The state of an authorization request and the PKCE code verifier that goes with it, and with a secret, a cookie that carries the session, signed, and ties the state to the browser.
The state is random and short whatever the session holds, since it travels in a URL, which a provider may limit and logs. The kind of a cookie is a keyword of its sign-in protocol, e.g. :dk.simongray.indieauth/session, so that under a shared secret the cookie of one protocol never passes for that of another.
The state of an authorization request and the PKCE code verifier that goes with it, and with a secret, a cookie that carries the session, signed, and ties the state to the browser. The state is random and short whatever the session holds, since it travels in a URL, which a provider may limit and logs. The kind of a cookie is a keyword of its sign-in protocol, e.g. :dk.simongray.indieauth/session, so that under a shared secret the cookie of one protocol never passes for that of another.
(fresh secret kind session at)(fresh secret kind session at max-bytes)The random :state and the PKCE :code-verifier of the session, and
with a secret, the :cookie of the kind that carries the session and
the state, signed at the instant at.
Keep the cookie where only the user's browser has it, e.g. in an
HttpOnly cookie, and give it to session with the state when the browser
comes back. A cookie of more than max-bytes, max-cookie-bytes by
default, throws, since a browser drops a cookie that's too large without
a word.
The random :state and the PKCE :code-verifier of the `session`, and with a `secret`, the :cookie of the `kind` that carries the session and the state, signed at the instant `at`. Keep the cookie where only the user's browser has it, e.g. in an HttpOnly cookie, and give it to session with the state when the browser comes back. A cookie of more than `max-bytes`, max-cookie-bytes by default, throws, since a browser drops a cookie that's too large without a word.
The size of the largest cookie that fresh gives by default, which leaves room for the cookie's name within the 4096 bytes of a browser.
The size of the largest cookie that fresh gives by default, which leaves room for the cookie's name within the 4096 bytes of a browser.
(session secret kind state cookie at max-seconds)The session that the cookie of the kind carries, by the secret, if
its state is the state that came back, and it was signed at most
max-seconds before the instant at, or else nil. The session has its
:state, :code-verifier and :cookie too.
The session that the `cookie` of the `kind` carries, by the `secret`, if its state is the `state` that came back, and it was signed at most `max-seconds` before the instant `at`, or else nil. The session has its :state, :code-verifier and :cookie too.
cljdoc builds & hosts documentation for Clojure/Script libraries
| Ctrl+k | Jump to recent docs |
| ← | Move to previous article |
| → | Move to next article |
| Ctrl+/ | Jump to the search field |