nagaboinaramgopal opened a new pull request, #14296:
URL: https://github.com/apache/cloudstack/pull/14296

   ### Description
   
   Follow-up to #14205. Hardens the generic OIDC login by binding it to the 
authorization request with a nonce and a per-attempt state, as raised in review.
   
   On login the UI generates a random nonce and state, stores them, and sends 
the nonce in the authorization request. On the callback it rejects the request 
when the returned state does not match the stored one, before the code is 
exchanged, which closes the login CSRF where state was fixed to `cloudstack`. 
The backend verifies the id_token nonce claim against the nonce from the 
request. Only the generic OIDC provider checks the nonce, and the state check 
only applies to the OIDC flow (the built-in providers do not set it), so the 
google, github and keycloak logins are unchanged. The nonce travels 
`verifyOAuthCodeAndGetUser` to `OAuth2AuthManager` to `UserOAuth2Authenticator` 
to `GenericOIDCOAuth2Provider.validateAndExtractEmail`, carried by a new 
`nonce` API parameter.
   
   Depends on #14205.
   
   ### Types of changes
   
   - [ ] Breaking change (fix or feature that would cause existing 
functionality to change)
   - [ ] New feature (non-breaking change which adds functionality)
   - [ ] Bug fix (non-breaking change which fixes an issue)
   - [x] Enhancement (improves an existing feature and functionality)
   - [ ] Cleanup (Code refactoring and cleanup, that may add test cases)
   - [ ] Build/CI
   - [ ] Test (unit or integration test code)
   
   ### How Has This Been Tested?
   
   Unit tests in the oauth2 plugin: a matching nonce is accepted and a 
mismatched nonce is rejected in `GenericOIDCOAuth2ProviderTest`; the existing 
signature and claim tests still pass.
   
   Not yet verified end to end against a live identity provider or in a 
browser, which needs a real IdP. The frontend state and nonce round trip has 
been reviewed by hand but not run.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to