Fix again, didn't work
This commit is contained in:
+20
-22
@@ -16,7 +16,7 @@ from datetime import UTC, datetime
|
|||||||
from uuid import UUID
|
from uuid import UUID
|
||||||
|
|
||||||
import base64url
|
import base64url
|
||||||
from fastapi import Body, Depends, FastAPI, HTTPException, Request
|
from fastapi import Depends, FastAPI, Form, HTTPException, Request
|
||||||
from fastapi.responses import JSONResponse
|
from fastapi.responses import JSONResponse
|
||||||
from fastapi.security import HTTPBearer
|
from fastapi.security import HTTPBearer
|
||||||
|
|
||||||
@@ -99,13 +99,13 @@ def _parse_client_credentials(
|
|||||||
@app.post("/token")
|
@app.post("/token")
|
||||||
async def token(
|
async def token(
|
||||||
request: Request,
|
request: Request,
|
||||||
grant_type: str | None = Body(None, embed=False),
|
grant_type: str = Form(...),
|
||||||
code: str | None = Body(None, embed=False),
|
code: str | None = Form(None),
|
||||||
redirect_uri: str | None = Body(None, embed=False),
|
redirect_uri: str | None = Form(None),
|
||||||
client_id: str | None = Body(None, embed=False),
|
client_id: str | None = Form(None),
|
||||||
client_secret: str | None = Body(None, embed=False),
|
client_secret: str | None = Form(None),
|
||||||
code_verifier: str | None = Body(None, embed=False),
|
code_verifier: str | None = Form(None),
|
||||||
refresh_token: str | None = Body(None, embed=False),
|
refresh_token: str | None = Form(None),
|
||||||
):
|
):
|
||||||
"""OIDC Token endpoint.
|
"""OIDC Token endpoint.
|
||||||
|
|
||||||
@@ -114,23 +114,21 @@ async def token(
|
|||||||
- grant_type=refresh_token: Refresh access token using sid
|
- grant_type=refresh_token: Refresh access token using sid
|
||||||
|
|
||||||
Supports client_secret_post and client_secret_basic authentication.
|
Supports client_secret_post and client_secret_basic authentication.
|
||||||
|
Per RFC 6749 Section 4.1.3: MUST use POST with application/x-www-form-urlencoded.
|
||||||
"""
|
"""
|
||||||
# Parse form data (OAuth uses application/x-www-form-urlencoded)
|
|
||||||
content_type = request.headers.get("content-type", "")
|
|
||||||
if "application/x-www-form-urlencoded" in content_type:
|
|
||||||
form = await request.form()
|
|
||||||
grant_type = form.get("grant_type", grant_type)
|
|
||||||
code = form.get("code", code)
|
|
||||||
redirect_uri = form.get("redirect_uri", redirect_uri)
|
|
||||||
client_id = form.get("client_id", client_id)
|
|
||||||
client_secret = form.get("client_secret", client_secret)
|
|
||||||
code_verifier = form.get("code_verifier", code_verifier)
|
|
||||||
refresh_token = form.get("refresh_token", refresh_token)
|
|
||||||
|
|
||||||
# Validate grant_type is present
|
# RFC 6749: Token endpoint MUST NOT accept query parameters
|
||||||
if not grant_type:
|
if request.url.query:
|
||||||
return JSONResponse(
|
return JSONResponse(
|
||||||
{"error": "invalid_request", "error_description": "Missing grant_type"},
|
{"error": "invalid_request", "error_description": "Query parameters not allowed"},
|
||||||
|
status_code=400,
|
||||||
|
)
|
||||||
|
|
||||||
|
# RFC 6749: MUST use application/x-www-form-urlencoded
|
||||||
|
content_type = request.headers.get("content-type", "")
|
||||||
|
if "application/x-www-form-urlencoded" not in content_type:
|
||||||
|
return JSONResponse(
|
||||||
|
{"error": "invalid_request", "error_description": "Content-Type must be application/x-www-form-urlencoded"},
|
||||||
status_code=400,
|
status_code=400,
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user