Documentation
¶
Overview ¶
Package oauthclient provides OAuth client helpers for SystemForge applications. This package contains utilities for fetching user info from OAuth providers (Google, GitHub, SystemAuth) as part of the OAuth authorization code flow.
Index ¶
Constants ¶
const ( // StateCookieName is the default name for the OAuth state cookie. StateCookieName = "oauth_state" // StateCookieMaxAge is the default max age for the state cookie (5 minutes). StateCookieMaxAge = 5 * 60 )
Variables ¶
This section is empty.
Functions ¶
func GenerateState ¶
GenerateState generates a cryptographically secure random state string.
func GitHubConfig ¶
func GitHubConfig(cfg ProviderConfig) *oauth2.Config
GitHubConfig creates an OAuth2 config for GitHub.
func GoogleConfig ¶
func GoogleConfig(cfg ProviderConfig) *oauth2.Config
GoogleConfig creates an OAuth2 config for Google.
Types ¶
type ProviderConfig ¶
type ProviderConfig struct {
ClientID string
ClientSecret string
RedirectURL string
Scopes []string
}
ProviderConfig holds OAuth configuration for a provider.
func (ProviderConfig) Enabled ¶
func (c ProviderConfig) Enabled() bool
Enabled returns true if the provider is configured.
type StateManager ¶
type StateManager struct {
CookieName string
MaxAge int
Secure bool // Secure flag for cookies (default: true, requires HTTPS)
SameSite http.SameSite
}
StateManager handles OAuth state cookie management.
func NewStateManager ¶
func NewStateManager() *StateManager
NewStateManager creates a state manager with secure defaults. Cookies are set with Secure: true, requiring HTTPS. For local development over HTTP, use NewStateManagerInsecure().
func NewStateManagerInsecure ¶
func NewStateManagerInsecure() *StateManager
NewStateManagerInsecure creates a state manager for local development over HTTP. WARNING: Only use this for local development. Never use in production.
func (*StateManager) SetStateCookie ¶
func (m *StateManager) SetStateCookie(w http.ResponseWriter, state string)
SetStateCookie sets the OAuth state cookie.
func (*StateManager) ValidateState ¶
func (m *StateManager) ValidateState(w http.ResponseWriter, r *http.Request, state string) bool
ValidateState validates the OAuth state against the cookie and clears it. Returns true if valid, false otherwise.
type SystemAuthConfig ¶ added in v0.11.0
type SystemAuthConfig struct {
ProviderConfig
BaseURL string // SystemAuth server base URL
}
SystemAuthConfig holds SystemAuth OAuth configuration.
func (SystemAuthConfig) AuthorizationURL ¶ added in v0.11.0
func (c SystemAuthConfig) AuthorizationURL() string
AuthorizationURL returns the SystemAuth authorization endpoint.
func (SystemAuthConfig) OAuth2Config ¶ added in v0.11.0
func (c SystemAuthConfig) OAuth2Config() *oauth2.Config
OAuth2Config creates an OAuth2 config for SystemAuth.
func (SystemAuthConfig) TokenURL ¶ added in v0.11.0
func (c SystemAuthConfig) TokenURL() string
TokenURL returns the SystemAuth token endpoint.
func (SystemAuthConfig) UserInfoURL ¶ added in v0.11.0
func (c SystemAuthConfig) UserInfoURL() string
UserInfoURL returns the SystemAuth userinfo endpoint.
type User ¶
type User struct {
// ProviderID is the unique identifier from the OAuth provider.
ProviderID string `json:"provider_id"`
// Provider is the name of the OAuth provider (google, github, etc.).
Provider string `json:"provider"`
// Email is the user's email address.
Email string `json:"email"`
// Name is the user's display name.
Name string `json:"name"`
// AvatarURL is the URL to the user's profile picture.
AvatarURL string `json:"avatar_url,omitempty"`
// Username is the user's username (primarily for GitHub).
Username string `json:"username,omitempty"`
// AccessToken is the OAuth access token.
AccessToken string `json:"-"`
// RefreshToken is the OAuth refresh token (if provided).
RefreshToken string `json:"-"`
// TokenExpiry is when the access token expires.
TokenExpiry time.Time `json:"-"`
// Raw contains the raw user data from the provider.
Raw map[string]any `json:"raw,omitempty"`
}
User represents user information from an OAuth provider.
func FetchGitHubUser ¶
FetchGitHubUser fetches user info from GitHub using an authorization code.
func FetchGoogleUser ¶
FetchGoogleUser fetches user info from Google using an authorization code.
func FetchSystemAuthUser ¶ added in v0.11.0
func FetchSystemAuthUser(ctx context.Context, cfg SystemAuthConfig, accessToken string) (*User, error)
FetchSystemAuthUser fetches user info from SystemAuth using an access token.