Documentation
¶
Overview ¶
Package discovery serves the OIDC/OAuth provider-metadata documents at /.well-known/openid-configuration and /.well-known/oauth-authorization-server.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Handler ¶
type Handler struct {
// contains filtered or unexported fields
}
Handler serves the provider-metadata document. Both well-known paths route to the same handler function, which branches internally (see oauthAuthorizationServerPath) on the one field that differs between them. The two possible documents are fixed for the handler's lifetime, so NewHandler builds both once rather than on every request.
func NewHandler ¶
NewHandler builds a Handler. pkcePlainEnabled should be fosite.Configurator.GetEnablePKCEPlainChallengeMethod(ctx) read off the same *fosite.Config the OAuth provider was built with, so this document can't advertise a PKCE method the provider doesn't actually accept. cacheDuration mirrors jwk.Handler's own (same kind of static, public document); a non-positive value defaults to an hour, matching jwk.NewHandler.
func (*Handler) SetupRoutes ¶
type Metadata ¶
type Metadata struct {
Issuer string `json:"issuer"`
AuthorizationEndpoint string `json:"authorization_endpoint"`
TokenEndpoint string `json:"token_endpoint"`
RevocationEndpoint string `json:"revocation_endpoint"`
IntrospectionEndpoint string `json:"introspection_endpoint"`
UserinfoEndpoint string `json:"userinfo_endpoint"`
JwksURI string `json:"jwks_uri"`
RegistrationEndpoint string `json:"registration_endpoint,omitempty"`
ScopesSupported []string `json:"scopes_supported,omitempty"`
ResponseTypesSupported []string `json:"response_types_supported"`
ResponseModesSupported []string `json:"response_modes_supported,omitempty"`
GrantTypesSupported []string `json:"grant_types_supported,omitempty"`
TokenEndpointAuthMethodsSupported []string `json:"token_endpoint_auth_methods_supported,omitempty"`
SubjectTypesSupported []string `json:"subject_types_supported"`
IDTokenSigningAlgValuesSupported []string `json:"id_token_signing_alg_values_supported"`
ClaimTypesSupported []string `json:"claim_types_supported,omitempty"`
ClaimsSupported []string `json:"claims_supported,omitempty"`
CodeChallengeMethodsSupported []string `json:"code_challenge_methods_supported,omitempty"`
}
Metadata is the OIDC Discovery 1.0 / RFC 8414 provider-metadata document — see .ai/components.md for the Doorkeeper-parity design principle behind which fields are hardcoded and why. omitempty is used throughout except the handful of fields the specs never allow to be empty.