Documentation
¶
Overview ¶
Package testidp is a fake identity provider for tests of AuthKit's provider sign-in, link and recovery flows: an OpenID Provider (discovery, JWKS, ID tokens) and a plain OAuth2 server (token, userinfo) on one TLS server.
The IdP keeps no state. A test reads the authorization request a flow start produced (Authorize), signs in there as an Identity (Code), and replays the IdP's redirect to AuthKit's callback. The code carries the identity and what the request bound it to: the nonce the ID token echoes, the redirect URI and the S256 challenge the token endpoint checks.
Index ¶
- Constants
- type Authorization
- type IdP
- func (p *IdP) Authorize(t testing.TB, authURL string) Authorization
- func (p *IdP) Code(id Identity, a Authorization) string
- func (p *IdP) OAuth2(name string, opts ...provider.Option) provider.Provider
- func (p *IdP) OIDC(name string, opts ...provider.Option) provider.Provider
- func (p *IdP) Redirect(t testing.TB, authURL string, id Identity) url.Values
- func (p *IdP) SetOutage(o Outage)
- type Identity
- type Outage
Constants ¶
const ClientSecret = "testidp-secret"
ClientSecret is the client secret every IdP accepts.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Authorization ¶
Authorization is what the IdP's authorization endpoint received: the state it hands back, and the nonce, redirect URI and S256 code challenge a code is bound to.
type IdP ¶
IdP is a running identity provider, closed at the test's cleanup.
func (*IdP) Authorize ¶
func (p *IdP) Authorize(t testing.TB, authURL string) Authorization
Authorize reads the authorization request a flow start sent the browser to; the test fails when authURL is not one for this IdP.
func (*IdP) Code ¶
func (p *IdP) Code(id Identity, a Authorization) string
Code is the authorization code for id signing in after a. The token endpoint redeems it for an ID token naming id with a's nonce, only for a's redirect URI and, when a carries a code challenge, only with its verifier.
func (*IdP) OAuth2 ¶
OAuth2 is a plain OAuth2 provider named name for this IdP, reading the identity from its userinfo endpoint, trusted to verify email. opts come after the defaults.
func (*IdP) OIDC ¶
OIDC is an OpenID Connect provider named name for this IdP, trusted to verify email. opts come after the defaults.
type Identity ¶
type Identity struct {
Subject string `json:"sub"`
Email string `json:"email,omitempty"`
// EmailVerified asserts Email; false omits the claim.
EmailVerified bool `json:"email_verified,omitempty"`
Username string `json:"preferred_username,omitempty"`
Name string `json:"name,omitempty"`
}
Identity is who signs in at the IdP.