oauth

package
v0.0.0-...-30b4b00 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 5, 2026 License: AGPL-3.0 Imports: 13 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func GenerateState

func GenerateState() string

GenerateState generates a random state string for OAuth CSRF protection

func GenerateUsername

func GenerateUsername(prefix string) string

GenerateUsername generates a unique username with prefix

func GetAllProviders

func GetAllProviders() map[string]Provider

GetAllProviders returns all registered OAuth providers

func GetWeChatQRCodeURL

func GetWeChatQRCodeURL(state string) string

GetWeChatQRCodeURL returns the WeChat QR code login URL

func IsProviderRegistered

func IsProviderRegistered(name string) bool

IsProviderRegistered checks if a provider is registered

func LoadCustomProviders

func LoadCustomProviders() error

LoadCustomProviders loads custom OAuth providers from the database and registers them

func Register

func Register(name string, provider Provider)

Register registers an OAuth provider with the given name

Types

type AccessDeniedError

type AccessDeniedError struct {
	Message string
}

AccessDeniedError is a direct user-facing access denial message.

func (*AccessDeniedError) Error

func (e *AccessDeniedError) Error() string

type GenericOAuthConfig

type GenericOAuthConfig struct {
	Id                    int    `json:"id"`
	Name                  string `json:"name"`
	Slug                  string `json:"slug"`
	Icon                  string `json:"icon"`
	ClientId              string `json:"client_id"`
	AuthorizationEndpoint string `json:"authorization_endpoint"`
	Scopes                string `json:"scopes"`
	Enabled               bool   `json:"enabled"`
}

GenericOAuthConfig holds configuration for a custom OAuth provider

type GenericOAuthProvider

type GenericOAuthProvider struct {
	Name         string
	ClientID     string
	ClientSecret string
	Enabled      bool
	ProviderID   int
}

GenericOAuthProvider is a generic OAuth provider implementation

func (*GenericOAuthProvider) ExchangeToken

func (p *GenericOAuthProvider) ExchangeToken(ctx context.Context, code string, c *gin.Context) (*OAuthToken, error)

ExchangeToken exchanges authorization code for access token

func (*GenericOAuthProvider) FillUserByProviderID

func (p *GenericOAuthProvider) FillUserByProviderID(user *model.User, providerUserID string) error

FillUserByProviderID fills the user model by provider user ID

func (*GenericOAuthProvider) GetConfig

GetConfig returns the provider's configuration

func (*GenericOAuthProvider) GetName

func (p *GenericOAuthProvider) GetName() string

GetName returns the provider name

func (*GenericOAuthProvider) GetProviderId

func (p *GenericOAuthProvider) GetProviderId() int

GetProviderId returns the provider ID

func (*GenericOAuthProvider) GetProviderPrefix

func (p *GenericOAuthProvider) GetProviderPrefix() string

GetProviderPrefix returns the prefix for auto-generated usernames

func (*GenericOAuthProvider) GetUserInfo

func (p *GenericOAuthProvider) GetUserInfo(ctx context.Context, token *OAuthToken) (*OAuthUser, error)

GetUserInfo retrieves user information using the access token

func (*GenericOAuthProvider) IsEnabled

func (p *GenericOAuthProvider) IsEnabled() bool

IsEnabled returns whether the provider is enabled

func (*GenericOAuthProvider) IsUserIDTaken

func (p *GenericOAuthProvider) IsUserIDTaken(providerUserID string) bool

IsUserIDTaken checks if the provider user ID is already associated with an account

func (*GenericOAuthProvider) SetProviderUserID

func (p *GenericOAuthProvider) SetProviderUserID(user *model.User, providerUserID string)

SetProviderUserID sets the provider user ID on the user model

type OAuthError

type OAuthError struct {
	// MsgKey is the i18n message key
	MsgKey string
	// Params contains optional parameters for the message template
	Params map[string]any
	// RawError is the underlying error for logging purposes
	RawError string
}

OAuthError represents a translatable OAuth error

func NewOAuthError

func NewOAuthError(msgKey string, params map[string]any) *OAuthError

NewOAuthError creates a new OAuth error with the given message key

func NewOAuthErrorWithRaw

func NewOAuthErrorWithRaw(msgKey string, params map[string]any, rawError string) *OAuthError

NewOAuthErrorWithRaw creates a new OAuth error with raw error message for logging

func (*OAuthError) Error

func (e *OAuthError) Error() string

type OAuthToken

type OAuthToken struct {
	AccessToken  string `json:"access_token"`
	TokenType    string `json:"token_type"`
	RefreshToken string `json:"refresh_token,omitempty"`
	ExpiresIn    int    `json:"expires_in,omitempty"`
	Scope        string `json:"scope,omitempty"`
	IDToken      string `json:"id_token,omitempty"`
	OpenID       string `json:"openid,omitempty"`  // WeChat specific
	UnionID      string `json:"unionid,omitempty"` // WeChat specific
}

OAuthToken represents the token received from OAuth provider

type OAuthUser

type OAuthUser struct {
	// ProviderUserID is the unique identifier from the OAuth provider
	ProviderUserID string
	// Username is the username from the OAuth provider (e.g., GitHub login)
	Username string
	// DisplayName is the display name from the OAuth provider
	DisplayName string
	// Email is the email from the OAuth provider
	Email string
	// Extra contains any additional provider-specific data
	Extra map[string]any
}

OAuthUser represents the user info from OAuth provider

type Provider

type Provider interface {
	// GetName returns the display name of the provider (e.g., "GitHub", "Discord")
	GetName() string

	// IsEnabled returns whether this OAuth provider is enabled
	IsEnabled() bool

	// ExchangeToken exchanges the authorization code for an access token
	// The gin.Context is passed for providers that need request info (e.g., for redirect_uri)
	ExchangeToken(ctx context.Context, code string, c *gin.Context) (*OAuthToken, error)

	// GetUserInfo retrieves user information using the access token
	GetUserInfo(ctx context.Context, token *OAuthToken) (*OAuthUser, error)

	// IsUserIDTaken checks if the provider user ID is already associated with an account
	IsUserIDTaken(providerUserID string) bool

	// FillUserByProviderID fills the user model by provider user ID
	FillUserByProviderID(user *model.User, providerUserID string) error

	// SetProviderUserID sets the provider user ID on the user model
	SetProviderUserID(user *model.User, providerUserID string)

	// GetProviderPrefix returns the prefix for auto-generated usernames (e.g., "github_")
	GetProviderPrefix() string

	// GetConfig returns the provider's configuration (for custom OAuth providers)
	GetConfig() GenericOAuthConfig
}

Provider defines the interface for OAuth providers

func GetEnabledCustomProviders

func GetEnabledCustomProviders() []Provider

GetEnabledCustomProviders returns all registered custom OAuth providers that are enabled

func GetProvider

func GetProvider(name string) Provider

GetProvider returns the OAuth provider for the given name

type TrustLevelError

type TrustLevelError struct{}

TrustLevelError indicates the user's trust level is insufficient for OAuth.

func (*TrustLevelError) Error

func (e *TrustLevelError) Error() string

type WeChatProvider

type WeChatProvider struct{}

WeChatProvider implements Provider for WeChat Open Platform

func (*WeChatProvider) ExchangeToken

func (w *WeChatProvider) ExchangeToken(ctx context.Context, code string, c *gin.Context) (*OAuthToken, error)

func (*WeChatProvider) FillUserByProviderID

func (w *WeChatProvider) FillUserByProviderID(user *model.User, providerUserID string) error

func (*WeChatProvider) GetConfig

func (w *WeChatProvider) GetConfig() GenericOAuthConfig

func (*WeChatProvider) GetName

func (w *WeChatProvider) GetName() string

func (*WeChatProvider) GetProviderPrefix

func (w *WeChatProvider) GetProviderPrefix() string

func (*WeChatProvider) GetUserInfo

func (w *WeChatProvider) GetUserInfo(ctx context.Context, token *OAuthToken) (*OAuthUser, error)

func (*WeChatProvider) IsEnabled

func (w *WeChatProvider) IsEnabled() bool

func (*WeChatProvider) IsUserIDTaken

func (w *WeChatProvider) IsUserIDTaken(providerUserID string) bool

func (*WeChatProvider) SetProviderUserID

func (w *WeChatProvider) SetProviderUserID(user *model.User, providerUserID string)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL