Directories
¶
| Path | Synopsis |
|---|---|
|
accesstokens
Package accesstokens is the public API for access-token persistence.
|
Package accesstokens is the public API for access-token persistence. |
|
authcodes
Package authcodes is the public API for authorization-code persistence.
|
Package authcodes is the public API for authorization-code persistence. |
|
clients
Package clients serves the OAuth client management API (gRPC, internal HTTP, and the public unauthenticated dynamic client registration endpoint).
|
Package clients serves the OAuth client management API (gRPC, internal HTTP, and the public unauthenticated dynamic client registration endpoint). |
|
consent
Package consent persists consent challenges and verifiers as the consent stage of the oauth_flows table.
|
Package consent persists consent challenges and verifiers as the consent stage of the oauth_flows table. |
|
discovery
Package discovery serves the OIDC/OAuth provider-metadata documents at /.well-known/openid-configuration and /.well-known/oauth-authorization-server.
|
Package discovery serves the OIDC/OAuth provider-metadata documents at /.well-known/openid-configuration and /.well-known/oauth-authorization-server. |
|
internal/csrf
Package csrf provides the CSRF cookie and token helpers shared by the OAuth login and consent flows.
|
Package csrf provides the CSRF cookie and token helpers shared by the OAuth login and consent flows. |
|
login
Package login creates the oauth_flows row from the authorize request, and persists login challenges and verifiers as the login stage of that row.
|
Package login creates the oauth_flows row from the authorize request, and persists login challenges and verifiers as the login stage of that row. |
|
oidc
Package oidc is the public API for OpenID Connect session persistence.
|
Package oidc is the public API for OpenID Connect session persistence. |
|
pkce
Package pkce is the public API for PKCE-request persistence.
|
Package pkce is the public API for PKCE-request persistence. |
|
refreshtokens
Package refreshtokens is the public API for refresh-token persistence.
|
Package refreshtokens is the public API for refresh-token persistence. |
|
revocation
Package revocation implements the OAuth 2.0 token revocation endpoint per RFC 7009.
|
Package revocation implements the OAuth 2.0 token revocation endpoint per RFC 7009. |
|
revokedtokens
Package revokedtokens is the public API for the revoked-token denylist.
|
Package revokedtokens is the public API for the revoked-token denylist. |
|
tokens
Package tokens serves the internal InternalOAuthTokensService gRPC API, through which gitlab-rails revokes the tokens IAM holds for a (user, client) pair on OAuth app de-authorization.
|
Package tokens serves the internal InternalOAuthTokensService gRPC API, through which gitlab-rails revokes the tokens IAM holds for a (user, client) pair on OAuth app de-authorization. |
|
userinfo
Package userinfo calls GitLab Rails' `/api/v4/iam/userinfo` endpoint, authenticated with the access token minted for the same token exchange as a bearer credential.
|
Package userinfo calls GitLab Rails' `/api/v4/iam/userinfo` endpoint, authenticated with the access token minted for the same token exchange as a bearer credential. |
Click to show internal directories.
Click to hide internal directories.