diff --git a/.github/workflows/server.yml b/.github/workflows/server.yml index bbc447532..398dfa9e6 100644 --- a/.github/workflows/server.yml +++ b/.github/workflows/server.yml @@ -176,9 +176,18 @@ jobs: id: floating_tags run: | if [ "$GITHUB_REF" = "refs/heads/main" ]; then - echo "value=ghcr.io/zkldi/tachi:main\nghcr.io/zkldi/tachi:latest" >> "$GITHUB_OUTPUT" + { + echo "value<> "$GITHUB_OUTPUT" else - echo "value=ghcr.io/zkldi/tachi:main-dev" >> "$GITHUB_OUTPUT" + { + echo "value<> "$GITHUB_OUTPUT" fi - name: Build and push unified server image diff --git a/db/migrations/20260619120000_oauth2_pkce.sql b/db/migrations/20260619120000_oauth2_pkce.sql new file mode 100644 index 000000000..cc93abf61 --- /dev/null +++ b/db/migrations/20260619120000_oauth2_pkce.sql @@ -0,0 +1,6 @@ +-- Add PKCE (RFC 7636) support to OAuth2 authorization codes. +-- code_challenge: BASE64URL(SHA256(code_verifier)), stored at code creation time. +-- code_challenge_method: only "S256" is supported; NULL means client_secret flow. +ALTER TABLE "priv_oauth2_auth_token" + ADD COLUMN code_challenge TEXT, + ADD COLUMN code_challenge_method TEXT; diff --git a/typescript/client/src/app/pages/OAuthRequestAuthPage.tsx b/typescript/client/src/app/pages/OAuthRequestAuthPage.tsx index e5dbf3927..eda5498fa 100644 --- a/typescript/client/src/app/pages/OAuthRequestAuthPage.tsx +++ b/typescript/client/src/app/pages/OAuthRequestAuthPage.tsx @@ -65,6 +65,8 @@ function OAuthRequestAuthMain({ const params = useQueryString(); const context = params.get("context"); + const codeChallenge = params.get("code_challenge"); + const codeChallengeMethod = params.get("code_challenge_method"); return (
@@ -88,6 +90,16 @@ function OAuthRequestAuthMain({