Skip to content

OAuth: Pushed Authorization Requests (PAR) #171

@Radiergummi

Description

@Radiergummi

Description

Pushed Authorization Requests (RFC 9126) for enhanced security by sending auth parameters directly to the server.

Implemented

  • ✅ PAR endpoint (/auth/oauth/par)
  • ✅ Request URI generation
  • ✅ Request URI consumption
  • ✅ Request expiration
  • ✅ PKCE forwarding

Remaining Work

  • Request object support (RFC 9101)
  • Request object signing/encryption
  • Require PAR mode per client
  • Request URI caching optimization
  • Request binding (DPoP, mTLS)

Files

Getting Started

  1. Review existing PAR implementation
  2. Add request object support
  3. Implement require-PAR client option

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions