Skip to content

Commit f1e04ed

Browse files
StiensWoutcodex
andcommitted
fix: satisfy DPoP URL guard checks
Co-authored-by: Codex <codex@openai.com>
1 parent 004527c commit f1e04ed

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

apps/server/src/auth/dpop.ts

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ export const verifyRequestDpopProof = (input: {
3333
}) =>
3434
Effect.gen(function* () {
3535
const proof = input.request.headers.dpop;
36-
const url = HttpServerRequest.toURL(input.request)
36+
const url = HttpServerRequest.toURL(input.request);
3737
if (Option.isNone(url)) {
3838
return yield* new ServerAuthInvalidCredentialError({
3939
diagnostic: "Invalid DPoP request URL.",
@@ -43,7 +43,7 @@ export const verifyRequestDpopProof = (input: {
4343
const result = verifyDpopProof({
4444
proof,
4545
method: input.request.method,
46-
url: url.value,
46+
url: url.value.href,
4747
nowEpochSeconds: Math.floor(now.epochMilliseconds / 1_000),
4848
...(input.expectedThumbprint ? { expectedThumbprint: input.expectedThumbprint } : {}),
4949
...(input.expectedAccessToken ? { expectedAccessToken: input.expectedAccessToken } : {}),

0 commit comments

Comments
 (0)