From 801c1427001fd11b0f8f705506aad97583bc229f Mon Sep 17 00:00:00 2001 From: Mike P Date: Sun, 17 Aug 2025 10:49:56 +0100 Subject: [PATCH] appview/oauth: verify "iss" parameter in auth response From https://datatracker.ietf.org/doc/html/rfc9207#section-2.4 : "Clients MUST [...] compare the result to the issuer identifier of the authorization server where the authorization request was sent to. [...] If the value does not match the expected issuer identifier, clients MUST reject the authorization response and MUST NOT proceed with the authorization grant." Signed-off-by: Mike P --- appview/oauth/handler/handler.go | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/appview/oauth/handler/handler.go b/appview/oauth/handler/handler.go index 18393f27..1fd18bd3 100644 --- a/appview/oauth/handler/handler.go +++ b/appview/oauth/handler/handler.go @@ -253,6 +253,12 @@ func (o *OAuthHandler) callback(w http.ResponseWriter, r *http.Request) { return } + if iss != oauthRequest.AuthserverIss { + log.Println("mismatched iss:", iss, "!=", oauthRequest.AuthserverIss, "for state:", state) + o.pages.Notice(w, "login-msg", "Failed to authenticate. Try again later.") + return + } + self := o.oauth.ClientMetadata() oauthClient, err := client.NewClient( -- 2.51.2