fix!: do not allow insecure oauth requests by default (#27844)

* fix!: do not allow insecure oauth requests by default

* fix: format

* fix: make open-api

* fix: tests

* nit: casing

* chore: migration to allow insecure if current oauth uses http
This commit is contained in:
bo0tzz
2026-04-16 16:11:58 +02:00
committed by GitHub
parent 9c642bd6fc
commit 3356e81c85
11 changed files with 77 additions and 3 deletions
+4 -2
View File
@@ -1,6 +1,6 @@
import { Injectable, InternalServerErrorException } from '@nestjs/common';
import {
allowInsecureRequests,
allowInsecureRequests as allowInsecureRequestsExecute,
authorizationCodeGrant,
buildAuthorizationUrl,
calculatePKCECodeChallenge,
@@ -28,6 +28,7 @@ export type OAuthConfig = {
signingAlgorithm: string;
tokenEndpointAuthMethod: OAuthTokenEndpointAuthMethod;
timeout: number;
allowInsecureRequests: boolean;
};
export type OAuthProfile = UserInfoResponse;
@@ -133,6 +134,7 @@ export class OAuthRepository {
signingAlgorithm,
tokenEndpointAuthMethod,
timeout,
allowInsecureRequests,
}: OAuthConfig) {
try {
return await discovery(
@@ -146,7 +148,7 @@ export class OAuthRepository {
},
this.getTokenAuthMethod(tokenEndpointAuthMethod, clientSecret),
{
execute: [allowInsecureRequests],
execute: allowInsecureRequests ? [allowInsecureRequestsExecute] : [],
timeout,
},
);