test: codify SPA PKCE flow stages

This commit is contained in:
donghyeon-ka
2026-07-25 16:36:43 +09:00
parent 2765f5d109
commit 55a99b8147
2 changed files with 36 additions and 0 deletions
+15
View File
@@ -0,0 +1,15 @@
# Authorization Code + PKCE stages
1. SPA가 매 로그인마다 고엔트로피 `code_verifier`를 생성한다.
2. SHA-256과 Base64URL로 `code_challenge`를 만든다.
3. authorization request에는 challenge와 `S256`만 전송한다.
4. redirect의 code와 저장해 둔 state를 대조한다.
5. token request에 원래 verifier를 보내 code를 교환한다.
6. verifier/state/code는 한 번 사용한 뒤 메모리에서 제거한다.
Keycloak client는 public client이며 implicit와 password grant를 끄고 S256을
강제한다. PKCE는 악성 redirect endpoint가 code만 가로챘을 때의 교환을 막지만,
SPA 실행 컨텍스트를 장악한 XSS 자체를 막지는 않는다.
`verify-pkce-flow-stages.sh`는 Web Crypto 단위 테스트, realm client 계약,
authorization/token 요청의 필드를 함께 검사한다.