baseURL + CIMDMetadataPath) URL IS the OAuth client_id: the provider
|
||||
// (e.g. PostHog) fetches this document server-to-server during the
|
||||
// authorization flow to learn the client's name and redirect URIs, so no
|
||||
// app pre-registration is required. The endpoint must be reachable
|
||||
// unauthenticated from the public internet.
|
||||
const CIMDMetadataPath = "/api/console/v1/connectors/oauth-client-metadata"
|
||||
|
||||
Reference in New Issue
Block a user