MCPcopy Create free account
hub / github.com/zitadel/oidc / AuthorizeCodeClient

Function AuthorizeCodeClient

pkg/op/token_code.go:74–123  ·  view source on GitHub ↗

AuthorizeCodeClient checks the authorization of the client and that the used method was the one previously registered. It than returns the auth request corresponding to the auth code

(ctx context.Context, tokenReq *oidc.AccessTokenRequest, exchanger Exchanger)

Source from the content-addressed store, hash-verified

72// AuthorizeCodeClient checks the authorization of the client and that the used method was the one previously registered.
73// It than returns the auth request corresponding to the auth code
74func AuthorizeCodeClient(ctx context.Context, tokenReq *oidc.AccessTokenRequest, exchanger Exchanger) (request AuthRequest, client Client, err error) {
75 ctx, span := Tracer.Start(ctx, "AuthorizeCodeClient")
76 defer span.End()
77
78 request, err = AuthRequestByCode(ctx, exchanger.Storage(), tokenReq.Code)
79 if err != nil {
80 return nil, nil, err
81 }
82
83 codeChallenge := request.GetCodeChallenge()
84 err = AuthorizeCodeChallenge(tokenReq.CodeVerifier, codeChallenge)
85 if err != nil {
86 return nil, nil, err
87 }
88
89 if tokenReq.ClientAssertionType == oidc.ClientAssertionTypeJWTAssertion {
90 jwtExchanger, ok := exchanger.(JWTAuthorizationGrantExchanger)
91 if !ok || !exchanger.AuthMethodPrivateKeyJWTSupported() {
92 return nil, nil, oidc.ErrInvalidClient().WithDescription("auth_method private_key_jwt not supported")
93 }
94 client, err = AuthorizePrivateJWTKey(ctx, tokenReq.ClientAssertion, jwtExchanger)
95 if err != nil {
96 return nil, nil, err
97 }
98 return request, client, err
99 }
100
101 client, err = exchanger.Storage().GetClientByClientID(ctx, tokenReq.ClientID)
102 if err != nil {
103 return nil, nil, oidc.ErrInvalidClient().WithParent(err)
104 }
105 if client.AuthMethod() == oidc.AuthMethodPrivateKeyJWT {
106 return nil, nil, oidc.ErrInvalidClient().WithDescription("private_key_jwt not allowed for this client")
107 }
108 if client.AuthMethod() == oidc.AuthMethodNone {
109 if codeChallenge == nil {
110 return nil, nil, oidc.ErrInvalidRequest().WithDescription("PKCE required")
111 }
112 return request, client, nil
113 }
114 if client.AuthMethod() == oidc.AuthMethodPost && !exchanger.AuthMethodPostSupported() {
115 return nil, nil, oidc.ErrInvalidClient().WithDescription("auth_method post not supported")
116 }
117 err = AuthorizeClientIDSecret(ctx, tokenReq.ClientID, tokenReq.ClientSecret, exchanger.Storage())
118 if err != nil {
119 return nil, nil, err
120 }
121
122 return request, client, err
123}
124
125// AuthRequestByCode returns the AuthRequest previously created from Storage corresponding to the auth code or an error
126func AuthRequestByCode(ctx context.Context, storage Storage, code string) (AuthRequest, error) {

Callers 1

Calls 14

AuthRequestByCodeFunction · 0.85
AuthorizeCodeChallengeFunction · 0.85
AuthorizePrivateJWTKeyFunction · 0.85
AuthorizeClientIDSecretFunction · 0.85
StartMethod · 0.80
EndMethod · 0.80
WithDescriptionMethod · 0.80
WithParentMethod · 0.80
StorageMethod · 0.65
GetCodeChallengeMethod · 0.65
GetClientByClientIDMethod · 0.65

Tested by

no test coverage detected