This is an automated email from the ASF dual-hosted git repository.

lahirujayathilake pushed a commit to branch auth-endpoints-web
in repository https://gitbox.apache.org/repos/asf/airavata-custos.git

commit 661d83ee76ba9ea87c1579548be8fe83fbb18feb
Author: lahiruj <[email protected]>
AuthorDate: Wed Jun 17 16:16:35 2026 -0400

    Harden OIDC sign-in with state and nonce checks and log privilege fetch 
errors
---
 web/src/shared/auth/auth.ts | 12 ++++++++++--
 1 file changed, 10 insertions(+), 2 deletions(-)

diff --git a/web/src/shared/auth/auth.ts b/web/src/shared/auth/auth.ts
index f24c44e0c..77764ca1a 100644
--- a/web/src/shared/auth/auth.ts
+++ b/web/src/shared/auth/auth.ts
@@ -10,6 +10,10 @@ const oidcProvider = {
   clientId: serverEnv.OIDC_CLIENT_ID,
   clientSecret: serverEnv.OIDC_CLIENT_SECRET,
   authorization: { params: { scope: serverEnv.OIDC_SCOPES } },
+  // PKCE protects code interception, state binds the response to this browser
+  // session, nonce binds the id_token. id_token is the bearer the backend
+  // accepts, so replay protection matters here.
+  checks: ["pkce", "state", "nonce"] as ("pkce" | "state" | "nonce")[],
 };
 
 // Privileges aren't an OIDC claim — fetch from the backend so the layout gate 
sees them.
@@ -19,10 +23,14 @@ async function fetchPrivileges(bearer: string): 
Promise<Privilege[]> {
       headers: { Authorization: `Bearer ${bearer}` },
       cache: "no-store",
     });
-    if (!res.ok) return [];
+    if (!res.ok) {
+      console.error("fetchPrivileges: backend returned", res.status, 
res.statusText);
+      return [];
+    }
     const data = (await res.json()) as { privileges?: Privilege[] };
     return data.privileges ?? [];
-  } catch {
+  } catch (err) {
+    console.error("fetchPrivileges: request failed", err);
     return [];
   }
 }

Reply via email to