Part 9 · 1 chapters · ~8 min
Capstone: An Auth Service
The capstone: an OIDC-compliant auth service with the code flow and PKCE, passkey login, refresh rotation with reuse detection, step-up for transfers, an OpenFGA permission model for accounts, and a test suite of attacks it must stop.
18
The build and the attack suite
code
auth-capstone/ issuer /.well-known/openid-configuration, /jwks.json (ES256, kid rotation), /authorize, /token login passkey (WebAuthn) primary, TOTP fallback, risk-scored tokens access 10 min (aud-bound), refresh rotated with family reuse detection, ID token step-up acr=step-up claim valid 5 min, required by POST /transfers above ₦100,000 authz OpenFGA model (team, workspace, account) checked by the resource API attack tests (must all fail) alg=none token · HS256 signed with the public key · token for another audience · expired token with skewed clock replayed authorisation code · code without PKCE verifier · reused refresh token (family must be revoked) user A reading account of user B (BOLA) · tenant id injected in body · transfer without step-up