Repository navigation
test(verify): refuse the sign-in flow cookie presented as the session cookie - #252
Merged
Merged
Conversation
… cookie Every adapter cookie can be signed with the same secret, and the ephemeral cookie is handed out before any factor is proven, so an adapter's guard must not accept it in the access cookie's place. Express, Fastify and Go pass with fells-code/seamless-auth-server#211.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #251, which merged before this commit reached it.
Adds a conformance spec: the app's guard (
GET /api/me) must answer 401 when the sign-in flow's ephemeral cookie is presented in the access cookie's place. Every adapter cookie can be signed with the same secret, and the ephemeral cookie is handed out before any factor is proven, so a guard that checks only the signature lets it pass for a session. That was fells-code/seamless-auth-server#211.verify/CONFORMANCE.mdlists it under Guard.Verified against the Express and Fastify reference apps built with fells-code/seamless-auth-server#211, and the Go reference app in fells-code/seamless-auth-go: 25 of 25 on each.
The daily released smoke test fails this spec until the release containing #211 is published, accurately: the currently published adapters accept that cookie.