This is an automated email from the ASF dual-hosted git repository. lahirujayathilake pushed a commit to branch auth-endpoints-web in repository https://gitbox.apache.org/repos/asf/airavata-custos.git
commit 661d83ee76ba9ea87c1579548be8fe83fbb18feb Author: lahiruj <[email protected]> AuthorDate: Wed Jun 17 16:16:35 2026 -0400 Harden OIDC sign-in with state and nonce checks and log privilege fetch errors --- web/src/shared/auth/auth.ts | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/web/src/shared/auth/auth.ts b/web/src/shared/auth/auth.ts index f24c44e0c..77764ca1a 100644 --- a/web/src/shared/auth/auth.ts +++ b/web/src/shared/auth/auth.ts @@ -10,6 +10,10 @@ const oidcProvider = { clientId: serverEnv.OIDC_CLIENT_ID, clientSecret: serverEnv.OIDC_CLIENT_SECRET, authorization: { params: { scope: serverEnv.OIDC_SCOPES } }, + // PKCE protects code interception, state binds the response to this browser + // session, nonce binds the id_token. id_token is the bearer the backend + // accepts, so replay protection matters here. + checks: ["pkce", "state", "nonce"] as ("pkce" | "state" | "nonce")[], }; // Privileges aren't an OIDC claim — fetch from the backend so the layout gate sees them. @@ -19,10 +23,14 @@ async function fetchPrivileges(bearer: string): Promise<Privilege[]> { headers: { Authorization: `Bearer ${bearer}` }, cache: "no-store", }); - if (!res.ok) return []; + if (!res.ok) { + console.error("fetchPrivileges: backend returned", res.status, res.statusText); + return []; + } const data = (await res.json()) as { privileges?: Privilege[] }; return data.privileges ?? []; - } catch { + } catch (err) { + console.error("fetchPrivileges: request failed", err); return []; } }
