The seeded desktop/iOS OAuth clients carried a shared hardcoded secret that ships in every client binary and authenticates nothing. They are now public clients: secret seeded empty, token exchange requires PKCE (RFC 8252), client_secret is optional, and OIDC discovery advertises "none" as a supported token endpoint auth method. A migration patch clears the secrets on existing installs. Confidential clients are unchanged — a stored secret is still enforced. Also excludes generated ent/ code from desloppify scanning. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>pull/3582/head
parent
582621afa0
commit
47af73a7fd
@ -0,0 +1,24 @@
|
|||||||
|
package oauth
|
||||||
|
|
||||||
|
import (
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"github.com/cloudreve/Cloudreve/v4/ent"
|
||||||
|
"github.com/stretchr/testify/require"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestValidateClientAuth(t *testing.T) {
|
||||||
|
confidential := &ent.OAuthClient{Secret: "s3cret"}
|
||||||
|
public := &ent.OAuthClient{Secret: ""}
|
||||||
|
|
||||||
|
// Confidential clients: secret required and must match.
|
||||||
|
require.Error(t, validateClientAuth(confidential, "", "challenge"))
|
||||||
|
require.Error(t, validateClientAuth(confidential, "wrong", "challenge"))
|
||||||
|
require.NoError(t, validateClientAuth(confidential, "s3cret", ""))
|
||||||
|
|
||||||
|
// Public clients: secret ignored, PKCE challenge mandatory.
|
||||||
|
require.Error(t, validateClientAuth(public, "", ""))
|
||||||
|
require.Error(t, validateClientAuth(public, "anything", ""))
|
||||||
|
require.NoError(t, validateClientAuth(public, "", "challenge"))
|
||||||
|
require.NoError(t, validateClientAuth(public, "stale-known-secret", "challenge"))
|
||||||
|
}
|
||||||
Loading…
Reference in new issue