Wave M: a browser signs in through an external OIDC IdP, and a credential is exchanged for one
another platform accepts. Three stories, each attacked twice.
Added
- OIDC relying-party flow.
GET /v1/federation/authorizeredirects to the IdP's discoveredauthorization_endpoint
with a single-usestate, anonceand an S256 PKCE challenge, bound to the browser by a
__Host-cookie.GET /v1/federation/callbackredeems the code at the discoveredtoken_endpointwith HTTP
Basic client authentication. It requires RFC 9207isswhen the IdP advertises it, verifies
the ID token and itsnonce, and opens a session.- The session reaches the embedding application only through a single-use handoff code sent to
the connection'sreturn_uriand redeemed once atPOST /v1/federation/handoff, together with
theapp_statethe application supplied. - The client secret is read from
--client-secret-file NAME=PATH. - A relying-party connection refuses direct
/v1/federation/login. - (
story:relying-party-code-flow)
- RFC 8693 token exchange at
/oauth/token.- A Mandate access credential is exchanged for a credential for a resource server whose
allowed_exchange_sourceslists the subject's. - The target is named by id, by registered audience or by
resource. - Refusals answer
invalid_targetorinvalid_grantfrom one table, are recorded as
TokenExchangeDeniedand draw nothing. The metadata document advertises the grant. - (
story:federated-token-exchange)
- A Mandate access credential is exchanged for a credential for a resource server whose
Changed
- A tenant claim the connection's rule names that is not a JSON string is refused as
TenantClaimNotText(<type>), where before it resolved silently to no tenant
(story:federation-fixtures-rs256). - The transport gap and the roadmap state that TLS is terminated at the ingress and the hop from the
ingress to the process is plain HTTP.
Known
- An anonymous flood of authorize requests can evict a waiting browser's sign-in; rate limiting is
the ingress's (story:authorize-flood-eviction). - A slow IdP stalls every route on the single-threaded listener (
story:listener-outbound-stall). - Nothing persists: a restart loses sessions, pending sign-ins, handoff codes and credentials.