mirror of
https://github.com/suitenumerique/messages.git
synced 2026-09-30 13:45:00 +02:00
Capacitor apps must run the OIDC flow in the system browser (the IdP cookie has to live there to provide cross-app SSO), but the browser's cookies never reach the app's native HTTP layer, so the Django session created by the callback would be stranded. The callback now redirects to an allowlisted app deep link with a one-time token that the app exchanges for its session cookie and CSRF token. The token is bound to the initiating app instance with a PKCE S256 verifier, single-use, short-lived (MOBILE_AUTH_TOKEN_TTL) and the anonymous exchange endpoint is throttled per IP to cap brute-force guessing. An empty MOBILE_AUTH_CALLBACK_SCHEMES (the default) keeps the whole handoff disabled.