Add public-client (CIMD) OAuth support

Public clients authenticate with PKCE and no client secret, using a
hosted Client ID Metadata Document (CIMD) as the client_id.

Add a no-secret token-endpoint mode, derive the state-token salt and the
PKCE verifier from a server-side key so the verifier never appears in
the signed-but-unencrypted state, and expose Registration.PublicClient,
Registry.PublicClients and the CIMD metadata path for provider wiring.

Signed-off-by: Aurélien Sibiril <81782+aureliensibiril@users.noreply.github.com>
This commit is contained in:
Aurélien Sibiril
2026-05-29 12:23:57 +02:00
parent 8f40f460d4
commit cd8ddd8db5
5 changed files with 380 additions and 50 deletions

View File

@@ -16,3 +16,12 @@ package connector
// CallbackPath is the HTTP path for the OAuth2 callback endpoint.
const CallbackPath = "/api/console/v1/connectors/complete"
// CIMDMetadataPath is the HTTP path serving the public OAuth Client ID
// Metadata Document (CIMD). For public clients, the deployment's
// (baseURL + CIMDMetadataPath) URL IS the OAuth client_id: the provider
// (e.g. PostHog) fetches this document server-to-server during the
// authorization flow to learn the client's name and redirect URIs, so no
// app pre-registration is required. The endpoint must be reachable
// unauthenticated from the public internet.
const CIMDMetadataPath = "/api/console/v1/connectors/oauth-client-metadata"