Skip to content

feat(auth): OAuth2 PKCE flow for public clients — Issue #806 - #996

Merged
github-actions[bot] merged 1 commit into
Smartdevs17:mainfrom
Prozaks:feat/issue-806-oauth2-pkce
Sep 28, 2026
Merged

github-actions[bot] merged 1 commit into
Smartdevs17:mainfrom
Prozaks:feat/issue-806-oauth2-pkce

Conversation

@Prozaks

@Prozaks Prozaks commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Summary

Extends the existing OAuth2 service with PKCE (RFC 7636) support for public clients that cannot safely store a client secret.

Changes

src/services/oauth-service.ts

New exports added (backwards-compatible):

  • generateCodeVerifier() — 43-char cryptographically secure URL-safe verifier (randomBytes(32).base64url)
  • generateCodeChallenge(verifier, method) — S256 (SHA-256 base64url) or plain
  • validateCodeChallenge(verifier, challenge, method) — validates verifier against stored challenge
  • createPKCEAuthorizationUrl(provider, callbackUrl, redirectTo?) — convenience helper returning { url, codeVerifier }
  • createOAuthAuthorizationUrl extended with optional 4th pkce parameter
  • exchangeOAuthCode extended with optional codeVerifier validation

src/routes/oauth.ts

  • New GET /:provider/pkce route — returns { url, codeVerifier } for PKCE flow initiation
  • Updated callback handler to pass PKCE challenge through to token exchange

PKCE flow

1. Client  →  GET /auth/oauth/google/pkce
             ← { url: '...?code_challenge=...&code_challenge_method=S256', codeVerifier: '...' }
2. Client  →  redirects user to the url
3. Provider → redirects to callback with ?code=...&state=...
4. Client  →  GET /auth/oauth/google/callback?code=...&state=...&code_verifier=...
             ← redirects to frontend with session token

Test results

Test Files  1 passed
     Tests  22 passed
  Duration  ~1.7s

Closes #806

@vercel

vercel Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Prozaks is attempting to deploy a commit to the smartdevs17's projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Sep 28, 2026

Copy link
Copy Markdown

@Prozaks Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

@github-actions
github-actions Bot merged commit 2b4c60f into Smartdevs17:main Sep 28, 2026
14 of 25 checks passed
- Add PKCE (RFC 7636) support to oauth-service.ts:
  generateCodeVerifier() — 43-char URL-safe random verifier
  generateCodeChallenge(verifier, method) — S256/plain methods
  validateCodeChallenge(verifier, challenge, method)
  createPKCEAuthorizationUrl(provider, callbackUrl) — convenience fn
- Extend createOAuthAuthorizationUrl with optional pkce param
- Extend exchangeOAuthCode with optional codeVerifier validation
- Add GET /:provider/pkce route returning { url, codeVerifier }
- Update callback route to pass PKCE params through
- 22 tests covering all PKCE paths (S256, plain, validation errors)

Closes Smartdevs17#806
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Build OAuth2 PKCE flow for public clients

1 participant