No PKCE Implementation in OAuth Authorization Code Flow
@andrewmusselman ya está trabajando en esto.
Desde el 23/4/2026.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
Issue: FINDING-061 - No PKCE Implementation in OAuth Authorization Code Flow
Labels: bug, security, priority:high, asvs-level:L2
ASVS Level(s): [L2-only]
Description:
Summary
The OAuth flow uses the state parameter for CSRF protection but does not implement Proof Key for Code Exchange (PKCE). ASVS 10.1.2 specifically names PKCE code_verifier as a client-generated secret that should be transaction-specific and session-bound. Without PKCE, the authorization code itself is the sole bearer credential for obtaining tokens, vulnerable to code interception attacks via Referer header leak, browser history, open redirector, malicious browser extensions, or network-level interception.
Details
Affected Files and Lines:
src/asfquart/generics.py:48-101- OAuth flow without PKCE
The flow lacks PKCE protection, making authorization codes vulnerable to interception.
Recommended Remediation
Implement PKCE (RFC 7636) if the ASF OAuth service supports it:
# On login initiation
code_verifier = secrets.token_urlsafe(64)
code_challenge = base64.urlsafe_b64encode(
hashlib.sha256(code_verifier.encode()).digest()
).rstrip(b'=').decode()
# Store code_verifier in pending_states
pending_states[state]['code_verifier'] = code_verifier
# Include in authorization request
oauth_url = (
f"{OAUTH_URL_AUTHORIZE}?"
f"response_type=code&"
f"client_id={CLIENT_ID}&"
f"redirect_uri={redirect_uri}&"
f"state={state}&"
f"code_challenge={code_challenge}&"
f"code_challenge_method=S256"
)
# On token exchange
code_verifier = state_data['code_verifier']
token_params = {
'code': code,
'code_verifier': code_verifier,
# ... other params
}
Acceptance Criteria
- PKCE implementation added
- code_verifier generated
- code_challenge computed
- Challenge included in auth request
- Verifier included in token exchange
- Unit test verifying the fix
References
- Source reports: L2:10.1.2.md, L2:10.2.1.md
- Related findings: FINDING-060, FINDING-062
- ASVS sections: 10.1.2, 10.2.1
Priority
High
- Lenguaje dominante
- Python
- Estrellas
- 7
- Forks
- 13
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de apache/infrastructure-asfquart
-
bug priority
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
-
documentation
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
-
Document OAuth callback consistency rulesPosiblemente ocupada @Marrshal15 la tomó hace 4 días. Abiertodocumentation
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
apache/infrastructure-asfquart#126 · 1 comentario ·
-
ASVS priority
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
apache/infrastructure-asfquart#85 · 1 comentario ·
-
Triage and track asfquart issuesPosiblemente ocupada @sbp la tomó hace 3 días. Abierto
apache/infrastructure-asfquart#134 · 1 asignado ·
Todos los issues de apache/infrastructure-asfquart
Issues similares
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100
MystenLabs/MemWal#1163 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
infertopics leaves new nodes without a topic when untopiced neighbours outnumber topiced onesPosiblemente ocupada @moneebullah25 la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
FinanceFlash/unvibecode#218 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
NVIDIA/earth2studio#1241 ·
Los mantenedores suelen responder en 3 días