| 1 |
|
| 2 |
|
| 3 |
|
| 4 |
|
| 5 |
|
| 6 |
|
| 7 |
|
| 8 |
|
| 9 |
|
| 10 |
|
| 11 |
|
| 12 |
|
| 13 |
use base64::{engine::general_purpose::URL_SAFE_NO_PAD, Engine}; |
| 14 |
use rand::RngCore; |
| 15 |
use sha2::{Digest, Sha256}; |
| 16 |
|
| 17 |
|
| 18 |
pub struct Pkce { |
| 19 |
|
| 20 |
pub verifier: String, |
| 21 |
|
| 22 |
pub challenge: String, |
| 23 |
} |
| 24 |
|
| 25 |
|
| 26 |
|
| 27 |
|
| 28 |
|
| 29 |
pub fn generate_pkce() -> Pkce { |
| 30 |
let mut bytes = [0u8; 32]; |
| 31 |
rand::rng().fill_bytes(&mut bytes); |
| 32 |
let verifier = URL_SAFE_NO_PAD.encode(bytes); |
| 33 |
let digest = Sha256::digest(verifier.as_bytes()); |
| 34 |
let challenge = URL_SAFE_NO_PAD.encode(digest); |
| 35 |
Pkce { verifier, challenge } |
| 36 |
} |
| 37 |
|
| 38 |
|
| 39 |
pub fn generate_oauth_state() -> String { |
| 40 |
let mut bytes = [0u8; 16]; |
| 41 |
rand::rng().fill_bytes(&mut bytes); |
| 42 |
URL_SAFE_NO_PAD.encode(bytes) |
| 43 |
} |
| 44 |
|
| 45 |
#[cfg(test)] |
| 46 |
mod tests { |
| 47 |
use super::*; |
| 48 |
|
| 49 |
#[test] |
| 50 |
fn verifier_is_43_chars_unreserved() { |
| 51 |
let p = generate_pkce(); |
| 52 |
assert_eq!(p.verifier.len(), 43); |
| 53 |
assert!( |
| 54 |
p.verifier |
| 55 |
.chars() |
| 56 |
.all(|c| c.is_ascii_alphanumeric() || c == '-' || c == '_'), |
| 57 |
"verifier must use only the unreserved PKCE charset: {}", |
| 58 |
p.verifier |
| 59 |
); |
| 60 |
} |
| 61 |
|
| 62 |
#[test] |
| 63 |
fn challenge_is_s256_of_verifier() { |
| 64 |
let p = generate_pkce(); |
| 65 |
let expected = URL_SAFE_NO_PAD.encode(Sha256::digest(p.verifier.as_bytes())); |
| 66 |
assert_eq!(p.challenge, expected); |
| 67 |
|
| 68 |
assert_eq!(p.challenge.len(), 43); |
| 69 |
} |
| 70 |
|
| 71 |
#[test] |
| 72 |
fn pairs_and_states_are_unique() { |
| 73 |
assert_ne!(generate_pkce().verifier, generate_pkce().verifier); |
| 74 |
assert_ne!(generate_oauth_state(), generate_oauth_state()); |
| 75 |
} |
| 76 |
} |
| 77 |
|