oauthclient

package
v0.11.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: MIT Imports: 11 Imported by: 0

Documentation

Overview

Package oauthclient provides OAuth client helpers for SystemForge applications. This package contains utilities for fetching user info from OAuth providers (Google, GitHub, SystemAuth) as part of the OAuth authorization code flow.

Index

Constants

View Source
const (
	// StateCookieName is the default name for the OAuth state cookie.
	StateCookieName = "oauth_state"
	// StateCookieMaxAge is the default max age for the state cookie (5 minutes).
	StateCookieMaxAge = 5 * 60
)

Variables

This section is empty.

Functions

func GenerateState

func GenerateState() (string, error)

GenerateState generates a cryptographically secure random state string.

func GitHubConfig

func GitHubConfig(cfg ProviderConfig) *oauth2.Config

GitHubConfig creates an OAuth2 config for GitHub.

func GoogleConfig

func GoogleConfig(cfg ProviderConfig) *oauth2.Config

GoogleConfig creates an OAuth2 config for Google.

Types

type ProviderConfig

type ProviderConfig struct {
	ClientID     string
	ClientSecret string
	RedirectURL  string
	Scopes       []string
}

ProviderConfig holds OAuth configuration for a provider.

func (ProviderConfig) Enabled

func (c ProviderConfig) Enabled() bool

Enabled returns true if the provider is configured.

type StateManager

type StateManager struct {
	CookieName string
	MaxAge     int
	Secure     bool // Secure flag for cookies (default: true, requires HTTPS)
	SameSite   http.SameSite
}

StateManager handles OAuth state cookie management.

func NewStateManager

func NewStateManager() *StateManager

NewStateManager creates a state manager with secure defaults. Cookies are set with Secure: true, requiring HTTPS. For local development over HTTP, use NewStateManagerInsecure().

func NewStateManagerInsecure

func NewStateManagerInsecure() *StateManager

NewStateManagerInsecure creates a state manager for local development over HTTP. WARNING: Only use this for local development. Never use in production.

func (*StateManager) SetStateCookie

func (m *StateManager) SetStateCookie(w http.ResponseWriter, state string)

SetStateCookie sets the OAuth state cookie.

func (*StateManager) ValidateState

func (m *StateManager) ValidateState(w http.ResponseWriter, r *http.Request, state string) bool

ValidateState validates the OAuth state against the cookie and clears it. Returns true if valid, false otherwise.

type SystemAuthConfig added in v0.11.0

type SystemAuthConfig struct {
	ProviderConfig
	BaseURL string // SystemAuth server base URL
}

SystemAuthConfig holds SystemAuth OAuth configuration.

func (SystemAuthConfig) AuthorizationURL added in v0.11.0

func (c SystemAuthConfig) AuthorizationURL() string

AuthorizationURL returns the SystemAuth authorization endpoint.

func (SystemAuthConfig) OAuth2Config added in v0.11.0

func (c SystemAuthConfig) OAuth2Config() *oauth2.Config

OAuth2Config creates an OAuth2 config for SystemAuth.

func (SystemAuthConfig) TokenURL added in v0.11.0

func (c SystemAuthConfig) TokenURL() string

TokenURL returns the SystemAuth token endpoint.

func (SystemAuthConfig) UserInfoURL added in v0.11.0

func (c SystemAuthConfig) UserInfoURL() string

UserInfoURL returns the SystemAuth userinfo endpoint.

type User

type User struct {
	// ProviderID is the unique identifier from the OAuth provider.
	ProviderID string `json:"provider_id"`

	// Provider is the name of the OAuth provider (google, github, etc.).
	Provider string `json:"provider"`

	// Email is the user's email address.
	Email string `json:"email"`

	// Name is the user's display name.
	Name string `json:"name"`

	// AvatarURL is the URL to the user's profile picture.
	AvatarURL string `json:"avatar_url,omitempty"`

	// Username is the user's username (primarily for GitHub).
	Username string `json:"username,omitempty"`

	// AccessToken is the OAuth access token.
	AccessToken string `json:"-"`

	// RefreshToken is the OAuth refresh token (if provided).
	RefreshToken string `json:"-"`

	// TokenExpiry is when the access token expires.
	TokenExpiry time.Time `json:"-"`

	// Raw contains the raw user data from the provider.
	Raw map[string]any `json:"raw,omitempty"`
}

User represents user information from an OAuth provider.

func FetchGitHubUser

func FetchGitHubUser(ctx context.Context, cfg *oauth2.Config, code string) (*User, error)

FetchGitHubUser fetches user info from GitHub using an authorization code.

func FetchGoogleUser

func FetchGoogleUser(ctx context.Context, cfg *oauth2.Config, code string) (*User, error)

FetchGoogleUser fetches user info from Google using an authorization code.

func FetchSystemAuthUser added in v0.11.0

func FetchSystemAuthUser(ctx context.Context, cfg SystemAuthConfig, accessToken string) (*User, error)

FetchSystemAuthUser fetches user info from SystemAuth using an access token.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL