The state of an authorization request and the PKCE code verifier that goes with it: random, or with a secret, a state that carries the session, signed, and that a nonce ties to the browser.
The kind of a state is a keyword of its sign-in protocol, e.g. :dk.simongray.indieauth/session, so that under a shared secret the state of one protocol never passes for that of another.
The state of an authorization request and the PKCE code verifier that goes with it: random, or with a secret, a state that carries the session, signed, and that a nonce ties to the browser. The kind of a state is a keyword of its sign-in protocol, e.g. :dk.simongray.indieauth/session, so that under a shared secret the state of one protocol never passes for that of another.
(fresh secret kind session at)The :state and the PKCE :code-verifier of the session, and with a
secret, the :nonce of a state of the kind that carries the session,
signed at the instant at.
Keep the nonce where only the user's browser has it, e.g. in a cookie, and give it to session with the state when the browser comes back. Without a secret, the state is random and carries nothing.
The :state and the PKCE :code-verifier of the `session`, and with a `secret`, the :nonce of a state of the `kind` that carries the session, signed at the instant `at`. Keep the nonce where only the user's browser has it, e.g. in a cookie, and give it to session with the state when the browser comes back. Without a secret, the state is random and carries nothing.
(session secret kind state nonce at max-seconds)The session that the state of the kind carries, by the secret, if
the nonce is the session's, and the state was signed at most
max-seconds before the instant at, or else nil. The session has its
:nonce, :state and :code-verifier too.
The session that the `state` of the `kind` carries, by the `secret`, if the `nonce` is the session's, and the state was signed at most `max-seconds` before the instant `at`, or else nil. The session has its :nonce, :state and :code-verifier too.
cljdoc builds & hosts documentation for Clojure/Script libraries
| Ctrl+k | Jump to recent docs |
| ← | Move to previous article |
| → | Move to next article |
| Ctrl+/ | Jump to the search field |