Skip to content

fix(client): keep PAR off the mTLS alias for certificate-bound tokens alone - #553

Merged
osanderson merged 1 commit into
mainfrom
fix/mtls-aliases-per-request
Oct 4, 2026
Merged

osanderson merged 1 commit into
mainfrom
fix/mtls-aliases-per-request

Conversation

@osanderson

Copy link
Copy Markdown
Collaborator

Summary

This fixes a regression from #552, found by the conformance run against that branch. #552 is on main but unreleased: release PR #551 (v0.48.1) should not be merged until this lands.

What went wrong. #552 made ApplyForSenderConstrain move PAR to its mtls_endpoint_aliases entry, reading RFC 8705 §5 as one rule for every endpoint. FAPI 2.0 conformance testing reads §5 per request instead: an alias applies to a request that itself does mutual TLS. A private_key_jwt client with certificate-bound tokens does no mutual TLS at PAR, and the suite refused its PAR request in 19 of 21 relying-party tests:

The PAR endpoint was called over an mTLS secured connection, but this is not expected when using private_key_jwt client authentication without use_mtls_endpoint_aliases. The regular (non-mTLS) pushed_authorization_request_endpoint must be used.

The fix (per request):

Helper Moves Leaves
ApplyForSenderConstrain Token, CIBA backchannel authentication, revocation (as in v0.48.0) PAR: certificate binding has no PAR-time step (RFC 8705 §3)
ApplyForClientAuth Token, PAR, CIBA (CIBA Core §7.1: the client authenticates there), revocation
  • The part of fix(client): apply every mTLS endpoint alias, whatever the reason for mutual TLS #552 that holds: ApplyForClientAuth now also moves the CIBA endpoint, because a certificate-authenticated client does mutual TLS at every request that authenticates it.
  • Superset: ApplyForClientAuth covers everything ApplyForSenderConstrain does, so a client doing both needs one call.
  • Docs: the mTLS guide and the conformance client's comment describe the per-request rule.

Verification

  • Test: it pins the PAR exclusion for ApplyForSenderConstrain (citing the suite's message), and the full set for ApplyForClientAuth.
  • Mutation checks: moving PAR under sender-constrain, dropping PAR under client auth, or dropping the CIBA alias each makes the test fail.
  • Builds and suite: go vet, the full test suite, golangci-lint and the conformance client's build are clean.
  • Conformance: the full suite is being run against this branch. Merge only once it's clean.

🤖 Generated with Claude Code

… alone

The previous change made MTLSEndpoints.ApplyForSenderConstrain move PAR
to its mtls_endpoint_aliases entry, reading RFC 8705 §5 as one rule for
every endpoint. FAPI 2.0 conformance testing reads it per request: an
alias applies to a request that itself does mutual TLS. A client that
authenticates with private_key_jwt and uses mutual TLS only for
certificate-bound tokens does none at PAR, and the conformance suite
refuses its PAR request over mutual TLS ("The PAR endpoint was called
over an mTLS secured connection, but this is not expected when using
private_key_jwt client authentication"), failing 19 of 21 relying-party
tests for that configuration.

ApplyForSenderConstrain is back to Token, the CIBA backchannel
authentication endpoint and revocation, leaving PAR at the conventional
endpoint. ApplyForClientAuth keeps the part of the previous change that
holds either way: a certificate-authenticated client does mutual TLS at
every request that authenticates it, so it moves Token, PAR, the CIBA
endpoint (CIBA Core §7.1) and revocation, a superset of
ApplyForSenderConstrain's. The test pins the PAR exclusion, and the mTLS
guide and the conformance client's comment describe the per-request
rule.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sonarqubecloud

sonarqubecloud Bot commented Oct 4, 2026

Copy link
Copy Markdown

@codecov

codecov Bot commented Oct 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@osanderson
osanderson merged commit 648603b into main Oct 4, 2026
18 checks passed
@osanderson
osanderson deleted the fix/mtls-aliases-per-request branch October 4, 2026 14:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant