Part 9 · 1 chapters · ~8 min

Capstone: An Auth Service

The capstone: an OIDC-compliant auth service with the code flow and PKCE, passkey login, refresh rotation with reuse detection, step-up for transfers, an OpenFGA permission model for accounts, and a test suite of attacks it must stop.

18

The build and the attack suite

code
auth-capstone/
  issuer        /.well-known/openid-configuration, /jwks.json (ES256, kid rotation), /authorize, /token
  login         passkey (WebAuthn) primary, TOTP fallback, risk-scored
  tokens        access 10 min (aud-bound), refresh rotated with family reuse detection, ID token
  step-up       acr=step-up claim valid 5 min, required by POST /transfers above ₦100,000
  authz         OpenFGA model (team, workspace, account) checked by the resource API
attack tests (must all fail)
  alg=none token · HS256 signed with the public key · token for another audience · expired token with skewed clock
  replayed authorisation code · code without PKCE verifier · reused refresh token (family must be revoked)
  user A reading account of user B (BOLA) · tenant id injected in body · transfer without step-up