Documentation
¶
Overview ¶
Package providers exchanges OAuth 2.0 authorization codes for a normalized user profile across providers (currently Google and GitHub), for use in "Sign in with ..." login flows.
Provider-specific packages such as google offer richer, provider-native APIs; this package trades that depth for one uniform OAuthUser type.
Index ¶
Constants ¶
const ( ProviderGitHub = "github" GitHubUserURL = "https://api.github.com/user" GitHubEmailsURL = "https://api.github.com/user/emails" )
const ( ProviderGoogle = "google" GoogleUserInfoURL = "https://www.googleapis.com/oauth2/v2/userinfo" )
const DefaultTimeout = 30 * time.Second
DefaultTimeout bounds requests made by the *WithToken functions, which use their own HTTP client. Code-exchange functions use the client derived from the oauth2.Config; bound those with a context deadline.
Variables ¶
var ErrNoVerifiedEmail = errors.New("no verified email found")
ErrNoVerifiedEmail is returned when a GitHub user has no verified email.
Functions ¶
func PrimaryVerifiedEmail ¶
func PrimaryVerifiedEmail(emails []GitHubEmail) (string, error)
PrimaryVerifiedEmail returns the primary verified email, falling back to any verified email, or ErrNoVerifiedEmail.
Types ¶
type GitHubEmail ¶
type GitHubEmail struct {
Email string `json:"email"`
Primary bool `json:"primary"`
Verified bool `json:"verified"`
}
GitHubEmail represents an email from GitHub's emails endpoint.
type GitHubUserInfo ¶
type GitHubUserInfo struct {
ID int64 `json:"id"`
Login string `json:"login"`
Name string `json:"name"`
Email string `json:"email"`
AvatarURL string `json:"avatar_url"`
}
GitHubUserInfo represents the response from GitHub's user endpoint.
func FetchGitHubUserWithToken ¶
func FetchGitHubUserWithToken(ctx context.Context, accessToken string) (*GitHubUserInfo, error)
FetchGitHubUserWithToken fetches user info using an existing access token.
type GoogleUserInfo ¶
type GoogleUserInfo struct {
ID string `json:"id"`
Email string `json:"email"`
VerifiedEmail bool `json:"verified_email"`
Name string `json:"name"`
GivenName string `json:"given_name"`
FamilyName string `json:"family_name"`
Picture string `json:"picture"`
}
GoogleUserInfo represents the response from Google's userinfo endpoint.
func FetchGoogleUserWithToken ¶
func FetchGoogleUserWithToken(ctx context.Context, accessToken string) (*GoogleUserInfo, error)
FetchGoogleUserWithToken fetches user info using an existing access token.
type OAuthUser ¶
type OAuthUser struct {
ProviderID string // User ID from the provider
Email string
Name string
AvatarURL string
Provider string // "google" or "github"
AccessToken string // Provider access token (for API calls)
RefreshToken string // Provider refresh token (if available)
}
OAuthUser is a user profile normalized across OAuth providers.
func FetchGitHubUser ¶
FetchGitHubUser exchanges the authorization code and fetches user info from GitHub. When the profile email is private, the primary verified email is fetched from the emails endpoint, which requires the "user:email" scope.