SIGN IN SIGN UP

TUN-10800: Consume authentication callback state

This adds callback handling for the browser-bound Quick Tunnel authentication state, consuming the POST to /.cloudflared/qt-auth/callback that the broker sends after login. The handler accepts a bounded application/x-www-form-urlencoded body containing exactly one state and one assertion, verifies the HMAC-signed state cookie, and binds it to the submitted state. 

It fails closed and clears the state cookie once consumption succeeds. On success, the handler returns the broker assertion and the validated return path for later use.
A
Alessandro Frigerio committed
eeac161daad63dc4d33f1c5a2e3825c63e501dc7
Parent: 5cf510d
Committed by Miguel da Costa Martins Marcelino <mdacostamartinsmarcelino@cloudflare.com> on 9/15/2026, 1:52:36 PM