1#ifndef SOURCEMETA_CORE_OAUTH_DPOP_H_
2#define SOURCEMETA_CORE_OAUTH_DPOP_H_
4#ifndef SOURCEMETA_CORE_OAUTH_EXPORT
5#include <sourcemeta/core/oauth_export.h>
8#include <sourcemeta/core/jose_algorithm.h>
9#include <sourcemeta/core/jose_jwk_private.h>
11#include <sourcemeta/core/json.h>
25namespace sourcemeta::core {
78 proof(
const std::string_view server,
const std::string_view method,
79 const std::string_view url,
const std::string_view access_token,
80 const std::chrono::system_clock::time_point now, std::string &sink)
86 auto observe(
const std::string_view server,
const std::string_view nonce)
93 [[nodiscard]]
auto thumbprint() const -> std::optional<std::
string>;
100#pragma warning(disable : 4251)
102 mutable std::mutex mutex_;
103 std::map<std::string, std::string, std::less<>> nonces_;
124[[nodiscard]] SOURCEMETA_CORE_OAUTH_EXPORT
auto
140[[nodiscard]] SOURCEMETA_CORE_OAUTH_EXPORT
auto
142 -> std::optional<std::string>;
232 const std::string_view proof,
const std::string_view method,
233 const std::string_view url,
const std::chrono::system_clock::time_point now,
292 const std::string_view target,
293 const std::chrono::system_clock::time_point now,
294 const std::chrono::seconds window,
295 const bool normalize_target =
true) -> bool;
300 [[nodiscard]]
auto size(
const std::chrono::system_clock::time_point now)
const
305 std::array<std::uint8_t, 32> digest;
306 std::chrono::system_clock::time_point expiry;
309 std::size_t capacity_;
312#pragma warning(disable : 4251)
314 mutable std::mutex mutex_;
315 std::vector<Entry> entries_;
333[[nodiscard]] SOURCEMETA_CORE_OAUTH_EXPORT
auto
JWSAlgorithm
Definition jose_algorithm.h:21
@ Signature
The named key was found but its signature did not verify.
Definition jose_verify.h:214
std::optional< std::string_view > access_token
Definition oauth_dpop.h:206
std::span< const JWSAlgorithm > allowed_algorithms
Definition oauth_dpop.h:194
std::optional< std::string_view > expected_nonce
Definition oauth_dpop.h:202
auto check_and_insert(const std::string_view identifier, const std::string_view target, const std::chrono::system_clock::time_point now, const std::chrono::seconds window, const bool normalize_target=true) -> bool
auto proof(const std::string_view server, const std::string_view method, const std::string_view url, const std::string_view access_token, const std::chrono::system_clock::time_point now, std::string &sink) -> bool
OAuthDPoPProofer(JWKPrivate key, const JWSAlgorithm algorithm)
OAuthDPoPProofer(const OAuthDPoPProofer &)=delete
std::chrono::seconds past_window
How far in the past a creation time may be (RFC 9449 Section 11.1).
Definition oauth_dpop.h:196
std::chrono::seconds future_window
Definition oauth_dpop.h:199
std::optional< std::string_view > bound_thumbprint
Definition oauth_dpop.h:209
OAuthDPoPReplayStore(const OAuthDPoPReplayStore &)=delete
A store owns a mutex, so it is neither copied nor moved.
std::size_t proof_count
Definition oauth_dpop.h:191
auto observe(const std::string_view server, const std::string_view nonce) -> void
auto thumbprint() const -> std::optional< std::string >
static constexpr std::size_t DEFAULT_CAPACITY
The default maximum number of live entries a store retains.
Definition oauth_dpop.h:265
OAuthDPoPReplayStore(const std::size_t capacity=DEFAULT_CAPACITY) noexcept
Definition oauth_dpop.h:269
auto size(const std::chrono::system_clock::time_point now) const -> std::size_t
OAuthDPoPError
Definition oauth_dpop.h:148
SOURCEMETA_CORE_OAUTH_EXPORT auto oauth_is_valid_dpop_nonce(const std::string_view value) noexcept -> bool
SOURCEMETA_CORE_OAUTH_EXPORT auto oauth_dpop_verify(const std::string_view proof, const std::string_view method, const std::string_view url, const std::chrono::system_clock::time_point now, const OAuthDPoPVerifyOptions &options) -> std::optional< OAuthDPoPError >
SOURCEMETA_CORE_OAUTH_EXPORT auto oauth_dpop_confirmation(const std::string_view thumbprint) -> JSON
constexpr std::string_view OAUTH_TOKEN_TYPE_DPOP
Definition oauth_dpop.h:30
SOURCEMETA_CORE_OAUTH_EXPORT auto oauth_dpop_proof_thumbprint(const std::string_view proof) -> std::optional< std::string >
@ MissingClaim
A required header parameter or claim was absent (check 3).
Definition oauth_dpop.h:154
@ MethodMismatch
The method claim did not match the request method (check 8).
Definition oauth_dpop.h:165
@ KeyMismatch
Definition oauth_dpop.h:180
@ MissingNonce
Definition oauth_dpop.h:170
@ AccessTokenMismatch
Definition oauth_dpop.h:177
@ NonceMismatch
The nonce claim did not match the nonce the server issued (check 10).
Definition oauth_dpop.h:172
@ ProofCount
More or fewer than one DPoP header field was present (check 1).
Definition oauth_dpop.h:150
@ UnexpectedType
The token type header parameter was not dpop+jwt (check 4).
Definition oauth_dpop.h:156
@ TargetMismatch
The target claim did not match the request target (check 9).
Definition oauth_dpop.h:167
@ Malformed
The assertion was not a well-formed JSON Web Token.
Definition oauth_assertion.h:131
@ Expired
The assertion has expired (RFC 7523 Section 3 check 4).
Definition oauth_assertion.h:147
@ UnsupportedAlgorithm
The algorithm was absent or outside the accepted set (RFC 7523 Section 5).
Definition oauth_assertion.h:133