0Pricing
OAuth2 & OpenID Connect Deep Dive · Leçon

Paramètre d’état et CSRF

Comprenez comment le paramètre « state » atténue les attaques par falsification de requête intersite (CSRF) dans les flux OAuth2.

Paramètre d’état et CSRF est une leçon OAuth2 & OpenID Connect Deep Dive gratuite sur CoddyKit. Ceci est la leçon 2 sur 4. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage OAuth2 & OpenID Connect Deep Dive, et ta progression se synchronise sur le web et l'application CoddyKit. Le cours OAuth2 & OpenID Connect Deep Dive comprend 4 leçons au total.

Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.

Understanding CSRF Attacks

Have you heard of Cross-Site Request Forgery (CSRF)? It's a type of attack where an attacker tricks a user's web browser into performing an unwanted action on a trusted site where the user is currently authenticated.

Think of it as someone forging your signature on a document you didn't intend to sign, leveraging your existing trust with the recipient.

CSRF's Threat to OAuth2

In OAuth2, a CSRF attack could be dangerous. An attacker might trick a user into clicking a malicious link that initiates an OAuth2 flow to an attacker-controlled application.

If the user is logged into the Authorization Server and grants access, the Authorization Code could be sent to the attacker's client instead of the legitimate one, compromising the user's data.

The 'state' Parameter to the Rescue

To combat CSRF in OAuth2, we use the state parameter. It's an opaque value that the client application generates and sends along with the authorization request.

The Authorization Server then returns this exact state value when redirecting the user back to the client. This allows the client to verify the request's authenticity.

Client Creates a Unique 'state'

The client application is responsible for generating a unique, unguessable state value for each authorization request. This value should be cryptographically strong and stored securely in the user's session (e.g., a cookie) on the client side.

Let's see a simple way to generate such a string in Java:

import java.security.SecureRandom;
import java.util.Base64;

public class StateGenerator {
  public static void main(String[] args) {
    SecureRandom random = new SecureRandom();
    byte[] bytes = new byte[32]; // 32 bytes = 256 bits
    random.nextBytes(bytes);
    String state = Base64.getUrlEncoder()
                         .withoutPadding()
                         .encodeToString(bytes);
    System.out.println("Generated state: " + state);
  }
}

Sending 'state' in the Request

When the client application redirects the user to the Authorization Server to begin the OAuth2 flow, it includes the generated state parameter in the URL. This is how the Authorization Server 'remembers' the state.

GET /authorize?
  response_type=code&
  client_id=myclientid&
  redirect_uri=https://client.com/callback&
  scope=profile&
  state=YOUR_UNIQUE_STATE_HERE

Authorization Server Echoes 'state'

After the user successfully authenticates and grants permission at the Authorization Server, the server redirects the user back to the client's registered redirect_uri.

Crucially, this redirect includes the *exact same* state parameter that the client originally sent.

GET https://client.com/callback?
  code=AUTHORIZATION_CODE&
  state=YOUR_UNIQUE_STATE_HERE

Verifying the 'state' Parameter

Upon receiving the redirect from the Authorization Server, the client application performs a critical check:

  • It retrieves the state value from the incoming URL.
  • It compares this value with the state it originally generated and stored in the user's session.

If they don't match, the client *must* reject the request.

'state' Parameter in Action

How does this prevent CSRF? If an attacker tries to trick a user, they won't know the legitimate state value stored in the user's session on the client side.

When the forged request returns to the client, the state parameter in the URL won't match the one the client expects, and the client will reject the request, thwarting the attack.

'state' Parameter Best Practices

To maximize the effectiveness of the state parameter:

  • Uniqueness: Always generate a new, random state for each authorization request.
  • Storage: Store it securely, typically in a session cookie, linked to the user's browser session.
  • Expiration: Implement a short expiration time for the state to prevent replay attacks.
  • Cryptographic Strength: Use a cryptographically secure random number generator to ensure unpredictability.

Quick Check: 'state' Parameter

Review what you've learned about the state parameter in OAuth2.

Recap: Securing with 'state'

We learned that the state parameter is a vital security feature in OAuth2. It's a unique, random value generated by the client, sent to the Authorization Server, and then echoed back to the client.

By validating this parameter, the client can confirm the authenticity of the incoming request, effectively protecting against CSRF attacks and ensuring a secure authorization flow.

Questions Fréquemment Posées

La leçon « Paramètre d’état et CSRF » est-elle gratuite ?

Oui — le texte complet de « Paramètre d’état et CSRF » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours OAuth2 & OpenID Connect Deep Dive, passe à CoddyKit PRO. Le cours OAuth2 & OpenID Connect Deep Dive comprend 4 leçons au total.

Qu'est-ce que j'apprendrai dans « Paramètre d’état et CSRF » ?

Comprenez comment le paramètre « state » atténue les attaques par falsification de requête intersite (CSRF) dans les flux OAuth2. Tu pratiques OAuth2 & OpenID Connect Deep Dive avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.

Dois-je avoir de l'expérience pour commencer OAuth2 & OpenID Connect Deep Dive ?

Aucune expérience préalable n'est requise. OAuth2 & OpenID Connect Deep Dive sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 2 sur 4.

Combien de temps prend la leçon « Paramètre d’état et CSRF » ?

La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.

Peux-tu écrire et exécuter du code dans cette leçon OAuth2 & OpenID Connect Deep Dive ?

Oui. Chaque leçon OAuth2 & OpenID Connect Deep Dive inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.

Toutes les leçons de ce cours

  1. Sécurité des jetons d’accès et d’actualisation
  2. Paramètre d’état et CSRF
  3. Bonnes pratiques relatives aux types d’octroi
  4. Sécuriser les URI de redirection
← Retour à OAuth2 & OpenID Connect Deep Dive