Commit bc5d118
committed
fix(oauth2): exact-match redirect_uris, declare scheme predicate on IClient
isUriAllowed() matched a registered redirect_uri via str_contains() against
the requested URI - a prefix/substring check, not an exact match. Registering
"myapp://callback" therefore also permitted "myapp://callback/<anything>":
any path appended after the registered value passed, on the field that
carries the OAuth2 authorization code. Both sides now go through the same
canonicalUrl()+normalizeUrl() pipeline and are compared with strict equality;
query strings remain tolerated exactly as before (canonicalUrl already drops
them from both sides).
Also:
- Declare isDisallowedNativeUriScheme() on IClient alongside the constants it
interprets, matching the interface-first convention every other predicate
on Client already follows.
- Add a regression test for the path-suffix bypass.
- Correct ADR 0001 decision item 6, which still claimed create() never
validates redirect_uris - stale relative to its own Consequences section
and the actual assertNativeCustomSchemesAllowed() field list.1 parent a0e83b1 commit bc5d118
4 files changed
Lines changed: 43 additions & 4 deletions
File tree
- app
- Models/OAuth2
- libs/OAuth2/Models
- docs/adr
- tests/unit
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
687 | 687 | | |
688 | 688 | | |
689 | 689 | | |
690 | | - | |
| 690 | + | |
691 | 691 | | |
692 | 692 | | |
693 | 693 | | |
| 694 | + | |
694 | 695 | | |
695 | | - | |
696 | | - | |
| 696 | + | |
| 697 | + | |
| 698 | + | |
| 699 | + | |
| 700 | + | |
| 701 | + | |
| 702 | + | |
| 703 | + | |
| 704 | + | |
| 705 | + | |
| 706 | + | |
697 | 707 | | |
698 | 708 | | |
699 | 709 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
61 | 61 | | |
62 | 62 | | |
63 | 63 | | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
64 | 76 | | |
65 | 77 | | |
66 | 78 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
38 | | - | |
| 38 | + | |
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
252 | 252 | | |
253 | 253 | | |
254 | 254 | | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
255 | 272 | | |
0 commit comments