Coverage Report

Created: 2026-09-27 07:07

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/mod_auth_openidc/src/oauth.c
Line
Count
Source
1
/*
2
 * Licensed to the Apache Software Foundation (ASF) under one
3
 * or more contributor license agreements.  See the NOTICE file
4
 * distributed with this work for additional information
5
 * regarding copyright ownership.  The ASF licenses this file
6
 * to you under the Apache License, Version 2.0 (the
7
 * "License"); you may not use this file except in compliance
8
 * with the License.  You may obtain a copy of the License at
9
 *
10
 *   http://www.apache.org/licenses/LICENSE-2.0
11
 *
12
 * Unless required by applicable law or agreed to in writing,
13
 * software distributed under the License is distributed on an
14
 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15
 * KIND, either express or implied.  See the License for the
16
 * specific language governing permissions and limitations
17
 * under the License.
18
 */
19
20
/***************************************************************************
21
 * Copyright (C) 2017-2026 ZmartZone Holding BV
22
 * Copyright (C) 2013-2017 Ping Identity Corporation
23
 * All rights reserved.
24
 *
25
 * DISCLAIMER OF WARRANTIES:
26
 *
27
 * THE SOFTWARE PROVIDED HEREUNDER IS PROVIDED ON AN "AS IS" BASIS, WITHOUT
28
 * ANY WARRANTIES OR REPRESENTATIONS EXPRESS, IMPLIED OR STATUTORY; INCLUDING,
29
 * WITHOUT LIMITATION, WARRANTIES OF QUALITY, PERFORMANCE, NONINFRINGEMENT,
30
 * MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.  NOR ARE THERE ANY
31
 * WARRANTIES CREATED BY A COURSE OR DEALING, COURSE OF PERFORMANCE OR TRADE
32
 * USAGE.  FURTHERMORE, THERE ARE NO WARRANTIES THAT THE SOFTWARE WILL MEET
33
 * YOUR NEEDS OR BE FREE FROM ERRORS, OR THAT THE OPERATION OF THE SOFTWARE
34
 * WILL BE UNINTERRUPTED.  IN NO EVENT SHALL THE COPYRIGHT HOLDERS OR
35
 * CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
36
 * EXEMPLARY, OR CONSEQUENTIAL DAMAGES HOWEVER CAUSED AND ON ANY THEORY OF
37
 * LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
38
 * NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
39
 * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
40
 *
41
 * @Author: Hans Zandbelt - hans.zandbelt@openidc.com
42
 */
43
44
#include "cfg/oauth.h"
45
#include "cfg/dir.h"
46
#include "cfg/parse.h"
47
#include "handle/handle.h"
48
#include "metadata.h"
49
#include "metrics.h"
50
#include "mod_auth_openidc.h"
51
#include "proto/proto.h"
52
#include "util/request_state.h"
53
#include "util/util.h"
54
#include "util/util_cfg.h"
55
56
#include <apr_lib.h>
57
58
/*
59
 * retrieve the OAuth 2.0 metadata discovery document from the specified URL
60
 */
61
apr_byte_t oidc_oauth_metadata_provider_retrieve(request_rec *r, oidc_cfg_t *cfg, const char *issuer, const char *url,
62
0
             oidc_json_t **j_metadata, char **response) {
63
64
  /* get provider metadata from the specified URL with the specified parameters */
65
0
  if (oidc_http_get(r, url, NULL, NULL, NULL, NULL, oidc_cfg_oauth_ssl_validate_server_get(cfg), response, NULL,
66
0
        NULL, oidc_cfg_http_timeout_short_get(cfg), oidc_cfg_outgoing_proxy_get(cfg),
67
0
        oidc_cfg_dir_pass_cookies_get(r), NULL, NULL, NULL) == FALSE)
68
0
    return FALSE;
69
70
  /* decode and see if it is not an error response somehow */
71
0
  if (oidc_json_decode_and_check_error(r, *response, j_metadata) == FALSE) {
72
0
    oidc_error(r, "JSON parsing of retrieved Discovery document failed");
73
0
    return FALSE;
74
0
  }
75
76
  /* check to see if it is valid metadata */
77
78
  /* all OK */
79
0
  return TRUE;
80
0
}
81
82
/*
83
 * Return the shared configuration or a request-scoped copy containing metadata endpoints.
84
 * Request-pool strings must never be stored in the shared server configuration.
85
 */
86
0
static oidc_cfg_t *oidc_oauth_provider_config(request_rec *r, oidc_cfg_t *c) {
87
88
0
  oidc_json_t *j_provider = NULL;
89
0
  char *s_json = NULL;
90
0
  oidc_cfg_t *rc = NULL;
91
92
  /* see if we should configure a static provider based on external (cached) metadata */
93
0
  if (oidc_cfg_oauth_metadata_url_get(c) == NULL)
94
0
    return c;
95
96
0
  oidc_cache_get_oauth_provider(r, oidc_cfg_oauth_metadata_url_get(c), &s_json);
97
98
0
  if (s_json == NULL) {
99
100
0
    if (oidc_oauth_metadata_provider_retrieve(r, c, NULL, oidc_cfg_oauth_metadata_url_get(c), &j_provider,
101
0
                &s_json) == FALSE) {
102
0
      oidc_error(r, "could not retrieve metadata from url: %s", oidc_cfg_oauth_metadata_url_get(c));
103
0
      return c;
104
0
    }
105
106
0
    oidc_cache_set_oauth_provider(
107
0
        r, oidc_cfg_oauth_metadata_url_get(c), s_json,
108
0
        apr_time_now() + apr_time_from_sec(oidc_cfg_provider_metadata_refresh_interval_get(c) <= 0
109
0
                 ? OIDC_CACHE_PROVIDER_METADATA_EXPIRY_DEFAULT
110
0
                 : oidc_cfg_provider_metadata_refresh_interval_get(c)));
111
112
0
  } else {
113
114
0
    oidc_json_decode_object(r, s_json, &j_provider);
115
116
    /* check to see if it is valid metadata */
117
0
  }
118
119
  /* parse into a private per-request view; on failure fall back to the (unmutated) shared config */
120
0
  rc = oidc_cfg_request_view(r->pool, c);
121
0
  if (oidc_oauth_metadata_provider_parse(r, rc, j_provider) == FALSE) {
122
0
    oidc_error(r, "could not parse metadata from url: %s", oidc_cfg_oauth_metadata_url_get(c));
123
0
    rc = c;
124
0
  }
125
126
0
  if (j_provider)
127
0
    oidc_json_decref(j_provider);
128
129
0
  return rc;
130
0
}
131
132
/*
133
 * validate an access token against the validation endpoint of the Authorization server and gets a response back
134
 */
135
0
static apr_byte_t oidc_oauth_validate_access_token(request_rec *r, oidc_cfg_t *c, const char *token, char **response) {
136
137
0
  oidc_debug(r, "enter");
138
139
0
  char *basic_auth = NULL;
140
0
  char *bearer_auth = NULL;
141
142
  /* assemble parameters to call the token endpoint for validation */
143
0
  apr_table_t *params = apr_table_make(r->pool, 4);
144
145
  /* add any configured extra static parameters to the introspection endpoint */
146
0
  oidc_util_table_add_query_encoded_params(r->pool, params, oidc_cfg_oauth_introspection_endpoint_params_get(c));
147
148
  /* add the access_token itself */
149
0
  apr_table_addn(params, oidc_cfg_oauth_introspection_token_param_name_get(c), token);
150
151
0
  const char *bearer_access_token_auth =
152
0
      ((oidc_cfg_oauth_introspection_client_auth_bearer_token_get(c) != NULL) &&
153
0
       _oidc_strcmp(oidc_cfg_oauth_introspection_client_auth_bearer_token_get(c), "") == 0)
154
0
    ? token
155
0
    : oidc_cfg_oauth_introspection_client_auth_bearer_token_get(c);
156
157
  /* add the token endpoint authentication credentials */
158
0
  if (oidc_proto_token_endpoint_auth(r, c, oidc_cfg_oauth_introspection_endpoint_auth_get(c),
159
0
             oidc_cfg_oauth_introspection_endpoint_auth_alg_get(c),
160
0
             oidc_cfg_oauth_client_id_get(c), oidc_cfg_oauth_client_secret_get(c), NULL,
161
0
             oidc_cfg_oauth_introspection_endpoint_url_get(c), params,
162
0
             bearer_access_token_auth, &basic_auth, &bearer_auth) == FALSE)
163
0
    return FALSE;
164
165
  /* call the endpoint with the constructed parameter set and return the resulting response */
166
0
  return oidc_cfg_oauth_introspection_endpoint_method_get(c) == OIDC_INTROSPECTION_METHOD_GET
167
0
       ? oidc_http_get(r, oidc_cfg_oauth_introspection_endpoint_url_get(c), params, basic_auth, bearer_auth,
168
0
           NULL, oidc_cfg_oauth_ssl_validate_server_get(c), response, NULL, NULL,
169
0
           oidc_cfg_http_timeout_long_get(c), oidc_cfg_outgoing_proxy_get(c),
170
0
           oidc_cfg_dir_pass_cookies_get(r),
171
0
           oidc_cfg_oauth_introspection_endpoint_tls_client_cert_get(c),
172
0
           oidc_cfg_oauth_introspection_endpoint_tls_client_key_get(c),
173
0
           oidc_cfg_oauth_introspection_endpoint_tls_client_key_pwd_get(c))
174
0
       : oidc_http_post_form(r, oidc_cfg_oauth_introspection_endpoint_url_get(c), params, basic_auth,
175
0
           bearer_auth, NULL, oidc_cfg_oauth_ssl_validate_server_get(c), response, NULL,
176
0
           NULL, oidc_cfg_http_timeout_long_get(c), oidc_cfg_outgoing_proxy_get(c),
177
0
           oidc_cfg_dir_pass_cookies_get(r),
178
0
           oidc_cfg_oauth_introspection_endpoint_tls_client_cert_get(c),
179
0
           oidc_cfg_oauth_introspection_endpoint_tls_client_key_get(c),
180
0
           oidc_cfg_oauth_introspection_endpoint_tls_client_key_pwd_get(c));
181
0
}
182
183
/*
184
 * extract the password portion of a base64-encoded Basic auth value (treated as token)
185
 */
186
0
static const char *oidc_oauth_token_from_basic(request_rec *r, const char *auth_line) {
187
0
  char *decoded_line = NULL;
188
0
  int decoded_len = 0;
189
190
0
  if (oidc_util_base64_decode(r->pool, auth_line, &decoded_line, &decoded_len) != NULL)
191
0
    return NULL;
192
0
  decoded_line[decoded_len] = '\0';
193
0
  if (strchr(decoded_line, ':') == NULL)
194
0
    return NULL;
195
196
  /* Strip the username and colon and take just the password */
197
0
  ap_getword_nulls(r->pool, (const char **)&decoded_line, ':');
198
0
  return decoded_line;
199
0
}
200
201
/*
202
 * extract the bearer token from the Authorization header (Bearer or Basic scheme)
203
 */
204
0
static const char *oidc_oauth_token_from_auth_header(request_rec *r, oidc_oauth_accept_token_in_t accept_token_in) {
205
0
  const char *auth_line = oidc_http_hdr_in_authorization_get(r);
206
0
  const char *token = NULL;
207
0
  char *scheme = NULL;
208
209
0
  if (auth_line == NULL)
210
0
    return NULL;
211
212
0
  oidc_debug(r, "authorization header found");
213
0
  scheme = ap_getword(r->pool, &auth_line, OIDC_CHAR_SPACE);
214
215
0
  if ((_oidc_strnatcasecmp(scheme, OIDC_PROTO_BEARER) == 0) &&
216
0
      (accept_token_in & OIDC_OAUTH_ACCEPT_TOKEN_IN_HEADER)) {
217
0
    while (apr_isspace(*auth_line))
218
0
      auth_line++;
219
0
    return apr_pstrdup(r->pool, auth_line);
220
0
  }
221
222
0
  if ((_oidc_strnatcasecmp(scheme, OIDC_PROTO_BASIC) == 0) &&
223
0
      (accept_token_in & OIDC_OAUTH_ACCEPT_TOKEN_IN_BASIC)) {
224
0
    token = oidc_oauth_token_from_basic(r, auth_line);
225
0
    if (token != NULL)
226
0
      return token;
227
0
  }
228
229
0
  oidc_warn(r, "client used unsupported authentication scheme: %s", scheme);
230
0
  return NULL;
231
0
}
232
233
/* RFC 6750 permits the access token in exactly one location, so reject a repeated one */
234
static const char *const OIDC_OAUTH_NO_REPEAT[] = {OIDC_PROTO_ACCESS_TOKEN, NULL};
235
236
/*
237
 * extract the bearer token from a POST body parameter
238
 */
239
0
static const char *oidc_oauth_token_from_post(request_rec *r) {
240
0
  apr_table_t *params = apr_table_make(r->pool, 8);
241
0
  if (oidc_util_read_post_params_reject_dup(r, params, TRUE, OIDC_PROTO_ACCESS_TOKEN, OIDC_OAUTH_NO_REPEAT) ==
242
0
      FALSE)
243
0
    return NULL;
244
0
  return apr_table_get(params, OIDC_PROTO_ACCESS_TOKEN);
245
0
}
246
247
/*
248
 * extract the bearer token from a query string parameter
249
 */
250
0
static const char *oidc_oauth_token_from_query(request_rec *r) {
251
0
  apr_table_t *params = apr_table_make(r->pool, 8);
252
0
  if (oidc_util_read_form_encoded_params_reject_dup(r, params, r->args, OIDC_OAUTH_NO_REPEAT) == FALSE)
253
0
    return NULL;
254
0
  return apr_table_get(params, OIDC_PROTO_ACCESS_TOKEN);
255
0
}
256
257
/*
258
 * extract the bearer token from a cookie
259
 */
260
0
static const char *oidc_oauth_token_from_cookie(request_rec *r, const char *cookie_name) {
261
0
  const char *auth_line = oidc_http_get_cookie(r, cookie_name);
262
0
  if (auth_line == NULL) {
263
0
    oidc_warn(r, "no cookie found with name: %s", cookie_name);
264
0
    return NULL;
265
0
  }
266
0
  return apr_pstrdup(r->pool, auth_line);
267
0
}
268
269
/*
270
 * get the authorization header that should contain a bearer token
271
 */
272
0
apr_byte_t oidc_oauth_get_bearer_token(request_rec *r, const char **access_token) {
273
274
  /* get the directory specific setting on how the token can be passed in */
275
0
  oidc_oauth_accept_token_in_t accept_token_in = oidc_cfg_dir_oauth_accept_token_in_get(r);
276
0
  const char *cookie_name =
277
0
      oidc_cfg_dir_accept_token_in_option_get(r, OIDC_OAUTH_ACCEPT_TOKEN_IN_OPTION_COOKIE_NAME);
278
279
0
  oidc_debug(r, "accept_token_in=%d", accept_token_in);
280
281
0
  *access_token = NULL;
282
283
0
  if (accept_token_in & (OIDC_OAUTH_ACCEPT_TOKEN_IN_HEADER | OIDC_OAUTH_ACCEPT_TOKEN_IN_BASIC))
284
0
    *access_token = oidc_oauth_token_from_auth_header(r, accept_token_in);
285
286
0
  if ((*access_token == NULL) && (r->method_number == M_POST) &&
287
0
      (accept_token_in & OIDC_OAUTH_ACCEPT_TOKEN_IN_POST))
288
0
    *access_token = oidc_oauth_token_from_post(r);
289
290
0
  if ((*access_token == NULL) && (accept_token_in & OIDC_OAUTH_ACCEPT_TOKEN_IN_QUERY))
291
0
    *access_token = oidc_oauth_token_from_query(r);
292
293
0
  if ((*access_token == NULL) && (accept_token_in & OIDC_OAUTH_ACCEPT_TOKEN_IN_COOKIE))
294
0
    *access_token = oidc_oauth_token_from_cookie(r, cookie_name);
295
296
0
  if (*access_token == NULL) {
297
0
    oidc_debug(r, "no bearer token found in the allowed methods: %s",
298
0
         oidc_cfg_dir_accept_oauth_token_in2str(r->pool, accept_token_in));
299
0
    return FALSE;
300
0
  }
301
302
  /* log some stuff */
303
0
  oidc_debug(r, "bearer token: %s", oidc_util_mask_value(r, *access_token));
304
0
  return TRUE;
305
0
}
306
307
/* number of seconds a validated token is cached for when its expiry claim cannot bound the entry */
308
#define OIDC_OAUTH_CACHE_DEFAULT_EXPIRY_SECONDS 60
309
310
/*
311
 * Bound the cache entry by the configured expiry claim. Missing or nonnumeric mandatory claims
312
 * fail; optional unusable claims and nonpositive numeric claims leave the default unchanged.
313
 */
314
static apr_byte_t oidc_oauth_parse_and_cache_token_expiry(request_rec *r, oidc_cfg_t *c,
315
                const oidc_json_t *introspection_response,
316
                const char *expiry_claim_name, int expiry_format_absolute,
317
0
                int expiry_claim_is_mandatory, apr_time_t *cache_until) {
318
319
0
  oidc_debug(r, "expiry_claim_name=%s, expiry_format_absolute=%d, expiry_claim_is_mandatory=%d",
320
0
       expiry_claim_name, expiry_format_absolute, expiry_claim_is_mandatory);
321
322
0
  const oidc_json_t *expiry = oidc_json_object_get(introspection_response, expiry_claim_name);
323
324
0
  if (expiry == NULL) {
325
0
    if (expiry_claim_is_mandatory) {
326
0
      oidc_error(r, "the token claims did not contain the mandatory \"%s\" expiry claim",
327
0
           expiry_claim_name);
328
0
      return FALSE;
329
0
    }
330
0
    return TRUE;
331
0
  }
332
333
  /*
334
   * a NumericDate is a JSON number and may hold a non-integer value (RFC 7519 section 2), so accept any
335
   * number here: this matches what oidc_proto_jwt_validate accepted when it verified the same claim
336
   */
337
0
  if (!oidc_json_is_number(expiry)) {
338
0
    if (expiry_claim_is_mandatory) {
339
0
      oidc_error(r,
340
0
           "the token claims contain a \"%s\" expiry claim but it is not a JSON number (RFC "
341
0
           "7519 section 2)",
342
0
           expiry_claim_name);
343
0
      return FALSE;
344
0
    }
345
0
    oidc_warn(r,
346
0
        "the token claims contain an (optional) \"%s\" expiry claim that is not a JSON number (RFC "
347
0
        "7519 section 2); caching the result for the default %d seconds instead",
348
0
        expiry_claim_name, OIDC_OAUTH_CACHE_DEFAULT_EXPIRY_SECONDS);
349
0
    return TRUE;
350
0
  }
351
352
  /* Truncate to expire no later than the claim; clamp the double before converting it. */
353
0
  double value = oidc_json_number_value(expiry);
354
0
  if (!(value > 0)) {
355
0
    oidc_warn(r,
356
0
        "the \"%s\" expiry claim has a value <= 0 (%.0f); caching the result for the default %d "
357
0
        "seconds instead",
358
0
        expiry_claim_name, value, OIDC_OAUTH_CACHE_DEFAULT_EXPIRY_SECONDS);
359
0
    return TRUE;
360
0
  }
361
362
0
  *cache_until = oidc_util_apr_time_from_sec(value);
363
0
  if (expiry_format_absolute == FALSE)
364
0
    *cache_until = oidc_util_apr_time_add(*cache_until, apr_time_now());
365
366
0
  return TRUE;
367
0
}
368
369
0
#define OIDC_OAUTH_CACHE_KEY_RESPONSE "r"
370
0
#define OIDC_OAUTH_CACHE_KEY_TIMESTAMP "t"
371
372
/*
373
 * cache the OAuth 2.0 introspection results for the specified access token
374
 */
375
static apr_byte_t oidc_oauth_cache_access_token(request_rec *r, oidc_cfg_t *c, apr_time_t cache_until,
376
0
            const char *access_token, oidc_json_t *json) {
377
378
  /* no cache mode */
379
0
  int token_introspection_interval = oidc_cfg_dir_token_introspection_interval_get(r);
380
0
  if (token_introspection_interval == -1) {
381
0
    oidc_debug(r, "not caching introspection result");
382
0
    return TRUE;
383
0
  }
384
385
0
  oidc_debug(r, "caching introspection result");
386
387
0
  oidc_json_t *cache_entry = oidc_json_object();
388
0
  oidc_json_object_set(cache_entry, OIDC_OAUTH_CACHE_KEY_RESPONSE, json);
389
0
  oidc_json_object_set_new(cache_entry, OIDC_OAUTH_CACHE_KEY_TIMESTAMP,
390
0
         oidc_json_integer(apr_time_sec(apr_time_now())));
391
0
  const char *cache_value = oidc_json_encode(r->pool, cache_entry, OIDC_JSON_PRESERVE_ORDER | OIDC_JSON_COMPACT);
392
393
  /* set it in the cache so subsequent request don't need to validate the access_token and get the claims anymore
394
   */
395
0
  oidc_cache_set_access_token(r, access_token, cache_value, cache_until);
396
397
0
  oidc_json_decref(cache_entry);
398
399
0
  return TRUE;
400
0
}
401
402
/*
403
 * retrieve the OAuth 2.0 introspection results from the cache, for a previously introspected access token
404
 */
405
static apr_byte_t oidc_oauth_get_cached_access_token(request_rec *r, oidc_cfg_t *c, const char *access_token,
406
0
                 oidc_json_t **json) {
407
0
  oidc_json_t *cache_entry = NULL;
408
0
  char *s_cache_entry = NULL;
409
410
  /* no cache mode */
411
0
  int token_introspection_interval = oidc_cfg_dir_token_introspection_interval_get(r);
412
0
  if (token_introspection_interval == -1) {
413
0
    return FALSE;
414
0
  }
415
416
  /* see if we've got the claims for this access_token cached already */
417
0
  oidc_cache_get_access_token(r, access_token, &s_cache_entry);
418
419
0
  if (s_cache_entry == NULL)
420
0
    return FALSE;
421
422
  /* json decode the cache entry */
423
0
  if (oidc_json_decode_object(r, s_cache_entry, &cache_entry) == FALSE) {
424
0
    *json = NULL;
425
0
    return FALSE;
426
0
  }
427
428
  /* compare the timestamp against the freshness requirement */
429
0
  const oidc_json_t *v = oidc_json_object_get(cache_entry, OIDC_OAUTH_CACHE_KEY_TIMESTAMP);
430
0
  apr_time_t now = apr_time_sec(apr_time_now());
431
0
  if ((token_introspection_interval > 0) && (now > oidc_json_integer_value(v) + token_introspection_interval)) {
432
433
    /* printout info about the event */
434
0
    char buf[APR_RFC822_DATE_LEN + 1];
435
0
    apr_rfc822_date(buf, apr_time_from_sec(oidc_json_integer_value(v)));
436
0
    oidc_debug(r,
437
0
         "token that was validated/cached at: [%s], does not meet token freshness requirement: %d)",
438
0
         buf, token_introspection_interval);
439
440
    /* invalidate the cache entry */
441
0
    *json = NULL;
442
0
    oidc_json_decref(cache_entry);
443
0
    return FALSE;
444
0
  }
445
446
0
  oidc_debug(r, "returning cached introspection result that meets freshness requirements: %s", s_cache_entry);
447
448
  /* we've got a cached introspection result that is still valid for this path's requirements */
449
0
  *json = oidc_json_copy(oidc_json_object_get(cache_entry, OIDC_OAUTH_CACHE_KEY_RESPONSE));
450
451
0
  oidc_json_decref(cache_entry);
452
0
  return TRUE;
453
0
}
454
455
/*
456
 * check the value of the "active" claim in an introspection response
457
 */
458
0
static apr_byte_t oidc_oauth_introspection_active_is_valid(request_rec *r, const oidc_json_t *active) {
459
0
  if (oidc_json_is_boolean(active)) {
460
0
    if (oidc_json_is_true(active))
461
0
      return TRUE;
462
0
    oidc_debug(r, "\"%s\" boolean object with value \"false\" found in response JSON object",
463
0
         OIDC_PROTO_ACTIVE);
464
0
    return FALSE;
465
0
  }
466
0
  if (oidc_json_is_string(active)) {
467
0
    if (_oidc_strnatcasecmp(oidc_json_string_value(active), "true") == 0)
468
0
      return TRUE;
469
0
    oidc_debug(r,
470
0
         "\"%s\" string object with value that is not equal to \"true\" found in response JSON "
471
0
         "object: %s",
472
0
         OIDC_PROTO_ACTIVE, oidc_json_string_value(active));
473
0
    return FALSE;
474
0
  }
475
0
  oidc_debug(r, "no \"%s\" boolean or string object found in response JSON object", OIDC_PROTO_ACTIVE);
476
0
  return FALSE;
477
0
}
478
479
/*
480
 * validate the introspection response (active claim + expiry) and cache it on success
481
 */
482
static apr_byte_t oidc_oauth_introspection_validate_and_cache(request_rec *r, oidc_cfg_t *c, const char *access_token,
483
0
                    oidc_json_t *result) {
484
0
  const oidc_json_t *active = oidc_json_object_get(result, OIDC_PROTO_ACTIVE);
485
0
  apr_time_t cache_until = apr_time_now() + apr_time_from_sec(OIDC_OAUTH_CACHE_DEFAULT_EXPIRY_SECONDS);
486
487
0
  if (active != NULL) {
488
0
    if (oidc_oauth_introspection_active_is_valid(r, active) == FALSE) {
489
0
      OIDC_METRICS_ERROR_REASON(r, "inactive");
490
0
      return FALSE;
491
0
    }
492
0
    if (oidc_oauth_parse_and_cache_token_expiry(r, c, result, OIDC_CLAIM_EXP, TRUE, FALSE, &cache_until) ==
493
0
        FALSE) {
494
0
      OIDC_METRICS_ERROR_REASON(r, "exp");
495
0
      return FALSE;
496
0
    }
497
0
  } else {
498
    /* the "active" member is REQUIRED by RFC 7662; warn when it is absent since validity is then
499
     * derived solely from the (possibly optional) configured expiry claim */
500
0
    oidc_warn(r,
501
0
        "introspection response did not contain the RFC 7662 \"%s\" member; token validity is "
502
0
        "determined solely from the \"%s\" expiry claim",
503
0
        OIDC_PROTO_ACTIVE, oidc_cfg_oauth_introspection_token_expiry_claim_name_get(c));
504
0
    if (oidc_oauth_parse_and_cache_token_expiry(
505
0
      r, c, result, oidc_cfg_oauth_introspection_token_expiry_claim_name_get(c),
506
0
      oidc_cfg_oauth_introspection_token_expiry_claim_format_get(c) ==
507
0
          OIDC_TOKEN_EXPIRY_CLAIM_FORMAT_ABSOLUTE,
508
0
      oidc_cfg_oauth_introspection_token_expiry_claim_required_get(c) ==
509
0
          OIDC_TOKEN_EXPIRY_CLAIM_REQUIRED_MANDATORY,
510
0
      &cache_until) == FALSE) {
511
0
      OIDC_METRICS_ERROR_REASON(r, "exp");
512
0
      return FALSE;
513
0
    }
514
0
  }
515
516
  /* set it in the cache so subsequent request don't need to validate the access_token and get the claims anymore
517
   */
518
0
  oidc_oauth_cache_access_token(r, c, cache_until, access_token, result);
519
0
  return TRUE;
520
0
}
521
522
/*
523
 * fetch and validate an introspection result for the given access_token from the AS
524
 */
525
0
static apr_byte_t oidc_oauth_introspect(request_rec *r, oidc_cfg_t *c, const char *access_token, oidc_json_t **result) {
526
0
  char *s_json = NULL;
527
528
  /* not cached, go out and validate the access_token against the Authorization server and get the JSON
529
   * claims back */
530
0
  if (oidc_oauth_validate_access_token(r, c, access_token, &s_json) == FALSE) {
531
0
    oidc_error(r, "could not get a validation response from the Authorization server");
532
0
    return FALSE;
533
0
  }
534
535
  /* decode and see if it is not an error response somehow */
536
0
  if (oidc_json_decode_and_check_error(r, s_json, result) == FALSE)
537
0
    return FALSE;
538
539
0
  if (oidc_oauth_introspection_validate_and_cache(r, c, access_token, *result) == FALSE) {
540
0
    oidc_json_decref(*result);
541
0
    *result = NULL;
542
0
    return FALSE;
543
0
  }
544
545
0
  return TRUE;
546
0
}
547
548
/*
549
 * shape the introspection result into the form returned to the caller: a PingFederate-style
550
 * nested access_token (enriched with client_id/scope) or the spec-compliant result as-is
551
 */
552
0
static void oidc_oauth_shape_introspection_token(oidc_json_t *result, oidc_json_t **token) {
553
0
  oidc_json_t *tkn = oidc_json_object_get(result, OIDC_PROTO_ACCESS_TOKEN);
554
0
  if ((tkn != NULL) && (oidc_json_is_object(tkn))) {
555
    /*
556
     * assume PingFederate validation: copy over those claims from the access_token
557
     * that are relevant for authorization purposes
558
     */
559
0
    oidc_json_object_set(tkn, OIDC_PROTO_CLIENT_ID, oidc_json_object_get(result, OIDC_PROTO_CLIENT_ID));
560
0
    oidc_json_object_set(tkn, OIDC_PROTO_SCOPE, oidc_json_object_get(result, OIDC_PROTO_SCOPE));
561
    /* return only the pimped access_token results */
562
0
    *token = oidc_json_copy(tkn);
563
0
    oidc_json_decref(result);
564
0
  } else {
565
    /* assume spec compliant introspection */
566
0
    *token = result;
567
0
  }
568
0
}
569
570
/*
571
 * resolve and validate an access_token against the configured Authorization Server
572
 */
573
static apr_byte_t oidc_oauth_resolve_access_token(request_rec *r, oidc_cfg_t *c, const char *access_token,
574
0
              oidc_json_t **token, char **response) {
575
0
  oidc_json_t *result = NULL;
576
577
  /* see if we've got the claims for this access_token cached already */
578
0
  oidc_oauth_get_cached_access_token(r, c, access_token, &result);
579
580
0
  if ((result == NULL) && (oidc_oauth_introspect(r, c, access_token, &result) == FALSE))
581
0
    return FALSE;
582
583
  /* return the access_token JSON object */
584
0
  oidc_oauth_shape_introspection_token(result, token);
585
586
  /* stringify the response */
587
0
  *response = oidc_json_encode(r->pool, *token, OIDC_JSON_PRESERVE_ORDER | OIDC_JSON_COMPACT);
588
589
0
  return TRUE;
590
0
}
591
592
/*
593
 * validate the "aud" claim of a locally validated JWT access token against the configured
594
 * audience value(s): this resource server must be among the intended recipients of the token,
595
 * but - unlike an id_token - other audiences may legitimately be present as well
596
 */
597
0
static apr_byte_t oidc_oauth_validate_jwt_aud(request_rec *r, const oidc_cfg_t *c, const oidc_json_t *claims) {
598
0
  const apr_array_header_t *arr = oidc_cfg_oauth_verify_aud_values_get(c);
599
0
  const oidc_json_t *aud = NULL;
600
601
  /* no audience configured: nothing to match against */
602
0
  if ((arr == NULL) || (arr->nelts == 0))
603
0
    return TRUE;
604
605
0
  aud = oidc_json_object_get(claims, OIDC_CLAIM_AUD);
606
0
  if (aud == NULL) {
607
0
    oidc_error(r,
608
0
         "JWT access token does not contain an \"%s\" claim, so it cannot be matched against the "
609
0
         "configured " OIDCOAuthVerifyAudience " value(s)",
610
0
         OIDC_CLAIM_AUD);
611
0
    return FALSE;
612
0
  }
613
614
0
  if (oidc_json_is_string(aud)) {
615
0
    for (int i = 0; i < arr->nelts; i++)
616
0
      if (_oidc_strcmp(oidc_json_string_value(aud), APR_ARRAY_IDX(arr, i, const char *)) == 0)
617
0
        return TRUE;
618
0
  } else if (oidc_json_is_array(aud)) {
619
    /* "aud" may be a single string or an array of strings (RFC 7519 section 4.1.3) */
620
0
    for (int i = 0; i < arr->nelts; i++)
621
0
      if (oidc_json_array_has_value(r, aud, APR_ARRAY_IDX(arr, i, const char *)) == TRUE)
622
0
        return TRUE;
623
0
  } else {
624
0
    oidc_error(r, "\"%s\" claim in the JWT access token is neither a string nor an array", OIDC_CLAIM_AUD);
625
0
    return FALSE;
626
0
  }
627
628
0
  oidc_error(r,
629
0
       "none of the configured " OIDCOAuthVerifyAudience " values matches the \"%s\" claim in the JWT "
630
0
       "access token",
631
0
       OIDC_CLAIM_AUD);
632
0
  return FALSE;
633
0
}
634
635
/*
636
 * validate the "iss" claim of a locally validated JWT access token against the configured issuer
637
 */
638
0
static apr_byte_t oidc_oauth_validate_jwt_iss(request_rec *r, const oidc_cfg_t *c, const oidc_json_t *claims) {
639
0
  const char *iss = oidc_cfg_oauth_verify_issuer_get(c);
640
0
  char *s_iss = NULL;
641
642
  /* no issuer configured: nothing to match against */
643
0
  if (iss == NULL)
644
0
    return TRUE;
645
646
0
  if (oidc_json_object_get_string(r->pool, claims, OIDC_CLAIM_ISS, &s_iss, NULL) == FALSE)
647
0
    return FALSE;
648
649
0
  if (s_iss == NULL) {
650
0
    oidc_error(r,
651
0
         "JWT access token does not contain an \"%s\" claim, so it cannot be matched against the "
652
0
         "configured " OIDCOAuthVerifyIssuer " value (%s)",
653
0
         OIDC_CLAIM_ISS, iss);
654
0
    return FALSE;
655
0
  }
656
657
0
  if (oidc_util_issuer_match(iss, s_iss) == FALSE) {
658
0
    oidc_error(r,
659
0
         "configured " OIDCOAuthVerifyIssuer " (%s) does not match the \"%s\" claim (%s) in the "
660
0
         "JWT access token",
661
0
         iss, OIDC_CLAIM_ISS, s_iss);
662
0
    return FALSE;
663
0
  }
664
665
0
  return TRUE;
666
0
}
667
668
/*
669
 * Validate RFC 9068 resource-server claims even on cache hits, which may be shared by vhosts
670
 * with different audience or issuer settings.
671
 */
672
0
static apr_byte_t oidc_oauth_validate_jwt_claims(request_rec *r, const oidc_cfg_t *c, const oidc_json_t *claims) {
673
0
  if (oidc_oauth_validate_jwt_iss(r, c, claims) == FALSE)
674
0
    return FALSE;
675
0
  return oidc_oauth_validate_jwt_aud(r, c, claims);
676
0
}
677
678
/*
679
 * validate a JWT access token (locally)
680
 *
681
 * NB: reuses the following settings from the OIDC (RP) configuration section, as documented
682
 *     in auth_openidc.conf:
683
 *     - the JWKs cache refresh interval (OIDCJWKSRefreshInterval)
684
 *     - decryption key material (OIDCPrivateKeyFiles)
685
 *
686
 * OIDCOAuthRemoteUserClaim client_id
687
 * # 32x 61 hex
688
 * OIDCOAuthVerifySharedKeys aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
689
 */
690
static apr_byte_t oidc_oauth_validate_jwt_access_token(request_rec *r, oidc_cfg_t *c, const char *access_token,
691
0
                   oidc_json_t **token, char **response) {
692
693
0
  oidc_debug(r, "enter: JWT access_token header=%s",
694
0
       oidc_proto_jwt_header_peek(r, access_token, NULL, NULL, NULL));
695
696
0
  oidc_jose_error_t err;
697
0
  oidc_jwk_t *jwk = NULL;
698
0
  apr_hash_t *decrypt_keys = NULL;
699
0
  oidc_json_t *cached = NULL;
700
701
  /* Reuse cached validation until token expiry or the configured introspection interval. */
702
0
  oidc_oauth_get_cached_access_token(r, c, access_token, &cached);
703
0
  if (cached != NULL) {
704
0
    if (oidc_oauth_validate_jwt_claims(r, c, cached) == FALSE) {
705
0
      oidc_json_decref(cached);
706
0
      return FALSE;
707
0
    }
708
0
    *token = cached;
709
0
    *response = oidc_json_encode(r->pool, cached, OIDC_JSON_PRESERVE_ORDER | OIDC_JSON_COMPACT);
710
0
    return TRUE;
711
0
  }
712
713
0
  if (oidc_cfg_oauth_decrypt_shared_keys_get(c) != NULL) {
714
    /* symmetric decryption keys configured with OIDCOAuthDecryptSharedKeys */
715
0
    decrypt_keys = oidc_util_key_sets_merge(r->pool, oidc_cfg_oauth_decrypt_shared_keys_get(c),
716
0
              oidc_cfg_private_keys_get(c));
717
0
  } else {
718
    /* fall back to a symmetric key derived from the client secret configured for the
719
     * OpenID Connect provider, alongside the OIDCPrivateKeyFiles key material */
720
0
    if (oidc_util_key_symmetric_create(r, oidc_cfg_provider_client_secret_get(oidc_cfg_provider_get(c)), 0,
721
0
               NULL, TRUE, &jwk) == FALSE)
722
0
      return FALSE;
723
0
    decrypt_keys = oidc_util_key_symmetric_merge(r->pool, oidc_cfg_private_keys_get(c), jwk);
724
0
  }
725
726
0
  oidc_jwt_t *jwt = NULL;
727
0
  if (oidc_jwt_parse(r->pool, access_token, &jwt, decrypt_keys, FALSE, &err) == FALSE) {
728
0
    oidc_error(r, "could not parse JWT from access_token: %s", oidc_jose_e2s(r->pool, err));
729
0
    oidc_jwk_destroy(jwk);
730
0
    return FALSE;
731
0
  }
732
733
0
  oidc_jwk_destroy(jwk);
734
0
  oidc_debug(r, "successfully parsed JWT with header: %s", jwt->header.value.str);
735
736
  /*
737
   * RFC 9068 requires exp. Validate iss and aud after signature verification, including on
738
   * cache hits; iat is not enforced for access tokens.
739
   */
740
0
  if (oidc_proto_jwt_validate(r, jwt, NULL, TRUE, FALSE, -1) == FALSE) {
741
0
    oidc_jwt_destroy(jwt);
742
0
    return FALSE;
743
0
  }
744
745
0
  oidc_debug(
746
0
      r, "verify JWT against %d statically configured public keys and %d shared keys, with JWKs URI set to %s",
747
0
      oidc_cfg_oauth_verify_public_keys_get(c) ? oidc_cfg_oauth_verify_public_keys_get(c)->nelts : 0,
748
0
      oidc_cfg_oauth_verify_shared_keys_get(c) ? apr_hash_count(oidc_cfg_oauth_verify_shared_keys_get(c)) : 0,
749
0
      oidc_cfg_oauth_verify_jwks_uri_get(c));
750
751
  /* the JWKs cache refresh interval is shared with the OIDC provider one (OIDCJWKSRefreshInterval),
752
   * as documented in auth_openidc.conf */
753
0
  oidc_jwks_uri_t jwks_uri = {oidc_cfg_oauth_verify_jwks_uri_get(c),
754
0
            oidc_cfg_provider_jwks_uri_refresh_interval_get(oidc_cfg_provider_get(c)), NULL,
755
0
            NULL};
756
0
  if (oidc_proto_jwt_verify(r, c, jwt, &jwks_uri, oidc_cfg_oauth_ssl_validate_server_get(c),
757
0
          oidc_util_key_sets_merge(r->pool, oidc_cfg_oauth_verify_shared_keys_get(c),
758
0
                 oidc_cfg_oauth_verify_public_keys_get(c)),
759
0
          NULL) == FALSE) {
760
0
    oidc_error(r, "JWT access token signature could not be validated, aborting");
761
0
    oidc_jwt_destroy(jwt);
762
0
    return FALSE;
763
0
  }
764
765
0
  oidc_debug(r, "successfully verified JWT access token: %s", jwt->payload.value.str);
766
767
  /* the signature is authentic: now check that the token was actually meant for us */
768
0
  if (oidc_oauth_validate_jwt_claims(r, c, jwt->payload.value.json) == FALSE) {
769
0
    oidc_jwt_destroy(jwt);
770
0
    return FALSE;
771
0
  }
772
773
  /* cache the validated claims bounded by the token's expiry so subsequent requests carrying the same
774
   * bearer token skip re-verification; "exp" is mandatory and was verified above, so it always bounds
775
   * the entry here and the default below is not reached */
776
0
  apr_time_t cache_until = apr_time_now() + apr_time_from_sec(OIDC_OAUTH_CACHE_DEFAULT_EXPIRY_SECONDS);
777
0
  if (oidc_oauth_parse_and_cache_token_expiry(r, c, jwt->payload.value.json, OIDC_CLAIM_EXP, TRUE, FALSE,
778
0
                &cache_until) == TRUE)
779
0
    oidc_oauth_cache_access_token(r, c, cache_until, access_token, jwt->payload.value.json);
780
781
0
  *token = oidc_json_copy(jwt->payload.value.json);
782
0
  *response = jwt->payload.value.str;
783
784
0
  oidc_jwt_destroy(jwt);
785
786
0
  return TRUE;
787
0
}
788
789
/*
790
 * set the unique user identifier that will be propagated in the Apache r->user and REMOTE_USER variables
791
 */
792
0
static apr_byte_t oidc_oauth_set_request_user(request_rec *r, const oidc_cfg_t *c, const oidc_json_t *token) {
793
0
  char *remote_user = NULL;
794
795
0
  if (oidc_get_remote_user(r, oidc_cfg_oauth_remote_user_claim_name_get(c),
796
0
         oidc_cfg_oauth_remote_user_claim_get(c)->reg_exp,
797
0
         oidc_cfg_oauth_remote_user_claim_get(c)->replace, token, &remote_user) == FALSE) {
798
0
    oidc_error(
799
0
        r,
800
0
        "" OIDCOAuthRemoteUserClaim
801
0
        " is set to \"%s\", but could not set the remote user based the available claims for the user",
802
0
        oidc_cfg_oauth_remote_user_claim_name_get(c));
803
0
    return FALSE;
804
0
  }
805
806
0
  r->user = apr_pstrdup(r->pool, remote_user);
807
0
  oidc_debug(r, "set user to \"%s\" based on claim: \"%s\"%s", r->user,
808
0
       oidc_cfg_oauth_remote_user_claim_name_get(c),
809
0
       oidc_cfg_oauth_remote_user_claim_get(c)->reg_exp
810
0
           ? apr_psprintf(r->pool, " and expression: \"%s\" and replace string: \"%s\"",
811
0
              oidc_cfg_oauth_remote_user_claim_get(c)->reg_exp,
812
0
              oidc_cfg_oauth_remote_user_claim_get(c)->replace)
813
0
           : "");
814
0
  return TRUE;
815
0
}
816
817
/*
818
 * sub-request handling: recycle the user from the initial request when available;
819
 * returns OK if handled, DECLINED to continue the main flow
820
 */
821
0
static int oidc_oauth_check_userid_subrequest(request_rec *r) {
822
0
  if (oidc_subrequest_recycle_user(r) == FALSE)
823
0
    return DECLINED;
824
825
0
  oidc_strip_cookies(r);
826
0
  return OK;
827
0
}
828
829
/*
830
 * handle "special" requests directed at the Redirect URI (JWKS, remove-access-token-cache);
831
 * returns the status to send back, or DECLINED if not a special request
832
 */
833
0
static int oidc_oauth_check_userid_redirect_uri(request_rec *r, oidc_cfg_t *c) {
834
0
  if (oidc_util_url_has_parameter(r, OIDC_REDIRECT_URI_REQUEST_JWKS)) {
835
0
    OIDC_METRICS_COUNTER_INC(r, c, OM_REDIRECT_URI_REQUEST_JWKS);
836
    /*
837
     * Will be handled in the content handler; avoid:
838
     * No authentication done but request not allowed without authentication
839
     * by setting r->user. No authentication happened, so any OIDC_* headers
840
     * on this request came from the client and must not survive it.
841
     */
842
0
    oidc_scrub_headers(r);
843
0
    r->user = "";
844
0
    return OK;
845
0
  }
846
0
  if (oidc_util_url_has_parameter(r, OIDC_REDIRECT_URI_REQUEST_REMOVE_AT_CACHE))
847
0
    return oidc_revoke_at_cache_remove(r, c);
848
0
  return DECLINED;
849
0
}
850
851
/*
852
 * validate the access token via the configured introspection endpoint or as a local JWT
853
 */
854
static apr_byte_t oidc_oauth_validate_token(request_rec *r, oidc_cfg_t *c, const char *access_token,
855
0
              oidc_json_t **claims, char **s_token) {
856
0
  if (oidc_cfg_oauth_introspection_endpoint_url_get(c) != NULL)
857
0
    return oidc_oauth_resolve_access_token(r, c, access_token, claims, s_token);
858
0
  return oidc_oauth_validate_jwt_access_token(r, c, access_token, claims, s_token);
859
0
}
860
861
/*
862
 * propagate claims and access_token into the application HTTP headers
863
 */
864
static void oidc_oauth_pass_info_to_app(request_rec *r, const oidc_cfg_t *c, oidc_json_t *claims,
865
0
          const char *access_token) {
866
0
  const char *authn_header = oidc_cfg_dir_authn_header_get(r);
867
0
  oidc_appinfo_pass_in_t pass_in = oidc_cfg_dir_pass_info_in_get(r);
868
0
  oidc_appinfo_encoding_t encoding = oidc_cfg_dir_pass_info_encoding_get(r);
869
870
0
  if ((r->user != NULL) && (authn_header != NULL))
871
0
    oidc_http_hdr_in_set(r, authn_header, r->user);
872
873
0
  oidc_util_appinfo_set_all(r, claims, oidc_cfg_claim_prefix_get(c), oidc_cfg_claim_delimiter_get(c), pass_in,
874
0
          encoding);
875
876
0
  if (access_token != NULL)
877
0
    oidc_util_appinfo_set(r, OIDC_APP_INFO_ACCESS_TOKEN, access_token, OIDC_DEFAULT_HEADER_PREFIX, pass_in,
878
0
              encoding);
879
0
}
880
881
/*
882
 * main routine: handle OAuth 2.0 authentication/authorization
883
 */
884
0
int oidc_oauth_check_userid(request_rec *r, oidc_cfg_t *c, const char *access_token) {
885
0
  oidc_json_t *claims = NULL;
886
0
  char *s_token = NULL;
887
0
  int rv = DECLINED;
888
889
  /* check if this is a sub-request or an initial request */
890
0
  if (!ap_is_initial_req(r))
891
0
    rv = oidc_oauth_check_userid_subrequest(r);
892
0
  else if (oidc_util_url_matches_redirect_uri(r, c) == TRUE)
893
0
    rv = oidc_oauth_check_userid_redirect_uri(r, c);
894
0
  if (rv != DECLINED)
895
0
    return rv;
896
897
  /* we don't have a session yet */
898
899
  /* obtain/refresh metadata from OAuth metadata document URL if configured; from here on use the
900
   * returned per-request view so metadata-derived endpoints never mutate the shared server config */
901
0
  c = oidc_oauth_provider_config(r, c);
902
903
  /* get the bearer access token from the Authorization header */
904
0
  if ((access_token == NULL) && (oidc_oauth_get_bearer_token(r, &access_token) == FALSE)) {
905
0
    if (r->method_number == M_OPTIONS) {
906
      /* a CORS preflight is let through unauthenticated, so the OIDC_* headers
907
       * it carries are the client's own and must be scrubbed like on any other
908
       * path that returns OK without authenticating */
909
0
      oidc_scrub_headers(r);
910
0
      r->user = "";
911
0
      return OK;
912
0
    }
913
0
    return oidc_proto_return_www_authenticate(r, OIDC_PROTO_ERR_INVALID_REQUEST,
914
0
                "No bearer token found in the request");
915
0
  }
916
917
0
  oidc_util_set_trace_parent(r, c, access_token);
918
919
  /* validate the obtained access token against the OAuth AS validation endpoint */
920
0
  if (oidc_oauth_validate_token(r, c, access_token, &claims, &s_token) == FALSE)
921
0
    return oidc_proto_return_www_authenticate(r, OIDC_PROTO_ERR_INVALID_TOKEN,
922
0
                oidc_cfg_oauth_introspection_endpoint_url_get(c) != NULL
923
0
                    ? "Reference token could not be introspected"
924
0
                    : "JWT token could not be validated");
925
926
  /* check that we've got something back */
927
0
  if (claims == NULL) {
928
0
    oidc_error(r, "could not resolve claims (token == NULL)");
929
0
    return oidc_proto_return_www_authenticate(r, OIDC_PROTO_ERR_INVALID_TOKEN,
930
0
                "No claims could be parsed from the token");
931
0
  }
932
933
  /* store the parsed token (cq. the claims from the response) in the request state so it can be accessed by the
934
   * authz routines */
935
0
  oidc_request_state_json_set(r, OIDC_REQUEST_STATE_KEY_CLAIMS, claims);
936
937
  /* set the request user */
938
0
  if (oidc_oauth_set_request_user(r, c, claims) == FALSE) {
939
0
    oidc_json_decref(claims);
940
0
    oidc_error(r, "remote user could not be set, aborting with HTTP_UNAUTHORIZED");
941
0
    return oidc_proto_return_www_authenticate(r, OIDC_PROTO_ERR_INVALID_TOKEN, "Could not set remote user");
942
0
  }
943
944
  /*
945
   * we're going to pass the information that we have to the application,
946
   * but first we need to scrub the headers that we're going to use for security reasons
947
   */
948
0
  oidc_scrub_headers(r);
949
950
0
  oidc_oauth_pass_info_to_app(r, c, claims, access_token);
951
952
  /* free JSON resources */
953
0
  oidc_json_decref(claims);
954
955
  /* strip any cookies that we need to */
956
0
  oidc_strip_cookies(r);
957
958
0
  return OK;
959
0
}