Skip to content

fix(client): apply the mTLS alias for revocation under certificate client auth - #550

Merged
osanderson merged 2 commits into
mainfrom
fix/mtls-alias-revocation
Oct 4, 2026
Merged

osanderson merged 2 commits into
mainfrom
fix/mtls-alias-revocation

Conversation

@osanderson

Copy link
Copy Markdown
Collaborator

Summary

These are two small corrections found while writing the mTLS and OpenID Federation guides (#549).

1. fix(client): ApplyForClientAuth now applies the revocation alias.

  • MTLSEndpoints.ApplyForClientAuth moved Token and PAR to their RFC 8705 §5 mtls_endpoint_aliases, but not the revocation endpoint added in v0.47.0.
  • A certificate-authenticated client (tls_client_auth, self_signed_tls_client_auth) authenticates at RevokeToken too. So with DPoP-bound tokens, where only ApplyForClientAuth applies, it sent revocation requests to the plain endpoint instead of the one where the server asks for its certificate.
  • ApplyForSenderConstrain already covered revocation. Now ApplyForClientAuth does too, and the test covers it; a mutation check confirms the test fails without the fix.

2. docs(federation): Resolver.Resolve's scope note was stale.

  • It said the package had "no trust marks" and no server-side federation endpoints. VerifyTrustMark, SelfIssuer and SubordinateIssuer all exist now.
  • The note now describes what Resolve itself does.

Verification

go vet, the full test suite and golangci-lint are clean.

🤖 Generated with Claude Code

@codecov

codecov Bot commented Oct 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

osanderson and others added 2 commits October 4, 2026 20:29
…ient auth

MTLSEndpoints.ApplyForClientAuth moved Token and PAR to their RFC 8705
§5 mtls_endpoint_aliases, but not the revocation endpoint added in
v0.47.0. A client that authenticates with its certificate
(tls_client_auth, self_signed_tls_client_auth) authenticates at
RevokeToken too, so it must reach the endpoint where the server asks
for that certificate. A certificate-authenticated client with
DPoP-bound tokens, which applies only ApplyForClientAuth, sent its
revocation requests to the plain endpoint. ApplyForClientAuth now
applies the Revocation alias as well.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The note said the package had no trust marks and no server-side
federation endpoints, but it now has VerifyTrustMark, SelfIssuer and
SubordinateIssuer. It now says what Resolve itself does: resolves a
leaf entity, returning its declared Trust Marks unverified for
VerifyTrustMark.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@osanderson
osanderson force-pushed the fix/mtls-alias-revocation branch from 1176d73 to a368902 Compare October 4, 2026 12:29
@sonarqubecloud

sonarqubecloud Bot commented Oct 4, 2026

Copy link
Copy Markdown

@osanderson
osanderson merged commit 4f4d76a into main Oct 4, 2026
17 checks passed
@osanderson
osanderson deleted the fix/mtls-alias-revocation branch October 4, 2026 12:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant