OpenIddict 7.7 (MongoDB stores, keys kept in Mongo so tokens survive
restarts) serves /oauth/authorize, /oauth/token, /oauth/revoke and the
discovery documents, including /.well-known/oauth-authorization-server:
- authorization code (PKCE optional) and client credentials, Mastodon's
scopes including the granular ones, non-expiring reference tokens,
`created_at` in the token response, and the urn:ietf:wg:oauth:2.0:oob
page that shows the code;
- /oauth/login signs the private login into a fifteen-minute cookie that
only /oauth sees (rate limited, antiforgery-protected); /oauth/authorize
then asks which persona the application acts as. The token's subject
is that persona's id and nothing else; no root id reaches a token, an
authorization or a log line;
- the token exchange refuses a persona whose login is banned or deleted,
and every API request checks the same.
/api/v1/apps registers applications dynamically, /api/v1/apps/
verify_credentials, /api/v1/instance (v1 and v2, "4.2.0 (compatible;
PrivaPub)") and verify_credentials answer in Mastodon's shapes: snake_case
with explicit nulls, Rails-style parameters from query, form or JSON,
{"error": ...} on failure, Link paging. CORS exposes Link.
/api goes to OpenIddict validation and everything else to the existing
JWT; the JWT failure handler no longer sends the exception and stack trace
to the client.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
62 lines
2.4 KiB
XML
62 lines
2.4 KiB
XML
<Project Sdk="Microsoft.NET.Sdk.Web">
|
|
|
|
<PropertyGroup>
|
|
<TargetFramework>net10.0</TargetFramework>
|
|
<Nullable>disable</Nullable>
|
|
<ImplicitUsings>enable</ImplicitUsings>
|
|
</PropertyGroup>
|
|
|
|
<ItemGroup>
|
|
<PackageReference Include="HtmlSanitizer" Version="9.2.1039" />
|
|
<PackageReference Include="MailKit" Version="4.18.0" />
|
|
<PackageReference Include="Markdig" Version="1.4.0" />
|
|
<PackageReference Include="Microsoft.AspNetCore.Authentication.JwtBearer" Version="10.0.9" />
|
|
<PackageReference Include="MongoDB.Entities" Version="25.1.0" />
|
|
<PackageReference Include="OpenIddict.AspNetCore" Version="7.7.1" />
|
|
<PackageReference Include="OpenIddict.MongoDb" Version="7.7.1" />
|
|
<PackageReference Include="PasswordGenerator" Version="3.0.0" />
|
|
<PackageReference Include="Serilog.AspNetCore" Version="10.0.0" />
|
|
<PackageReference Include="Serilog.Sinks.MongoDB" Version="7.3.0" />
|
|
<PackageReference Include="Swashbuckle.AspNetCore" Version="10.2.3" />
|
|
</ItemGroup>
|
|
|
|
<ItemGroup>
|
|
<ProjectReference Include="..\PrivaPub.ClientModels\PrivaPub.ClientModels.csproj" />
|
|
</ItemGroup>
|
|
|
|
<ItemGroup>
|
|
<Compile Update="Resources\GenericRes.Designer.cs">
|
|
<DesignTime>True</DesignTime>
|
|
<AutoGen>True</AutoGen>
|
|
<DependentUpon>GenericRes.resx</DependentUpon>
|
|
</Compile>
|
|
</ItemGroup>
|
|
|
|
<ItemGroup>
|
|
<EmbeddedResource Update="Resources\GenericRes.resx">
|
|
<Generator>PublicResXFileCodeGenerator</Generator>
|
|
<LastGenOutput>GenericRes.Designer.cs</LastGenOutput>
|
|
</EmbeddedResource>
|
|
</ItemGroup>
|
|
|
|
<Target Name="GenerateBuildInfo" BeforeTargets="BeforeCompile">
|
|
<PropertyGroup>
|
|
<BuildInfoPath>$(IntermediateOutputPath)BuildInfo.g.cs</BuildInfoPath>
|
|
</PropertyGroup>
|
|
<ItemGroup>
|
|
<BuildInfoLine Include="public static class BuildInfo" />
|
|
<BuildInfoLine Include="{" />
|
|
<BuildInfoLine Include=" public const string Commit = "$(BuildCommit)"%3B" />
|
|
<BuildInfoLine Include=" public const string Ref = "$(BuildRef)"%3B" />
|
|
<BuildInfoLine Include=" public const string BuiltAt = "$(BuildTimeUtc)"%3B" />
|
|
<BuildInfoLine Include="}" />
|
|
</ItemGroup>
|
|
<WriteLinesToFile File="$(BuildInfoPath)" Lines="@(BuildInfoLine)" Overwrite="true" WriteOnlyWhenDifferent="true" />
|
|
<ItemGroup>
|
|
<Compile Include="$(BuildInfoPath)" />
|
|
<FileWrites Include="$(BuildInfoPath)" />
|
|
</ItemGroup>
|
|
</Target>
|
|
|
|
</Project>
|