mirror of
https://github.com/coder/coder.git
synced 2026-06-04 13:38:21 +00:00
b776a14b46
## Summary Harden the OAuth2 provider with multiple security fixes addressing `coder/security#121` (CSRF session takeover) and converge on OAuth 2.1 compliance. ### Security Fixes | Fix | Description | Commits | |-----|-------------|---------| | **CSRF on `/oauth2/authorize`** | Enforce CSRF protection on the authorize endpoint POST (consent form submission) | `ba7d646`, `b94a64e` | | **Clickjacking: `frame-ancestors` CSP** | Prevent consent page from being iframed (`Content-Security-Policy: frame-ancestors 'none'` + `X-Frame-Options: DENY`) | `597aeb2` | | **Exact redirect URI matching** | Changed from prefix matching to full string exact matching per OAuth 2.1 §4.1.2.1 | `73d64b1`, `93897f1` | | **Store & verify `redirect_uri`** | Store redirect_uri with auth code in DB, verify at token exchange matches exactly (RFC 6749 §4.1.3) | `50569b9`, `d7ca315` | | **Mandatory PKCE** | Require `code_challenge` at authorization (for `response_type=code`) + unconditional `code_verifier` verification at token exchange | `d7ca315`, `1cda1a9` | | **Reject implicit grant** | `response_type=token` now returns `unsupported_response_type` error page (OAuth 2.1 removes implicit flow) | `d7ca315`, `91b8863` | ### Changes by File **`coderd/httpmw/csrf.go`** — Extended the CSRF `ExemptFunc` to enforce CSRF on `/oauth2/authorize` in addition to `/api` routes. The consent form POST is now CSRF-protected to prevent cross-site authorization code theft. **`site/site.go`** — Added `Content-Security-Policy: frame-ancestors 'none'` and `X-Frame-Options: DENY` headers to `RenderOAuthAllowPage` (consent page only — does not affect the SPA/global CSP used by AI tasks). **`coderd/httpapi/queryparams.go`** — Changed `RedirectURL` from prefix matching (`strings.HasPrefix(v.Path, base.Path)`) to full URI exact matching (`v.String() != base.String()`), comparing scheme, host, path, and query. **`coderd/oauth2provider/authorize.go`** — Added PKCE enforcement: `code_challenge` is required when `response_type=code` (via a conditional check, not `RequiredNotEmpty`, so `response_type=token` can reach the explicit rejection path). `ShowAuthorizePage` (GET) validates `response_type` before rendering and returns a 400 error page for unsupported types. `ProcessAuthorize` (POST) stores the `redirect_uri` with the auth code when explicitly provided. **`coderd/oauth2provider/tokens.go`** — PKCE verification is now unconditional (not gated on `code_challenge` being present in DB). If the stored code has a `redirect_uri`, the token endpoint verifies it matches exactly — mismatch returns `errBadCode` → `invalid_grant`. Missing `code_verifier` returns `invalid_grant`. **`codersdk/oauth2.go`** — `OAuth2ProviderResponseTypeToken` constant and `Valid()` acceptance are **kept** so the authorize handler can parse `response_type=token` and return the proper `unsupported_response_type` error rather than failing at parameter validation. **`coderd/database/migrations/000421_*`** — Added `redirect_uri text` column to `oauth2_provider_app_codes`. ### Design Decisions **`state` parameter remains optional** — The plan initially required `state` via `RequiredNotEmpty`, but this was reverted in `376a753` to avoid breaking existing clients. The `state` is still hashed and stored when provided (via `state_hash` column), securing clients that opt in. **`response_type=token` kept in `Valid()`** — Removing it from `Valid()` would cause the parameter parser to reject the request before the authorize handler can return the proper `unsupported_response_type` error. The constant is kept for correct error handling flow. **CSP scoped to consent page only** — `frame-ancestors 'none'` is set only on the OAuth consent page renderer, not globally. The SPA/global CSP was previously changed to allow framing for AI tasks ([#18102](https://github.com/coder/coder/pull/18102)); this change does not regress that. ### Out of Scope (follow-up PRs) - Bearer tokens in query strings (needs internal caller audit) - Scope enforcement on OAuth2 tokens - Rate limiting on dynamic client registration --- <details> <summary>📋 Implementation Plan</summary> # Plan: Harden OAuth2 Provider — Security Fixes + OAuth 2.1 Compliance ## Context & Why Security issue `coder/security#121` reports a critical session takeover via CSRF on the OAuth2 provider. This plan covers all remaining security fixes from that issue **plus** convergence on OAuth 2.1 requirements. The goal is a single PR that closes all actionable gaps. ## Current State (already committed on branch `csrf-sjx1`) | Fix | Status | Commits | |-----|--------|---------| | Fix 1: CSRF on `/oauth2/authorize` | ✅ Done | `ba7d646`, `b94a64e` | | CSRF token in consent form HTML | ✅ Done | `b94a64e` | | `state_hash` column + storage | ✅ Done (hash stored, but state still optional) | `9167d83`, `b94a64e` | | Tests for CSRF + state hash | ✅ Done | `e4119b5` | ## Remaining Work ### ~~Fix 2 — Require `state` parameter~~ (DROPPED) > **Decision:** Do not enforce `state` as required. The `state` parameter is still hashed and stored when provided (via `hashOAuth2State` / `state_hash` column from prior commits), but clients are not forced to supply it. This avoids breaking existing integrations that omit state. **Rollback:** Remove `"state"` from the `RequiredNotEmpty` call in `coderd/oauth2provider/authorize.go:42`: ```go // BEFORE (current on branch) p.RequiredNotEmpty("response_type", "client_id", "state", "code_challenge") // AFTER p.RequiredNotEmpty("response_type", "client_id", "code_challenge") ``` No test changes needed — tests already pass `state` voluntarily. ### Fix 4 — Exact redirect URI matching Currently `coderd/httpapi/queryparams.go:233` uses prefix matching: ```go // CURRENT — prefix match if v.Host != base.Host || !strings.HasPrefix(v.Path, base.Path) { ``` OAuth 2.1 requires **exact string matching**. Change to: ```go // AFTER — exact match (OAuth 2.1 §4.1.2.1) if v.Host != base.Host || v.Path != base.Path { ``` **File: `coderd/httpapi/queryparams.go` — `RedirectURL` method** Also update the error message from "must be a subset of" to "must exactly match". **Additionally**, store `redirect_uri` with the auth code and verify at the token endpoint (RFC 6749 §4.1.3): 1. **New migration** (same migration file or a new `000421`): Add `redirect_uri text` column to `oauth2_provider_app_codes` 2. **Update INSERT query** in `coderd/database/queries/oauth2.sql` to include `redirect_uri` 3. **`coderd/oauth2provider/authorize.go`**: Store `params.redirectURL.String()` when inserting the code 4. **`coderd/oauth2provider/tokens.go`**: After retrieving the code from DB, verify that `redirect_uri` from the token request matches the stored value exactly. Currently `tokens.go:103` calls `p.RedirectURL(vals, callbackURL, "redirect_uri")` for prefix validation only — it must compare against the stored redirect_uri from the code, not just the app's callback URL. <details> <summary>Why both exact match AND store+verify?</summary> Exact matching at the authorize endpoint prevents open redirectors (attacker can't use a sub-path). Storing and verifying at the token endpoint prevents code injection — an attacker who steals a code can't exchange it with a different redirect_uri than was originally authorized. This is required by RFC 6749 §4.1.3 and OAuth 2.1. </details> ### Fix 7 — `frame-ancestors` CSP on consent page The consent page can be iframed by a workspace app (same-site), which is the attack vector. Add a `Content-Security-Policy` header to prevent framing. **File: `site/site.go` — `RenderOAuthAllowPage` function (~line 731)** Before writing the response, add: ```go func RenderOAuthAllowPage(rw http.ResponseWriter, r *http.Request, data RenderOAuthAllowData) { rw.Header().Set("Content-Type", "text/html; charset=utf-8") // Prevent the consent page from being framed to mitigate // clickjacking attacks (coder/security#121). rw.Header().Set("Content-Security-Policy", "frame-ancestors 'none'") rw.Header().Set("X-Frame-Options", "DENY") ... ``` Both headers for defense-in-depth (CSP for modern browsers, X-Frame-Options for legacy). ### OAuth 2.1 — Mandatory PKCE Currently PKCE is checked only when `code_challenge` was provided during authorization (`tokens.go:258`): ```go // CURRENT — conditional check if dbCode.CodeChallenge.Valid && dbCode.CodeChallenge.String != "" { // verify PKCE } ``` OAuth 2.1 requires PKCE for ALL authorization code flows. Change to: **File: `coderd/oauth2provider/authorize.go`** — Add `"code_challenge"` to required params: ```go p.RequiredNotEmpty("response_type", "client_id", "code_challenge") ``` **File: `coderd/oauth2provider/tokens.go:257-265`** — Make PKCE verification unconditional: ```go // AFTER — PKCE always required (OAuth 2.1) if req.CodeVerifier == "" { return codersdk.OAuth2TokenResponse{}, errInvalidPKCE } if !dbCode.CodeChallenge.Valid || dbCode.CodeChallenge.String == "" { // Code was issued without a challenge — should not happen // with the authorize endpoint enforcement, but defend in // depth. return codersdk.OAuth2TokenResponse{}, errInvalidPKCE } if !VerifyPKCE(dbCode.CodeChallenge.String, req.CodeVerifier) { return codersdk.OAuth2TokenResponse{}, errInvalidPKCE } ``` **File: `codersdk/oauth2.go`** — Remove `OAuth2ProviderResponseTypeToken` from the enum or reject it explicitly in the authorize handler. Currently it's defined at line 216 but the handler ignores `response_type` and always issues a code. We should either: - (a) Remove the `"token"` variant from the enum and reject it with `unsupported_response_type`, OR - (b) Add an explicit check in `ProcessAuthorize` that rejects `response_type=token` Option (b) is simpler and more backwards-compatible: ```go // In ProcessAuthorize, after extracting params: if params.responseType != codersdk.OAuth2ProviderResponseTypeCode { httpapi.WriteOAuth2Error(ctx, rw, http.StatusBadRequest, codersdk.OAuth2ErrorCodeUnsupportedResponseType, "Only response_type=code is supported") return } ``` ### OAuth 2.1 — Bearer tokens in query strings `coderd/httpmw/apikey.go:743` accepts `access_token` from URL query parameters. OAuth 2.1 prohibits this. However, this may be used internally (e.g., workspace apps, DERP). Need to audit callers before removing. **Approach:** This is a larger change with potential breakage. Mark as a **separate follow-up issue** rather than including in this PR. Document the finding. ### OAuth 2.1 — Removed flows ✅ **Already compliant.** `tokens.go` only supports `authorization_code` and `refresh_token` grant types. The implicit grant (`response_type=token`) will be explicitly rejected per the PKCE section above. ### OAuth 2.1 — Refresh token rotation ✅ **Already compliant.** `tokens.go:442` deletes the old API key when a refresh token is used. ## Migration Plan All DB changes can go in a single new migration (or extend 000420 if the branch is rebased before merge). Columns to add: - `redirect_uri text` on `oauth2_provider_app_codes` The `state_hash` column is already added by migration 000420. ## Implementation Order 1. **Fix 7** — CSP headers on consent page (isolated, no deps) 2. ~~**Fix 2** — Require `state` parameter~~ (DROPPED — state stays optional) 3. **Fix 4** — Exact redirect URI matching + store/verify redirect_uri 4. **PKCE mandatory** — Require `code_challenge` + reject `response_type=token` 5. **Rollback** — Remove `"state"` from `RequiredNotEmpty` in `authorize.go` 6. **Tests** — Update/add tests for all changes 7. **`make gen`** after DB changes ## Out of Scope (separate PRs) - Bearer tokens in query strings (needs internal caller audit) - Scope enforcement on OAuth2 tokens - Rate limiting / quota on dynamic client registration </details> --- _Generated with [`mux`](https://github.com/coder/mux) • Model: `anthropic:claude-opus-4-6` • Thinking: `xhigh`_
516 lines
18 KiB
Go
516 lines
18 KiB
Go
package oauth2provider
|
|
|
|
import (
|
|
"context"
|
|
"database/sql"
|
|
"errors"
|
|
"fmt"
|
|
"net/http"
|
|
"net/url"
|
|
"slices"
|
|
"time"
|
|
|
|
"github.com/google/uuid"
|
|
"golang.org/x/xerrors"
|
|
|
|
"github.com/coder/coder/v2/coderd/apikey"
|
|
"github.com/coder/coder/v2/coderd/database"
|
|
"github.com/coder/coder/v2/coderd/database/dbauthz"
|
|
"github.com/coder/coder/v2/coderd/database/dbtime"
|
|
"github.com/coder/coder/v2/coderd/httpapi"
|
|
"github.com/coder/coder/v2/coderd/httpmw"
|
|
"github.com/coder/coder/v2/coderd/rbac"
|
|
"github.com/coder/coder/v2/codersdk"
|
|
)
|
|
|
|
var (
|
|
// errBadSecret means the user provided a bad secret.
|
|
errBadSecret = xerrors.New("Invalid client secret")
|
|
// errBadCode means the user provided a bad code.
|
|
errBadCode = xerrors.New("Invalid code")
|
|
// errBadToken means the user provided a bad token.
|
|
errBadToken = xerrors.New("Invalid token")
|
|
// errInvalidPKCE means the PKCE verification failed.
|
|
errInvalidPKCE = xerrors.New("invalid code_verifier")
|
|
// errInvalidResource means the resource parameter validation failed.
|
|
errInvalidResource = xerrors.New("invalid resource parameter")
|
|
// errConflictingClientAuth means the client provided credentials in both the
|
|
// request body and HTTP Basic, but they did not match.
|
|
errConflictingClientAuth = xerrors.New("conflicting client authentication")
|
|
)
|
|
|
|
func extractTokenRequest(r *http.Request, callbackURL *url.URL) (codersdk.OAuth2TokenRequest, []codersdk.ValidationError, error) {
|
|
p := httpapi.NewQueryParamParser()
|
|
err := r.ParseForm()
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenRequest{}, nil, xerrors.Errorf("parse form: %w", err)
|
|
}
|
|
|
|
vals := r.Form
|
|
p.RequiredNotEmpty("grant_type")
|
|
grantType := httpapi.ParseCustom(p, vals, "", "grant_type", httpapi.ParseEnum[codersdk.OAuth2ProviderGrantType])
|
|
|
|
// Grant-type specific validation - must be called before parsing values.
|
|
switch grantType {
|
|
case codersdk.OAuth2ProviderGrantTypeRefreshToken:
|
|
p.RequiredNotEmpty("refresh_token")
|
|
case codersdk.OAuth2ProviderGrantTypeAuthorizationCode:
|
|
p.RequiredNotEmpty("code")
|
|
}
|
|
|
|
req := codersdk.OAuth2TokenRequest{
|
|
GrantType: grantType,
|
|
ClientID: p.String(vals, "", "client_id"),
|
|
ClientSecret: p.String(vals, "", "client_secret"),
|
|
Code: p.String(vals, "", "code"),
|
|
RedirectURI: p.String(vals, "", "redirect_uri"),
|
|
RefreshToken: p.String(vals, "", "refresh_token"),
|
|
CodeVerifier: p.String(vals, "", "code_verifier"),
|
|
Resource: p.String(vals, "", "resource"),
|
|
Scope: p.String(vals, "", "scope"),
|
|
}
|
|
|
|
// RFC 6749 §2.3.1: confidential clients may authenticate via HTTP Basic.
|
|
if user, pass, ok := r.BasicAuth(); ok && user != "" {
|
|
if req.ClientID != "" && req.ClientID != user {
|
|
return codersdk.OAuth2TokenRequest{}, nil, errConflictingClientAuth
|
|
}
|
|
if req.ClientSecret != "" && req.ClientSecret != pass {
|
|
return codersdk.OAuth2TokenRequest{}, nil, errConflictingClientAuth
|
|
}
|
|
|
|
req.ClientID = user
|
|
req.ClientSecret = pass
|
|
}
|
|
|
|
// Grant-specific required checks that can be satisfied via HTTP Basic.
|
|
if req.GrantType == codersdk.OAuth2ProviderGrantTypeAuthorizationCode {
|
|
if req.ClientID == "" {
|
|
p.Errors = append(p.Errors, codersdk.ValidationError{
|
|
Field: "client_id",
|
|
Detail: "Parameter \"client_id\" is required and cannot be empty",
|
|
})
|
|
}
|
|
if req.ClientSecret == "" {
|
|
p.Errors = append(p.Errors, codersdk.ValidationError{
|
|
Field: "client_secret",
|
|
Detail: "Parameter \"client_secret\" is required and cannot be empty",
|
|
})
|
|
}
|
|
}
|
|
|
|
// Validate redirect URI - errors are added to p.Errors.
|
|
_ = p.RedirectURL(vals, callbackURL, "redirect_uri")
|
|
|
|
// Validate resource parameter syntax (RFC 8707): must be absolute URI without fragment.
|
|
if err := validateResourceParameter(req.Resource); err != nil {
|
|
p.Errors = append(p.Errors, codersdk.ValidationError{
|
|
Field: "resource",
|
|
Detail: "must be an absolute URI without fragment",
|
|
})
|
|
}
|
|
|
|
p.ErrorExcessParams(vals)
|
|
if len(p.Errors) > 0 {
|
|
return codersdk.OAuth2TokenRequest{}, p.Errors, xerrors.Errorf("invalid query params: %w", p.Errors)
|
|
}
|
|
return req, nil, nil
|
|
}
|
|
|
|
// Tokens
|
|
// Uses Sessions.DefaultDuration for access token (API key) TTL and
|
|
// Sessions.RefreshDefaultDuration for refresh token TTL.
|
|
func Tokens(db database.Store, lifetimes codersdk.SessionLifetime) http.HandlerFunc {
|
|
return func(rw http.ResponseWriter, r *http.Request) {
|
|
ctx := r.Context()
|
|
app := httpmw.OAuth2ProviderApp(r)
|
|
|
|
callbackURL, err := url.Parse(app.CallbackURL)
|
|
if err != nil {
|
|
httpapi.Write(ctx, rw, http.StatusInternalServerError, codersdk.Response{
|
|
Message: "Failed to validate form values.",
|
|
Detail: err.Error(),
|
|
})
|
|
return
|
|
}
|
|
|
|
req, validationErrs, err := extractTokenRequest(r, callbackURL)
|
|
if err != nil {
|
|
if errors.Is(err, errConflictingClientAuth) {
|
|
httpapi.WriteOAuth2Error(ctx, rw, http.StatusBadRequest, codersdk.OAuth2ErrorCodeInvalidRequest, "Conflicting client credentials between Authorization header and request body")
|
|
return
|
|
}
|
|
|
|
// Check for specific validation errors in priority order
|
|
if slices.ContainsFunc(validationErrs, func(validationError codersdk.ValidationError) bool {
|
|
return validationError.Field == "grant_type"
|
|
}) {
|
|
httpapi.WriteOAuth2Error(ctx, rw, http.StatusBadRequest, codersdk.OAuth2ErrorCodeUnsupportedGrantType, "The grant type is missing or unsupported")
|
|
return
|
|
}
|
|
|
|
// Check for missing required parameters for authorization_code grant
|
|
for _, field := range []string{"code", "client_id", "client_secret"} {
|
|
if slices.ContainsFunc(validationErrs, func(validationError codersdk.ValidationError) bool {
|
|
return validationError.Field == field
|
|
}) {
|
|
httpapi.WriteOAuth2Error(ctx, rw, http.StatusBadRequest, codersdk.OAuth2ErrorCodeInvalidRequest, fmt.Sprintf("Missing required parameter: %s", field))
|
|
return
|
|
}
|
|
}
|
|
// Generic invalid request for other validation errors
|
|
httpapi.WriteOAuth2Error(ctx, rw, http.StatusBadRequest, codersdk.OAuth2ErrorCodeInvalidRequest, "The request is missing required parameters or is otherwise malformed")
|
|
return
|
|
}
|
|
|
|
var token codersdk.OAuth2TokenResponse
|
|
//nolint:gocritic,revive // More cases will be added later.
|
|
switch req.GrantType {
|
|
// TODO: Client creds, device code.
|
|
case codersdk.OAuth2ProviderGrantTypeRefreshToken:
|
|
token, err = refreshTokenGrant(ctx, db, app, lifetimes, req)
|
|
case codersdk.OAuth2ProviderGrantTypeAuthorizationCode:
|
|
token, err = authorizationCodeGrant(ctx, db, app, lifetimes, req)
|
|
default:
|
|
// This should handle truly invalid grant types
|
|
httpapi.WriteOAuth2Error(ctx, rw, http.StatusBadRequest, codersdk.OAuth2ErrorCodeUnsupportedGrantType, fmt.Sprintf("The grant type %q is not supported", req.GrantType))
|
|
return
|
|
}
|
|
|
|
if errors.Is(err, errBadSecret) {
|
|
httpapi.WriteOAuth2Error(ctx, rw, http.StatusUnauthorized, codersdk.OAuth2ErrorCodeInvalidClient, "The client credentials are invalid")
|
|
return
|
|
}
|
|
if errors.Is(err, errBadCode) {
|
|
httpapi.WriteOAuth2Error(ctx, rw, http.StatusBadRequest, codersdk.OAuth2ErrorCodeInvalidGrant, "The authorization code is invalid or expired")
|
|
return
|
|
}
|
|
if errors.Is(err, errInvalidPKCE) {
|
|
httpapi.WriteOAuth2Error(ctx, rw, http.StatusBadRequest, codersdk.OAuth2ErrorCodeInvalidGrant, "The PKCE code verifier is invalid")
|
|
return
|
|
}
|
|
if errors.Is(err, errInvalidResource) {
|
|
httpapi.WriteOAuth2Error(ctx, rw, http.StatusBadRequest, codersdk.OAuth2ErrorCodeInvalidTarget, "The resource parameter is invalid")
|
|
return
|
|
}
|
|
if errors.Is(err, errBadToken) {
|
|
httpapi.WriteOAuth2Error(ctx, rw, http.StatusBadRequest, codersdk.OAuth2ErrorCodeInvalidGrant, "The refresh token is invalid or expired")
|
|
return
|
|
}
|
|
if err != nil {
|
|
httpapi.Write(ctx, rw, http.StatusInternalServerError, codersdk.Response{
|
|
Message: "Failed to exchange token",
|
|
Detail: err.Error(),
|
|
})
|
|
return
|
|
}
|
|
|
|
// Some client libraries allow this to be "application/x-www-form-urlencoded". We can implement that upon
|
|
// request. The same libraries should also accept JSON. If implemented, choose based on "Accept" header.
|
|
httpapi.Write(ctx, rw, http.StatusOK, token)
|
|
}
|
|
}
|
|
|
|
func authorizationCodeGrant(ctx context.Context, db database.Store, app database.OAuth2ProviderApp, lifetimes codersdk.SessionLifetime, req codersdk.OAuth2TokenRequest) (codersdk.OAuth2TokenResponse, error) {
|
|
// Validate the client secret.
|
|
secret, err := ParseFormattedSecret(req.ClientSecret)
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, errBadSecret
|
|
}
|
|
//nolint:gocritic // Users cannot read secrets so we must use the system.
|
|
dbSecret, err := db.GetOAuth2ProviderAppSecretByPrefix(dbauthz.AsSystemRestricted(ctx), []byte(secret.Prefix))
|
|
if errors.Is(err, sql.ErrNoRows) {
|
|
return codersdk.OAuth2TokenResponse{}, errBadSecret
|
|
}
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, err
|
|
}
|
|
|
|
equalSecret := apikey.ValidateHash(dbSecret.HashedSecret, secret.Secret)
|
|
if !equalSecret {
|
|
return codersdk.OAuth2TokenResponse{}, errBadSecret
|
|
}
|
|
|
|
// Validate the authorization code.
|
|
code, err := ParseFormattedSecret(req.Code)
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, errBadCode
|
|
}
|
|
//nolint:gocritic // There is no user yet so we must use the system.
|
|
dbCode, err := db.GetOAuth2ProviderAppCodeByPrefix(dbauthz.AsSystemRestricted(ctx), []byte(code.Prefix))
|
|
if errors.Is(err, sql.ErrNoRows) {
|
|
return codersdk.OAuth2TokenResponse{}, errBadCode
|
|
}
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, err
|
|
}
|
|
equalCode := apikey.ValidateHash(dbCode.HashedSecret, code.Secret)
|
|
if !equalCode {
|
|
return codersdk.OAuth2TokenResponse{}, errBadCode
|
|
}
|
|
|
|
// Ensure the code has not expired.
|
|
if dbCode.ExpiresAt.Before(dbtime.Now()) {
|
|
return codersdk.OAuth2TokenResponse{}, errBadCode
|
|
}
|
|
|
|
// Verify redirect_uri matches the one used during authorization
|
|
// (RFC 6749 §4.1.3).
|
|
if dbCode.RedirectUri.Valid && dbCode.RedirectUri.String != "" {
|
|
if req.RedirectURI != dbCode.RedirectUri.String {
|
|
return codersdk.OAuth2TokenResponse{}, errBadCode
|
|
}
|
|
}
|
|
|
|
// PKCE is mandatory for all authorization code flows
|
|
// (OAuth 2.1). Verify the code verifier against the stored
|
|
// challenge.
|
|
if req.CodeVerifier == "" {
|
|
return codersdk.OAuth2TokenResponse{}, errInvalidPKCE
|
|
}
|
|
if !dbCode.CodeChallenge.Valid || dbCode.CodeChallenge.String == "" {
|
|
// Code was issued without a challenge — should not happen
|
|
// with authorize endpoint enforcement, but defend in depth.
|
|
return codersdk.OAuth2TokenResponse{}, errInvalidPKCE
|
|
}
|
|
if !VerifyPKCE(dbCode.CodeChallenge.String, req.CodeVerifier) {
|
|
return codersdk.OAuth2TokenResponse{}, errInvalidPKCE
|
|
}
|
|
|
|
// Verify resource parameter consistency (RFC 8707)
|
|
if dbCode.ResourceUri.Valid && dbCode.ResourceUri.String != "" {
|
|
// Resource was specified during authorization - it must match in token request
|
|
if req.Resource == "" {
|
|
return codersdk.OAuth2TokenResponse{}, errInvalidResource
|
|
}
|
|
if req.Resource != dbCode.ResourceUri.String {
|
|
return codersdk.OAuth2TokenResponse{}, errInvalidResource
|
|
}
|
|
} else if req.Resource != "" {
|
|
// Resource was not specified during authorization but is now provided
|
|
return codersdk.OAuth2TokenResponse{}, errInvalidResource
|
|
}
|
|
|
|
// Generate a refresh token.
|
|
refreshToken, err := GenerateSecret()
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, err
|
|
}
|
|
|
|
// Generate the API key we will swap for the code.
|
|
// TODO: We are ignoring scopes for now.
|
|
tokenName := fmt.Sprintf("%s_%s_oauth_session_token", dbCode.UserID, app.ID)
|
|
key, sessionToken, err := apikey.Generate(apikey.CreateParams{
|
|
UserID: dbCode.UserID,
|
|
LoginType: database.LoginTypeOAuth2ProviderApp,
|
|
DefaultLifetime: lifetimes.DefaultDuration.Value(),
|
|
// For now, we allow only one token per app and user at a time.
|
|
TokenName: tokenName,
|
|
})
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, err
|
|
}
|
|
|
|
// Grab the user roles so we can perform the exchange as the user.
|
|
actor, _, err := httpmw.UserRBACSubject(ctx, db, dbCode.UserID, rbac.ScopeAll)
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, xerrors.Errorf("fetch user actor: %w", err)
|
|
}
|
|
|
|
// Do the actual token exchange in the database.
|
|
// Determine refresh token expiry independently from the access token.
|
|
refreshLifetime := lifetimes.RefreshDefaultDuration.Value()
|
|
if refreshLifetime == 0 {
|
|
refreshLifetime = lifetimes.DefaultDuration.Value()
|
|
}
|
|
refreshExpiresAt := dbtime.Now().Add(refreshLifetime)
|
|
|
|
err = db.InTx(func(tx database.Store) error {
|
|
ctx := dbauthz.As(ctx, actor)
|
|
err = tx.DeleteOAuth2ProviderAppCodeByID(ctx, dbCode.ID)
|
|
if err != nil {
|
|
return xerrors.Errorf("delete oauth2 app code: %w", err)
|
|
}
|
|
|
|
// Delete the previous key, if any.
|
|
prevKey, err := tx.GetAPIKeyByName(ctx, database.GetAPIKeyByNameParams{
|
|
UserID: dbCode.UserID,
|
|
TokenName: tokenName,
|
|
})
|
|
if err == nil {
|
|
err = tx.DeleteAPIKeyByID(ctx, prevKey.ID)
|
|
}
|
|
if err != nil && !errors.Is(err, sql.ErrNoRows) {
|
|
return xerrors.Errorf("delete api key by name: %w", err)
|
|
}
|
|
|
|
newKey, err := tx.InsertAPIKey(ctx, key)
|
|
if err != nil {
|
|
return xerrors.Errorf("insert oauth2 access token: %w", err)
|
|
}
|
|
|
|
_, err = tx.InsertOAuth2ProviderAppToken(ctx, database.InsertOAuth2ProviderAppTokenParams{
|
|
ID: uuid.New(),
|
|
CreatedAt: dbtime.Now(),
|
|
ExpiresAt: refreshExpiresAt,
|
|
HashPrefix: []byte(refreshToken.Prefix),
|
|
RefreshHash: refreshToken.Hashed,
|
|
AppSecretID: dbSecret.ID,
|
|
APIKeyID: newKey.ID,
|
|
UserID: dbCode.UserID,
|
|
Audience: dbCode.ResourceUri,
|
|
})
|
|
if err != nil {
|
|
return xerrors.Errorf("insert oauth2 refresh token: %w", err)
|
|
}
|
|
return nil
|
|
}, nil)
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, err
|
|
}
|
|
|
|
return codersdk.OAuth2TokenResponse{
|
|
AccessToken: sessionToken,
|
|
TokenType: codersdk.OAuth2TokenTypeBearer,
|
|
RefreshToken: refreshToken.Formatted,
|
|
ExpiresIn: int64(time.Until(key.ExpiresAt).Seconds()),
|
|
Expiry: &key.ExpiresAt,
|
|
}, nil
|
|
}
|
|
|
|
func refreshTokenGrant(ctx context.Context, db database.Store, app database.OAuth2ProviderApp, lifetimes codersdk.SessionLifetime, req codersdk.OAuth2TokenRequest) (codersdk.OAuth2TokenResponse, error) {
|
|
// Validate the token.
|
|
token, err := ParseFormattedSecret(req.RefreshToken)
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, errBadToken
|
|
}
|
|
//nolint:gocritic // There is no user yet so we must use the system.
|
|
dbToken, err := db.GetOAuth2ProviderAppTokenByPrefix(dbauthz.AsSystemRestricted(ctx), []byte(token.Prefix))
|
|
if errors.Is(err, sql.ErrNoRows) {
|
|
return codersdk.OAuth2TokenResponse{}, errBadToken
|
|
}
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, err
|
|
}
|
|
equal := apikey.ValidateHash(dbToken.RefreshHash, token.Secret)
|
|
if !equal {
|
|
return codersdk.OAuth2TokenResponse{}, errBadToken
|
|
}
|
|
|
|
// Ensure the token has not expired.
|
|
if dbToken.ExpiresAt.Before(dbtime.Now()) {
|
|
return codersdk.OAuth2TokenResponse{}, errBadToken
|
|
}
|
|
|
|
// Verify resource parameter consistency for refresh tokens (RFC 8707)
|
|
if req.Resource != "" {
|
|
// If resource is provided in refresh request, it must match the original token's audience
|
|
if !dbToken.Audience.Valid || dbToken.Audience.String != req.Resource {
|
|
return codersdk.OAuth2TokenResponse{}, errInvalidResource
|
|
}
|
|
}
|
|
|
|
// Grab the user roles so we can perform the refresh as the user.
|
|
//nolint:gocritic // There is no user yet so we must use the system.
|
|
prevKey, err := db.GetAPIKeyByID(dbauthz.AsSystemRestricted(ctx), dbToken.APIKeyID)
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, err
|
|
}
|
|
|
|
actor, _, err := httpmw.UserRBACSubject(ctx, db, prevKey.UserID, rbac.ScopeAll)
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, xerrors.Errorf("fetch user actor: %w", err)
|
|
}
|
|
|
|
// Generate a new refresh token.
|
|
refreshToken, err := GenerateSecret()
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, err
|
|
}
|
|
|
|
// Generate the new API key.
|
|
// TODO: We are ignoring scopes for now.
|
|
tokenName := fmt.Sprintf("%s_%s_oauth_session_token", prevKey.UserID, app.ID)
|
|
key, sessionToken, err := apikey.Generate(apikey.CreateParams{
|
|
UserID: prevKey.UserID,
|
|
LoginType: database.LoginTypeOAuth2ProviderApp,
|
|
DefaultLifetime: lifetimes.DefaultDuration.Value(),
|
|
// For now, we allow only one token per app and user at a time.
|
|
TokenName: tokenName,
|
|
})
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, err
|
|
}
|
|
|
|
// Replace the token.
|
|
// Determine refresh token expiry independently from the access token.
|
|
refreshLifetime := lifetimes.RefreshDefaultDuration.Value()
|
|
if refreshLifetime == 0 {
|
|
refreshLifetime = lifetimes.DefaultDuration.Value()
|
|
}
|
|
refreshExpiresAt := dbtime.Now().Add(refreshLifetime)
|
|
|
|
err = db.InTx(func(tx database.Store) error {
|
|
ctx := dbauthz.As(ctx, actor)
|
|
err = tx.DeleteAPIKeyByID(ctx, prevKey.ID) // This cascades to the token.
|
|
if err != nil {
|
|
return xerrors.Errorf("delete oauth2 app token: %w", err)
|
|
}
|
|
|
|
newKey, err := tx.InsertAPIKey(ctx, key)
|
|
if err != nil {
|
|
return xerrors.Errorf("insert oauth2 access token: %w", err)
|
|
}
|
|
|
|
_, err = tx.InsertOAuth2ProviderAppToken(ctx, database.InsertOAuth2ProviderAppTokenParams{
|
|
ID: uuid.New(),
|
|
CreatedAt: dbtime.Now(),
|
|
ExpiresAt: refreshExpiresAt,
|
|
HashPrefix: []byte(refreshToken.Prefix),
|
|
RefreshHash: refreshToken.Hashed,
|
|
AppSecretID: dbToken.AppSecretID,
|
|
APIKeyID: newKey.ID,
|
|
UserID: dbToken.UserID,
|
|
Audience: dbToken.Audience,
|
|
})
|
|
if err != nil {
|
|
return xerrors.Errorf("insert oauth2 refresh token: %w", err)
|
|
}
|
|
return nil
|
|
}, nil)
|
|
if err != nil {
|
|
return codersdk.OAuth2TokenResponse{}, err
|
|
}
|
|
|
|
return codersdk.OAuth2TokenResponse{
|
|
AccessToken: sessionToken,
|
|
TokenType: codersdk.OAuth2TokenTypeBearer,
|
|
RefreshToken: refreshToken.Formatted,
|
|
ExpiresIn: int64(time.Until(key.ExpiresAt).Seconds()),
|
|
Expiry: &key.ExpiresAt,
|
|
}, nil
|
|
}
|
|
|
|
// validateResourceParameter validates that a resource parameter conforms to RFC 8707:
|
|
// must be an absolute URI without fragment component.
|
|
func validateResourceParameter(resource string) error {
|
|
if resource == "" {
|
|
return nil // Resource parameter is optional
|
|
}
|
|
|
|
u, err := url.Parse(resource)
|
|
if err != nil {
|
|
return xerrors.Errorf("invalid URI syntax: %w", err)
|
|
}
|
|
|
|
if u.Scheme == "" {
|
|
return xerrors.New("must be an absolute URI with scheme")
|
|
}
|
|
|
|
if u.Fragment != "" {
|
|
return xerrors.New("must not contain fragment component")
|
|
}
|
|
|
|
return nil
|
|
}
|