🔒️(backend) secure native app OIDC login with exchange codes

Add one-time exchange code mechanism for native app OIDC login.
Instead of exposing session ID in redirect URL, generates a
short-lived single-use code stored in Redis. Native apps exchange
this code for the session ID via a dedicated API endpoint.

Includes NativeAppRedirect for custom URL schemes, rate limiting,
logging, and whitelist of allowed schemes.

Closes #1153

Co-Authored-By: gigi206
This commit is contained in:
Michel-Marie MAUDET
2026-03-20 18:35:49 +01:00
parent 4f2c4bfaf9
commit 724a4ef3df
72 changed files with 846 additions and 1755 deletions
+4
View File
@@ -7,6 +7,7 @@ from lasuite.oidc_login.urls import urlpatterns as oidc_urls
from rest_framework.routers import DefaultRouter
from core.api import get_frontend_configuration, viewsets
from core.authentication.api import session_exchange
from core.external_api import viewsets as external_viewsets
# - Main endpoints
@@ -40,6 +41,9 @@ urlpatterns = [
[
*router.urls,
*oidc_urls,
path(
"auth/session-exchange/", session_exchange, name="session_exchange"
),
path("config/", get_frontend_configuration, name="config"),
]
),