77f8f9f800779d886cbe1c5529277f3dc8aa2a94
okta_login() and okta_callback() (T10.2) both crash with a 500 (AssertionError: SessionMiddleware must be installed to access request.session) against a real Okta client, because Authlib's authorize_redirect() and authorize_access_token() both store/read OIDC state and nonce in request.session. Never caught by T10.2's or T10.3's own verification because every prior test mocked authorize_redirect / authorize_access_token directly, bypassing Authlib's real implementation entirely. Found while starting T10.5 and reproducing the real flow. Adds starlette.middleware.sessions.SessionMiddleware, on its own cookie (wp_oauth_state, distinct from the app's real session cookie wp_session) with a short 10-minute lifetime and same_site=lax so it survives the top-level redirect back from Okta. This cookie carries nothing but ephemeral per-attempt OAuth state — no identity, no long-term secret — so it reuses auth.SECRET_KEY rather than adding a new required config knob. Reused in T10.5 to carry the post-login redirect target across the same round trip. Adds itsdangerous to requirements.txt — SessionMiddleware's hard dependency, not previously needed anywhere in this app. Verified: reproduced the crash against server.app with a fake (network- bypassed) Authlib client and no SessionMiddleware, confirmed the AssertionError, then confirmed the same request succeeds (302 to the authorize URL, wp_oauth_state cookie set) once the middleware is added. wave-10.md T10.2 (bug fix)
Description
No description provided
Languages
Python
49.3%
JavaScript
32.6%
CSS
8.9%
HTML
8.7%
Shell
0.4%