authhttp

package
v0.10.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 20, 2026 License: Apache-2.0 Imports: 8 Imported by: 0

Documentation

Overview

Package authhttp serves the four site-user auth endpoints and ties together the provider registry (internal/auth), the Redis session store (internal/session), and the durable users table (internal/store):

GET  /auth/login?provider=…   begin OAuth/OIDC (redirect to the provider)
GET  /auth/callback           complete login: verify state, Exchange, upsert
                              user, issue session, set cookie
GET  /api/v1/auth/session     the current user, or 401
POST /api/v1/auth/logout      revoke the session and clear the cookie

The first two are public (state is the CSRF guard); the last two sit behind the session middleware in the /api/v1 group.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Handler

type Handler struct {
	// contains filtered or unexported fields
}

Handler serves the auth endpoints.

func New

func New(reg *auth.Registry, sessions sessionStore, users userUpserter, stateSecret []byte) *Handler

New builds a Handler. stateSecret (the session secret) signs the OAuth state.

func (*Handler) MountAPI

func (h *Handler) MountAPI(r chi.Router)

MountAPI registers /auth/session and /auth/logout on r, which the caller has already placed inside the session-gated /api/v1 group.

func (*Handler) MountPublic

func (h *Handler) MountPublic(r chi.Router)

MountPublic registers /auth/login and /auth/callback on the root router: they run without the session gate (login has no session yet; callback is authenticated by its signed state).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL