auth

package
v0.12.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 4, 2026 License: MIT Imports: 21 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func DeleteToken added in v0.12.0

func DeleteToken() error

DeleteToken removes the stored token from the system keychain. Deleting an already-absent token is not an error.

func EnvTokenSet added in v0.12.0

func EnvTokenSet() bool

EnvTokenSet reports whether HARDCOVER_TOKEN overrides the stored login.

func GetConf added in v0.12.0

func GetConf() *oauth2.Config

func GetToken

func GetToken() (*oauth2.Token, error)

GetToken returns the token to authenticate with, priority: env var > keychain. It does not refresh an expired token itself; pass the result through TokenSource to get one that refreshes (and persists the refresh) on demand.

func LogOut added in v0.12.0

func LogOut(ctx context.Context, token *oauth2.Token) error

func Login added in v0.12.0

func Login(ctx context.Context, out io.Writer) (*oauth2.Token, error)

func NewTokenURL added in v0.12.0

func NewTokenURL() string

NewTokenURL returns a link to Hardcover's "New API Key" form with oku's required scopes pre-checked, per https://docs.hardcover.app/api/pat-link-builder/

func PromptToken

func PromptToken() (string, error)

PromptToken reads a token interactively from stdin. On a terminal the input is not echoed so the secret stays out of the screen and scrollback. This backs the manual `set-token` fallback for environments where the browser-based login flow (`oku auth login`) isn't usable.

func SetToken

func SetToken(token *oauth2.Token) error

SetToken stores an OAuth token in the system keychain.

func StoredToken added in v0.12.0

func StoredToken() (*oauth2.Token, error)

StoredToken returns the token saved in the system keychain, ignoring any HARDCOVER_TOKEN override.

func TokenSource added in v0.12.0

func TokenSource(ctx context.Context, token *oauth2.Token) oauth2.TokenSource

TokenSource returns an oauth2.TokenSource backed by GetConf's endpoint that transparently refreshes token when it has expired, and persists any refreshed token back to the keychain so the next invocation of oku picks it up without needing to refresh again.

When HARDCOVER_TOKEN is set, token is used as-is and the keychain is never touched, so the env var keeps working as a workaround on machines without a usable keychain backend (it has no refresh token anyway, so there would be nothing to refresh).

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL