joyn auth

This commit is contained in:
Nirvana
2026-05-29 21:43:50 +02:00
parent 580572f840
commit add65362c6
2 changed files with 37 additions and 12 deletions
+31 -7
View File
@@ -373,13 +373,15 @@ class JoynAuthenticator(BaseOAuth2Authenticator):
"scope": self.oauth_scope,
"view_type": "login",
"cd1": cd1,
"client_id": self.oauth_client_id, # OUR correct web client ID
"client_id": self.oauth_client_id,
"prompt": "consent",
"response_mode": "query",
"cmpUcId": cmp_uc_id,
"cmpUcInstance": cmp_uc_instance,
"redirect_uri": self.oauth_redirect_uri,
"state": state,
"cd9": "", # NEW - required by server
"cd10": JOYN_DOMAINS.get(self.country, JOYN_DOMAINS["de"]), # NEW - required by server
"code_challenge": code_challenge,
"code_challenge_method": "S256",
}
@@ -471,16 +473,38 @@ class JoynAuthenticator(BaseOAuth2Authenticator):
except Exception as e:
logger.debug(f"User check failed (non-fatal): {e}")
# Submit login
# Step 1: Initiate verification — tells the server we're doing password auth
initiate_response = _request(
"POST",
f"https://auth.7pass.de/verification-srv/v2/authenticate/initiate/PASSWORD",
json={
"request_id": request_id,
"email": username,
"medium_id": "PASSWORD",
"usage_type": "PASSWORDLESS_AUTHENTICATION",
"type": "PASSWORD",
},
content_type="application/json",
)
initiate_response.raise_for_status()
initiate_data = initiate_response.json()
exchange_id = initiate_data.get("exchange_id")
sub = initiate_data.get("sub", "")
if not exchange_id:
raise Exception("Could not extract exchange_id from initiate response")
# Step 2: Submit the actual password
login_response = _request(
"POST",
"https://auth.7pass.de/login-srv/verification/login",
data=urlencode({
"username": username,
json={
"exchange_id": exchange_id,
"pass_code": password,
"sub": sub,
"type": "PASSWORD",
"password": password,
"requestId": request_id
}),
content_type="application/x-www-form-urlencoded",
},
content_type="application/json",
allow_redirects=True,
)
login_response.raise_for_status()
@@ -19,14 +19,15 @@ JOYN_7PASS_BASE_URL = "https://auth.7pass.de"
# 7pass OIDC endpoints (discovered via OIDC discovery)
JOYN_7PASS_ENDPOINTS = {
"AUTHORIZE": f"{JOYN_7PASS_BASE_URL}/authorize",
"AUTHORIZE": f"{JOYN_7PASS_BASE_URL}/authz-srv/authz", # correct path
"TOKEN": f"{JOYN_7PASS_BASE_URL}/token",
"LOGIN": f"{JOYN_7PASS_BASE_URL}/login-srv/login",
"CONSENT_ACCEPT": f"{JOYN_7PASS_BASE_URL}/consent-management-srv/consent/scope/accept",
"PRECHECK_CONTINUE": f"{JOYN_7PASS_BASE_URL}/login-srv/precheck/continue",
"LOGIN": f"{JOYN_7PASS_BASE_URL}/login-srv/verification/login", # correct login path
"CONSENT_ACCEPT": f"{JOYN_7PASS_BASE_URL}/login-srv/consent/accept", # correct consent path
"PRECHECK_CONTINUE": f"{JOYN_7PASS_BASE_URL}/precheck/continue", # correct precheck path
"USER_CHECK_EXISTS": f"{JOYN_7PASS_BASE_URL}/users-srv/user/checkexists",
"REGISTRATION_SETUP": f"{JOYN_7PASS_BASE_URL}/registration-setup-srv/public/list",
"VERIFICATION_CONFIGURED": f"{JOYN_7PASS_BASE_URL}/verification-srv/v2/setup/public/configured/list",
"VERIFICATION_INITIATE": f"{JOYN_7PASS_BASE_URL}/verification-srv/v2/authenticate/initiate/PASSWORD", # NEW
}
# Joyn auth endpoints (non-OIDC)
@@ -39,7 +40,7 @@ JOYN_OAUTH_SCOPE = "openid email profile offline_access"
# Device IDs for different platforms (fallback for client identification)
DEVICE_IDS = {
"web": "709115c2-f87e-4bad-9b94-28ac08d72cd9",
"web": "655e06a5-829b-40c7-8084-077b87d26f8c",
"android": "05f5f3df-1130-4707-a761-c04d0c50b7f2",
"ios": "21218403-52ec-4a65-abf4-f36a0eadd631",
}