testidp

package
v0.148.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: MIT Imports: 16 Imported by: 0

Documentation

Overview

Package testidp is a fake identity provider for tests of AuthKit's provider sign-in, link and recovery flows: an OpenID Provider (discovery, JWKS, ID tokens) and a plain OAuth2 server (token, userinfo) on one TLS server.

The IdP keeps no state. A test reads the authorization request a flow start produced (Authorize), signs in there as an Identity (Code), and replays the IdP's redirect to AuthKit's callback. The code carries the identity and what the request bound it to: the nonce the ID token echoes, the redirect URI and the S256 challenge the token endpoint checks.

Index

Constants

View Source
const ClientSecret = "testidp-secret"

ClientSecret is the client secret every IdP accepts.

Variables

This section is empty.

Functions

This section is empty.

Types

type Authorization

type Authorization struct {
	State         string
	Nonce         string
	RedirectURI   string
	CodeChallenge string
}

Authorization is what the IdP's authorization endpoint received: the state it hands back, and the nonce, redirect URI and S256 code challenge a code is bound to.

type IdP

type IdP struct {
	Issuer   string
	ClientID string
	// contains filtered or unexported fields
}

IdP is a running identity provider, closed at the test's cleanup.

func New

func New(t testing.TB) *IdP

New starts an IdP with its own signing key.

func (*IdP) Authorize

func (p *IdP) Authorize(t testing.TB, authURL string) Authorization

Authorize reads the authorization request a flow start sent the browser to; the test fails when authURL is not one for this IdP.

func (*IdP) Code

func (p *IdP) Code(id Identity, a Authorization) string

Code is the authorization code for id signing in after a. The token endpoint redeems it for an ID token naming id with a's nonce, only for a's redirect URI and, when a carries a code challenge, only with its verifier.

func (*IdP) OAuth2

func (p *IdP) OAuth2(name string, opts ...provider.Option) provider.Provider

OAuth2 is a plain OAuth2 provider named name for this IdP, reading the identity from its userinfo endpoint, trusted to verify email. opts come after the defaults.

func (*IdP) OIDC

func (p *IdP) OIDC(name string, opts ...provider.Option) provider.Provider

OIDC is an OpenID Connect provider named name for this IdP, trusted to verify email. opts come after the defaults.

func (*IdP) Redirect

func (p *IdP) Redirect(t testing.TB, authURL string, id Identity) url.Values

Redirect is the query of the IdP's redirect back to the callback once id signs in at authURL: its state and code.

func (*IdP) SetOutage

func (p *IdP) SetOutage(o Outage)

SetOutage makes every endpoint fail as o says, until the next call.

type Identity

type Identity struct {
	Subject string `json:"sub"`
	Email   string `json:"email,omitempty"`
	// EmailVerified asserts Email; false omits the claim.
	EmailVerified bool   `json:"email_verified,omitempty"`
	Username      string `json:"preferred_username,omitempty"`
	Name          string `json:"name,omitempty"`
}

Identity is who signs in at the IdP.

type Outage

type Outage int32

Outage is how the IdP answers every request.

const (
	Up          Outage = iota // serves normally
	Unavailable               // answers 503
	Reset                     // drops the connection
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL