discovery

package
v1.62.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: MIT Imports: 4 Imported by: 0

Documentation

Overview

Package discovery serves the OIDC/OAuth provider-metadata documents at /.well-known/openid-configuration and /.well-known/oauth-authorization-server.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Handler

type Handler struct {
	// contains filtered or unexported fields
}

Handler serves the provider-metadata document. Both well-known paths route to the same handler function, which branches internally (see oauthAuthorizationServerPath) on the one field that differs between them. The two possible documents are fixed for the handler's lifetime, so NewHandler builds both once rather than on every request.

func NewHandler

func NewHandler(issuer string, pkcePlainEnabled bool, cacheDuration time.Duration) *Handler

NewHandler builds a Handler. pkcePlainEnabled should be fosite.Configurator.GetEnablePKCEPlainChallengeMethod(ctx) read off the same *fosite.Config the OAuth provider was built with, so this document can't advertise a PKCE method the provider doesn't actually accept. cacheDuration mirrors jwk.Handler's own (same kind of static, public document); a non-positive value defaults to an hour, matching jwk.NewHandler.

func (*Handler) SetupRoutes

func (h *Handler) SetupRoutes(mux *http.ServeMux)

type Metadata

type Metadata struct {
	Issuer                            string   `json:"issuer"`
	AuthorizationEndpoint             string   `json:"authorization_endpoint"`
	TokenEndpoint                     string   `json:"token_endpoint"`
	RevocationEndpoint                string   `json:"revocation_endpoint"`
	IntrospectionEndpoint             string   `json:"introspection_endpoint"`
	UserinfoEndpoint                  string   `json:"userinfo_endpoint"`
	JwksURI                           string   `json:"jwks_uri"`
	RegistrationEndpoint              string   `json:"registration_endpoint,omitempty"`
	ScopesSupported                   []string `json:"scopes_supported,omitempty"`
	ResponseTypesSupported            []string `json:"response_types_supported"`
	ResponseModesSupported            []string `json:"response_modes_supported,omitempty"`
	GrantTypesSupported               []string `json:"grant_types_supported,omitempty"`
	TokenEndpointAuthMethodsSupported []string `json:"token_endpoint_auth_methods_supported,omitempty"`
	SubjectTypesSupported             []string `json:"subject_types_supported"`
	IDTokenSigningAlgValuesSupported  []string `json:"id_token_signing_alg_values_supported"`
	ClaimTypesSupported               []string `json:"claim_types_supported,omitempty"`
	ClaimsSupported                   []string `json:"claims_supported,omitempty"`
	CodeChallengeMethodsSupported     []string `json:"code_challenge_methods_supported,omitempty"`
}

Metadata is the OIDC Discovery 1.0 / RFC 8414 provider-metadata document — see .ai/components.md for the Doorkeeper-parity design principle behind which fields are hardcoded and why. omitempty is used throughout except the handful of fields the specs never allow to be empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL