Hey.
generate_token() uses a default length of 30 and string.ascii_letters + string.digits as characters:
https://github.com/authlib/authlib/blob/main/authlib/common/security.py#L7-L12
At least when being used for creating PKCE code verifiers, it might be good if it follows the recommendations of
RFC 7636 chapter 4.1. Client Creates a Code Verifier, i.e.:
- all unreserved characters (
-. ., _ and ~ are currently missing)
- a minimum length of 43 characters and a maximum length of 128 characters
I'd recommend taking the maximum of 128 as default (better safe than sorry, and if someone feels 128 costs too much performance, he could still reduce it)
If generate_token() is also used in other places where this isn't desirable, what about adding a small wrapper function that does the right thing for code verifiers?
Thanks,
Chris.
Hey.
generate_token()uses a default length of 30 andstring.ascii_letters + string.digitsas characters:https://github.com/authlib/authlib/blob/main/authlib/common/security.py#L7-L12
At least when being used for creating PKCE code verifiers, it might be good if it follows the recommendations of
RFC 7636 chapter 4.1. Client Creates a Code Verifier, i.e.:
-..,_and~are currently missing)I'd recommend taking the maximum of
128as default (better safe than sorry, and if someone feels 128 costs too much performance, he could still reduce it)If
generate_token()is also used in other places where this isn't desirable, what about adding a small wrapper function that does the right thing for code verifiers?Thanks,
Chris.