Browse Source

Reuse the CookieOptions instance instead of creating one for each operation

pull/2493/head
Kévin Chalet 1 month ago
parent
commit
4acdafdf01
  1. 4
      src/OpenIddict.Client.AspNetCore/OpenIddictClientAspNetCoreHandlers.cs
  2. 20
      src/OpenIddict.Client.Owin/OpenIddictClientOwinHandlers.cs

4
src/OpenIddict.Client.AspNetCore/OpenIddictClientAspNetCoreHandlers.cs

@ -446,7 +446,7 @@ public static partial class OpenIddictClientAspNetCoreHandlers
{ {
// Extract the payload and validate the version marker. // Extract the payload and validate the version marker.
var payload = Base64Url.DecodeFromChars(input); var payload = Base64Url.DecodeFromChars(input);
if (payload.Length < (1 + sizeof(uint)) || payload[0] is not 0x01) if (payload.Length is < (1 + sizeof(uint)) || payload[0] is not 0x01)
{ {
output = null; output = null;
return false; return false;
@ -454,7 +454,7 @@ public static partial class OpenIddictClientAspNetCoreHandlers
// Extract the length of the request forgery protection. // Extract the length of the request forgery protection.
var length = (int) BinaryPrimitives.ReadUInt32BigEndian(payload.AsSpan(1, sizeof(uint))); var length = (int) BinaryPrimitives.ReadUInt32BigEndian(payload.AsSpan(1, sizeof(uint)));
if (length is 0 || length != (payload.Length - (1 + sizeof(uint)))) if (length != (payload.Length - (1 + sizeof(uint))))
{ {
output = null; output = null;
return false; return false;

20
src/OpenIddict.Client.Owin/OpenIddictClientOwinHandlers.cs

@ -402,11 +402,6 @@ public static partial class OpenIddictClientOwinHandlers
throw new InvalidOperationException(SR.GetResourceString(SR.ID0354)); throw new InvalidOperationException(SR.GetResourceString(SR.ID0354));
} }
// Resolve the cookie manager and the cookie options from the OWIN integration options.
var (manager, options) = (
_options.CurrentValue.CookieManager,
_options.CurrentValue.CookieOptions);
// Compute the name of the cookie name based on the prefix and the random nonce. // Compute the name of the cookie name based on the prefix and the random nonce.
var name = new StringBuilder(_options.CurrentValue.CookieName) var name = new StringBuilder(_options.CurrentValue.CookieName)
.Append(Separators.Dot) .Append(Separators.Dot)
@ -419,7 +414,7 @@ public static partial class OpenIddictClientOwinHandlers
// //
// In any case, the authentication demand MUST be rejected as it's impossible to ensure // In any case, the authentication demand MUST be rejected as it's impossible to ensure
// it's not an injection or session fixation attack without the correlation cookie. // it's not an injection or session fixation attack without the correlation cookie.
var value = manager.GetRequestCookie(request.Context, name); var value = _options.CurrentValue.CookieManager.GetRequestCookie(request.Context, name);
if (string.IsNullOrEmpty(value)) if (string.IsNullOrEmpty(value))
{ {
context.Reject( context.Reject(
@ -447,14 +442,7 @@ public static partial class OpenIddictClientOwinHandlers
// Return a response header asking the browser to delete the state cookie. // Return a response header asking the browser to delete the state cookie.
// //
// Note: when deleting a cookie, the same options used when creating it MUST be specified. // Note: when deleting a cookie, the same options used when creating it MUST be specified.
manager.DeleteCookie(request.Context, name, new CookieOptions _options.CurrentValue.CookieManager.DeleteCookie(request.Context, name, _options.CurrentValue.CookieOptions);
{
Domain = options.Domain,
HttpOnly = options.HttpOnly,
Path = options.Path,
SameSite = options.SameSite,
Secure = options.Secure
});
return ValueTask.CompletedTask; return ValueTask.CompletedTask;
@ -464,7 +452,7 @@ public static partial class OpenIddictClientOwinHandlers
{ {
// Extract the payload and validate the version marker. // Extract the payload and validate the version marker.
var payload = Base64Url.DecodeFromChars(input); var payload = Base64Url.DecodeFromChars(input);
if (payload.Length < (1 + sizeof(uint)) || payload[0] is not 0x01) if (payload.Length is < (1 + sizeof(uint)) || payload[0] is not 0x01)
{ {
output = null; output = null;
return false; return false;
@ -472,7 +460,7 @@ public static partial class OpenIddictClientOwinHandlers
// Extract the length of the request forgery protection. // Extract the length of the request forgery protection.
var length = (int) BinaryPrimitives.ReadUInt32BigEndian(payload.AsSpan(1, sizeof(uint))); var length = (int) BinaryPrimitives.ReadUInt32BigEndian(payload.AsSpan(1, sizeof(uint)));
if (length is 0 || length != (payload.Length - (1 + sizeof(uint)))) if (length != (payload.Length - (1 + sizeof(uint))))
{ {
output = null; output = null;
return false; return false;

Loading…
Cancel
Save