Commit 80a42aa
authored
fix(idp): RFC 9207 iss param matches discovery issuer — normalize in createProvider (JavaScriptSolidServer#524) (JavaScriptSolidServer#551)
The discovery handler normalizes the `issuer` field of
/.well-known/openid-configuration to the trailing-slash form, but
oidc-provider was constructed with the RAW configured issuer. The
provider's issuer feeds the RFC 9207 `iss` authorization-response
parameter and the `iss` claim in issued tokens, so with an issuer
configured slash-free:
discovery issuer → http://host:port/
callback iss → http://host:port
RFC 9207 requires byte-identity; strict clients (solid-oidc's
handleRedirectFromLogin) rejected the callback BEFORE the token
request fired and sign-in silently bounced. Reproduced on Android /
nodejs-mobile (JavaScriptSolidServer#522), where it was the final blocker to a working
on-device login.
Fix: normalize inside createProvider with the same expression the
discovery handler uses, with bidirectional sync comments on both
sites so neither normalization can drift silently.
Blast-radius notes (verified before landing):
- Internal verification is slash-tolerant: addTrustedIssuer and
getOidcConfig strip trailing slashes; JWKS verification uses the
token's own iss (self-consistent).
- The discovery doc is unchanged (idp.test.js:62 keeps asserting
issuer === baseUrl + '/').
- handleCredentials' programmatic-token iss stamp (credentials.js:119)
is deliberately NOT touched: those tokens have their own
verification path and no RFC 9207 involvement.
Tests (test/idp-issuer-normalization.test.js, 3 cases): slash-free
issuer gains the slash, already-slashed passes through, and the
cross-component pin — provider.issuer byte-equals the discovery
issuer fetched from a running server, the exact comparison strict
clients perform.
Full suite: 937/937 passing.
Closes JavaScriptSolidServer#524.1 parent 666f7db commit 80a42aa
3 files changed
Lines changed: 116 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
219 | 219 | | |
220 | 220 | | |
221 | 221 | | |
222 | | - | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
223 | 227 | | |
224 | 228 | | |
225 | 229 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
91 | 91 | | |
92 | 92 | | |
93 | 93 | | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
94 | 105 | | |
95 | 106 | | |
96 | 107 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
0 commit comments