mirror of
https://github.com/tiennm99/DocsGPT.git
synced 2026-10-03 20:12:55 +00:00
Address the high/medium correctness findings on the OIDC/SCIM PR: - Login CSRF / session fixation: bind `state` to a Secure/HttpOnly/SameSite=Lax cookie at login and require the callback to echo it, so a code+state captured from another browser can't silently sign a victim into the attacker's account. - Require `exp` on session JWTs under AUTH_TYPE=oidc (require_exp), so an exp-less HS256 token signed with JWT_SECRET_KEY can't authenticate forever or outlive the denylist. - Denylist now keys revocation on an `iat` watermark instead of a deletable flag: a fresh login (newer iat) self-supersedes a revocation without clearing it, so sessions revoked on other devices stay revoked. Drops the login/SCIM-reactivation denylist-clearing paths (allow_user/allow_idp_sub). - Refresh: gate the disabled-account check on the post-grant identity (not just the old sub); attempt the IdP grant before consuming the refresh token and return a retryable 503 (restoring the token) on transient IdP errors instead of force-logging-out a live session. - Gate the oidc blueprint at request time on AUTH_TYPE=oidc, so non-oidc deployments cleanly 404 these routes instead of 500-ing on an unset OIDC_ISSUER (mirrors SCIM_ENABLED). - Surface revocation write failures: back-channel logout returns 502, and SCIM deactivation rolls back and returns 503, when the denylist write fails — so the IdP retries instead of recording a logout/deprovision that didn't revoke. - Back-channel logout: require `jti`, run the replay check unconditionally, and reject stale `iat` beyond the replay-cache window. - Make migration 0017 idempotent (IF NOT EXISTS) so re-apply can't wedge startup. - SCIM userName matching is case-insensitive (caseExact=false) for the list filter and create-dedup. Tests added/updated across test_oidc.py, test_scim.py, test_auth.py, test_app_routes.py and the SCIM integration test.
42 lines
1.5 KiB
Python
42 lines
1.5 KiB
Python
from jose import jwt
|
|
from jose.exceptions import ExpiredSignatureError
|
|
|
|
from application.core.settings import settings
|
|
|
|
|
|
def handle_auth(request, data={}):
|
|
if settings.AUTH_TYPE in ["simple_jwt", "session_jwt", "oidc"]:
|
|
jwt_token = request.headers.get("Authorization")
|
|
if not jwt_token:
|
|
return None
|
|
|
|
jwt_token = jwt_token.replace("Bearer ", "")
|
|
|
|
is_oidc = settings.AUTH_TYPE == "oidc"
|
|
try:
|
|
decoded_token = jwt.decode(
|
|
jwt_token,
|
|
settings.JWT_SECRET_KEY,
|
|
algorithms=["HS256"],
|
|
# oidc sessions are minted with an exp at the login callback and
|
|
# must carry one: require_exp rejects any exp-less HS256 token
|
|
# signed with JWT_SECRET_KEY (e.g. a legacy simple_jwt/session_jwt
|
|
# token), which would otherwise authenticate forever and be
|
|
# unrevocable. simple_jwt/session_jwt never carried an exp, so the
|
|
# requirement is scoped to oidc.
|
|
options={"verify_exp": is_oidc, "require_exp": is_oidc},
|
|
)
|
|
return decoded_token
|
|
except ExpiredSignatureError:
|
|
return {
|
|
"message": "Authentication error: token expired",
|
|
"error": "token_expired",
|
|
}
|
|
except Exception:
|
|
return {
|
|
"message": "Authentication error: invalid token",
|
|
"error": "invalid_token",
|
|
}
|
|
else:
|
|
return {"sub": "local"}
|