Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

No PKCE Implementation in OAuth Authorization Code Flow

Abierto
#87 1 comentario 0 reacciones 1 asignado Ver en GitHub

@andrewmusselman ya está trabajando en esto.

Desde el 23/4/2026.

Evaluación

Este issue todavía no se ha evaluado.

Descripción

ASVS priority

Issue: FINDING-061 - No PKCE Implementation in OAuth Authorization Code Flow

Labels: bug, security, priority:high, asvs-level:L2

ASVS Level(s): [L2-only]

Description:

Summary

The OAuth flow uses the state parameter for CSRF protection but does not implement Proof Key for Code Exchange (PKCE). ASVS 10.1.2 specifically names PKCE code_verifier as a client-generated secret that should be transaction-specific and session-bound. Without PKCE, the authorization code itself is the sole bearer credential for obtaining tokens, vulnerable to code interception attacks via Referer header leak, browser history, open redirector, malicious browser extensions, or network-level interception.

Details

Affected Files and Lines:

  • src/asfquart/generics.py:48-101 - OAuth flow without PKCE

The flow lacks PKCE protection, making authorization codes vulnerable to interception.

Recommended Remediation

Implement PKCE (RFC 7636) if the ASF OAuth service supports it:

# On login initiation
code_verifier = secrets.token_urlsafe(64)
code_challenge = base64.urlsafe_b64encode(
    hashlib.sha256(code_verifier.encode()).digest()
).rstrip(b'=').decode()

# Store code_verifier in pending_states
pending_states[state]['code_verifier'] = code_verifier

# Include in authorization request
oauth_url = (
    f"{OAUTH_URL_AUTHORIZE}?"
    f"response_type=code&"
    f"client_id={CLIENT_ID}&"
    f"redirect_uri={redirect_uri}&"
    f"state={state}&"
    f"code_challenge={code_challenge}&"
    f"code_challenge_method=S256"
)

# On token exchange
code_verifier = state_data['code_verifier']
token_params = {
    'code': code,
    'code_verifier': code_verifier,
    # ... other params
}
Acceptance Criteria
  • PKCE implementation added
  • code_verifier generated
  • code_challenge computed
  • Challenge included in auth request
  • Verifier included in token exchange
  • Unit test verifying the fix
References
  • Source reports: L2:10.1.2.md, L2:10.2.1.md
  • Related findings: FINDING-060, FINDING-062
  • ASVS sections: 10.1.2, 10.2.1
Priority

High

Lenguaje dominante
Python
Estrellas
7
Forks
13
Métricas de merge de PR
Sin PR fusionados en 30 d

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de apache/infrastructure-asfquart

Todos los issues de apache/infrastructure-asfquart

Issues similares

Más issues de Python

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.