diff --git a/oidc/provider.go b/oidc/provider.go index 0c1f2cb..94bcd61 100644 --- a/oidc/provider.go +++ b/oidc/provider.go @@ -98,7 +98,7 @@ func (p *Provider) JWKS() (map[string]interface{}, error) { } // IssueIDToken creates a signed JWT id_token -func (p *Provider) IssueIDToken(sub string, preferredUsername string, email string, audience string) (string, error) { +func (p *Provider) IssueIDToken(sub string, preferredUsername string, email string, audience string, nonce string) (string, error) { issuer := fmt.Sprintf("https://%s", p.hostname) now := time.Now() @@ -111,6 +111,7 @@ func (p *Provider) IssueIDToken(sub string, preferredUsername string, email stri Claim("preferred_username", preferredUsername). Claim("email", email). Claim("name", preferredUsername). + Claim("nonce", nonce). Build() if err != nil { return "", fmt.Errorf("error building token: %w", err) diff --git a/server/client_metadata.go b/server/client_metadata.go index b2260d1..acd7bdd 100644 --- a/server/client_metadata.go +++ b/server/client_metadata.go @@ -10,5 +10,7 @@ import ( // For non-localhost clients, the client_id URL must serve this document. func (s *Server) handleClientMetadata(e echo.Context) error { meta := s.oauthApp.Config.ClientMetadata() + name := "at-mesh" + meta.ClientName = &name return e.JSON(http.StatusOK, meta) } diff --git a/server/server.go b/server/server.go index 736ad5a..296bfdd 100644 --- a/server/server.go +++ b/server/server.go @@ -117,14 +117,13 @@ func New(args *Args) (*Server, error) { database := &db.DB{DB: gormDb} - // Init indigo OAuth client app (public client for localhost dev) + // Init indigo OAuth client app (public client) // Wrap the store in a CapturingStore so we can retrieve the OAuth state // that indigo generates inside StartAuthFlow. - callbackURL := fmt.Sprintf("http://127.0.0.1%s/oauth/callback", args.Addr) - if args.Addr == ":80" || args.Addr == "80" { - callbackURL = "http://127.0.0.1/oauth/callback" - } - oauthConfig := oauth.NewLocalhostConfig(callbackURL, []string{"atproto"}) + // Use the hostname for the callback URL so it works from any device. + callbackURL := fmt.Sprintf("https://%s/oauth/callback", args.Hostname) + clientID := fmt.Sprintf("https://%s/oauth/client-metadata.json", args.Hostname) + oauthConfig := oauth.NewPublicConfig(clientID, callbackURL, []string{"atproto"}) capturingStore := db.NewCapturingStore(oauthStore) oauthApp := oauth.NewClientApp(&oauthConfig, capturingStore) @@ -154,7 +153,7 @@ func New(args *Args) (*Server, error) { // Session store cookieStore := sessions.NewCookieStore([]byte(args.SessionSecret)) - cookieStore.Options.Secure = false + cookieStore.Options.Secure = true cookieStore.Options.SameSite = http.SameSiteLaxMode cookieStore.Options.HttpOnly = true cookieStore.Options.Path = "/" @@ -201,7 +200,7 @@ func (s *Server) setupEcho() { // AT Protocol OAuth client callback (PDS redirects here after user auth) e.GET("/oauth/callback", s.handleATProtoCallback) // Client metadata endpoint (for non-localhost OAuth clients) - e.GET("/client-metadata.json", s.handleClientMetadata) + e.GET("/oauth/client-metadata.json", s.handleClientMetadata) // Health e.GET("/health", s.handleHealth)