Skip to content

authlib.common.security.generate_token, at least when used for PKCE code verifiers, should follow RFC 7636 recommendations #935

Description

@calestyo

Hey.

generate_token() uses a default length of 30 and string.ascii_letters + string.digits as characters:
https://github.com/authlib/authlib/blob/main/authlib/common/security.py#L7-L12

At least when being used for creating PKCE code verifiers, it might be good if it follows the recommendations of
RFC 7636 chapter 4.1. Client Creates a Code Verifier, i.e.:

  • all unreserved characters (-. ., _ and ~ are currently missing)
  • a minimum length of 43 characters and a maximum length of 128 characters
    I'd recommend taking the maximum of 128 as default (better safe than sorry, and if someone feels 128 costs too much performance, he could still reduce it)

If generate_token() is also used in other places where this isn't desirable, what about adding a small wrapper function that does the right thing for code verifiers?

Thanks,
Chris.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions