fix(auth): persist PKCE state in sessionStorage
Store OIDC code_verifier and state in sessionStorage instead of static memory variables. This fixes the "No code verifier" error that occurred after Authentik redirect because the Flutter app restarts and loses in-memory state. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.5
parent
4c377b19c4
commit
0a6e9de4a8
@@ -8,6 +8,7 @@ import 'package:dio/dio.dart';
|
||||
|
||||
import '../config/app_config.dart';
|
||||
import 'oidc_service.dart';
|
||||
import 'web_utils.dart' as web_utils;
|
||||
|
||||
/// Web implementation of OIDC service using browser redirect flow.
|
||||
///
|
||||
@@ -25,9 +26,9 @@ class OidcServiceWeb implements OidcService {
|
||||
/// Redirect URI for web.
|
||||
static String get _redirectUri => '${AppConfig.webBaseUrl}/callback';
|
||||
|
||||
// PKCE state stored during auth flow (in-memory for single-page app)
|
||||
static String? _codeVerifier;
|
||||
static String? _state;
|
||||
// SessionStorage keys for PKCE state (persists across redirect)
|
||||
static const _codeVerifierKey = 'oidc_code_verifier';
|
||||
static const _stateKey = 'oidc_state';
|
||||
|
||||
/// Get the authorization URL to redirect the browser to.
|
||||
///
|
||||
@@ -39,11 +40,15 @@ class OidcServiceWeb implements OidcService {
|
||||
final authEndpoint = discovery['authorization_endpoint'] as String;
|
||||
|
||||
// Generate PKCE code verifier and challenge
|
||||
_codeVerifier = _generateCodeVerifier();
|
||||
final codeChallenge = _generateCodeChallenge(_codeVerifier!);
|
||||
final codeVerifier = _generateCodeVerifier();
|
||||
final codeChallenge = _generateCodeChallenge(codeVerifier);
|
||||
|
||||
// Generate state for CSRF protection
|
||||
_state = _generateRandomString(32);
|
||||
final state = _generateRandomString(32);
|
||||
|
||||
// Store PKCE state in sessionStorage (persists across redirect)
|
||||
web_utils.setSessionStorage(_codeVerifierKey, codeVerifier);
|
||||
web_utils.setSessionStorage(_stateKey, state);
|
||||
|
||||
// Build authorization URL
|
||||
final params = {
|
||||
@@ -53,7 +58,7 @@ class OidcServiceWeb implements OidcService {
|
||||
'scope': _scopes.join(' '),
|
||||
'code_challenge': codeChallenge,
|
||||
'code_challenge_method': 'S256',
|
||||
'state': _state,
|
||||
'state': state,
|
||||
};
|
||||
|
||||
final uri = Uri.parse(authEndpoint).replace(queryParameters: params);
|
||||
@@ -67,12 +72,21 @@ class OidcServiceWeb implements OidcService {
|
||||
/// [code] is the authorization code from the callback URL.
|
||||
/// [state] is the state parameter from the callback URL (verified for CSRF).
|
||||
Future<OidcTokens> exchangeCode(String code, String state) async {
|
||||
// Retrieve PKCE state from sessionStorage
|
||||
final storedState = web_utils.getSessionStorage(_stateKey);
|
||||
final codeVerifier = web_utils.getSessionStorage(_codeVerifierKey);
|
||||
|
||||
developer.log('Stored state: $storedState, received state: $state', name: 'oidc_web');
|
||||
developer.log('Code verifier present: ${codeVerifier != null}', name: 'oidc_web');
|
||||
|
||||
// Verify state matches
|
||||
if (_state == null || state != _state) {
|
||||
if (storedState == null || state != storedState) {
|
||||
_clearPkceState();
|
||||
throw OidcException('State mismatch - possible CSRF attack');
|
||||
}
|
||||
|
||||
if (_codeVerifier == null) {
|
||||
if (codeVerifier == null) {
|
||||
_clearPkceState();
|
||||
throw OidcException('No code verifier - flow not started properly');
|
||||
}
|
||||
|
||||
@@ -91,7 +105,7 @@ class OidcServiceWeb implements OidcService {
|
||||
'client_id': AppConfig.authClientId,
|
||||
'redirect_uri': _redirectUri,
|
||||
'code': code,
|
||||
'code_verifier': _codeVerifier,
|
||||
'code_verifier': codeVerifier,
|
||||
},
|
||||
options: Options(
|
||||
contentType: Headers.formUrlEncodedContentType,
|
||||
@@ -102,8 +116,7 @@ class OidcServiceWeb implements OidcService {
|
||||
developer.log('Token exchange successful', name: 'oidc_web');
|
||||
|
||||
// Clear stored PKCE state
|
||||
_codeVerifier = null;
|
||||
_state = null;
|
||||
_clearPkceState();
|
||||
|
||||
return OidcTokens(
|
||||
accessToken: data['access_token'] as String,
|
||||
@@ -115,14 +128,17 @@ class OidcServiceWeb implements OidcService {
|
||||
);
|
||||
} on DioException catch (e) {
|
||||
developer.log('Token exchange failed: $e', name: 'oidc_web');
|
||||
_clearPkceState();
|
||||
throw OidcException('Token exchange failed: ${e.message}');
|
||||
} finally {
|
||||
// Clear PKCE state on error too
|
||||
_codeVerifier = null;
|
||||
_state = null;
|
||||
}
|
||||
}
|
||||
|
||||
/// Clear PKCE state from sessionStorage.
|
||||
void _clearPkceState() {
|
||||
web_utils.removeSessionStorage(_codeVerifierKey);
|
||||
web_utils.removeSessionStorage(_stateKey);
|
||||
}
|
||||
|
||||
/// Not used on web - use [getAuthorizationUrl] and [exchangeCode] instead.
|
||||
@override
|
||||
Future<OidcTokens> signIn() async {
|
||||
|
||||
@@ -15,3 +15,18 @@ String getCurrentUrl() {
|
||||
void replaceUrl(String url) {
|
||||
throw UnsupportedError('replaceUrl is only supported on web');
|
||||
}
|
||||
|
||||
/// Store a value in sessionStorage (no-op on non-web).
|
||||
void setSessionStorage(String key, String value) {
|
||||
throw UnsupportedError('setSessionStorage is only supported on web');
|
||||
}
|
||||
|
||||
/// Get a value from sessionStorage (no-op on non-web).
|
||||
String? getSessionStorage(String key) {
|
||||
throw UnsupportedError('getSessionStorage is only supported on web');
|
||||
}
|
||||
|
||||
/// Remove a value from sessionStorage (no-op on non-web).
|
||||
void removeSessionStorage(String key) {
|
||||
throw UnsupportedError('removeSessionStorage is only supported on web');
|
||||
}
|
||||
|
||||
@@ -17,3 +17,18 @@ String getCurrentUrl() {
|
||||
void replaceUrl(String url) {
|
||||
web.window.history.replaceState(null, '', url);
|
||||
}
|
||||
|
||||
/// Store a value in sessionStorage.
|
||||
void setSessionStorage(String key, String value) {
|
||||
web.window.sessionStorage.setItem(key, value);
|
||||
}
|
||||
|
||||
/// Get a value from sessionStorage.
|
||||
String? getSessionStorage(String key) {
|
||||
return web.window.sessionStorage.getItem(key);
|
||||
}
|
||||
|
||||
/// Remove a value from sessionStorage.
|
||||
void removeSessionStorage(String key) {
|
||||
web.window.sessionStorage.removeItem(key);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user