-
Notifications
You must be signed in to change notification settings - Fork 2.2k
Version Packages #2849
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Version Packages #2849
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
This file was deleted.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🟡 (optional) Consumers reading the 2.1.1 release notes are not told that DCR registration now sends
application_type: 'native'forhttp://*.localhostredirect URIs. The entry at packages/client/CHANGELOG.md:7 scopes the change to the "SEP-2207 token-endpoint https guard", but the sameisLoopbackHosthelper also drivesderiveApplicationTypeat packages/client/src/client/auth.ts:911, so 2.1.0 sent'web'and 2.1.1 sends'native'for those clients. Fix: amend the client 2.1.1 entry (the changeset is already consumed) to state that*.localhostalso counts as loopback for the SEP-837application_typedefault, and that consumers whose AS enforces OIDC DCR §2 native redirect rules should setclientMetadata.application_typeexplicitly.Why this was flagged
A client using dynamic client registration with
redirect_uris: ['http://app.localhost:3000/callback']and no explicitclientMetadata.application_typegoes throughresolveClientMetadata, which callsderiveApplicationType(packages/client/src/client/auth.ts:902-914). That function returns'native'wheneverisLoopbackHost(url.hostname)is true (auth.ts:911), andisLoopbackHostnow also matcheshostname.endsWith('.localhost')(auth.ts:870). On 2.1.0 the same redirect URI producedapplication_type: 'web'; on 2.1.1 the DCR body carries'native'. The fix commit tests this deliberately (packages/client/test/client/auth.test.ts adds['http://tenant.example.localhost:3300/callback', 'native']), so it is intended, but the changelog text this PR adds at packages/client/CHANGELOG.md:7 describes only the token-endpoint https guard. An authorization server that applies OIDC DCR §2 (native clients may only register custom-scheme or literal localhost/127.0.0.1/[::1] http redirect URIs) can now reject a registration that 2.1.0 completed, and the operator has no release-note pointer…Verification: nit — triggered whenever a consumer reads the 2.1.1 client changelog to learn what changed for DCR clients with
http://*.localhostredirect URIs. The mechanism is verified:isLoopbackHost(packages/client/src/client/auth.ts:867-876, widened in 7f7a94c to addhostname.endsWith('.localhost')) has two callers — the https guard at auth.ts:883 andderiveApplicationTypeat auth.ts:911 (`if…