Class CookieOAuth2AuthorizationRequestRepository

java.lang.Object
com.codename1.backend.security.oauth2.client.CookieOAuth2AuthorizationRequestRepository
All Implemented Interfaces:
AuthorizationRequestRepository

public final class CookieOAuth2AuthorizationRequestRepository extends Object implements AuthorizationRequestRepository

Keeps the request in a cookie of its own, for a provider that answers with a form the browser posts (ClientRegistration.FORM_POST): Sign in with Apple.

That answer is a POST from the provider's page, and a browser does not send a SameSite=Lax cookie with one -- so the session, and a request kept in it, are not there when the answer arrives. This cookie is SameSite=None; Secure; HttpOnly, lasts five minutes, and uses a __Host- name with Path=/ and no Domain. Browsers therefore reject a sibling subdomain's attempt to plant this cookie for the parent domain. It is signed with HMAC-SHA256: a value this server did not write, or wrote more than five minutes ago, is no request at all. Its state is what ties the posted answer to this browser.

The cookie is signed, not encrypted. It holds the PKCE verifier, which the user's own browser may read; what protects the exchange from that browser's user is the client secret a form_post provider also requires.

Every process that may receive the answer needs the same key: set cn1.security.oauth2.client.cookie-secret. Without it each process makes a key of its own when it starts.