oauth

package
v0.44.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: MIT Imports: 2 Imported by: 0

Documentation

Overview

Package oauth signs somebody in with an account they already have.

It holds UserData -- what a provider says about the person who just signed in -- and the providers subpackage, which is the flow that gets it: Google, GitHub, Facebook and Twitter today.

What it is not

It is not an OAuth 2 authorization SERVER. This package is the client half: it sends somebody to a provider and reads back who they are. Issuing tokens for other applications to consume is a separate thing and is not here.

It is also not golang.org/x/oauth2. That library is the token exchange and nothing above it. What this adds is the part every application writes by hand otherwise: the state parameter and its verification, the redirect, the provider endpoints, and one shape for the user across providers that each describe a person differently.

The state parameter is not optional

A provider calls back with a code, and without a state parameter that the application issued and verified, anybody can trigger that callback with a code of their own -- which signs the victim into the attacker's account, or the reverse. See github.com/arandu-io/hesape/oauth/providers.Verify.

A provider built without a state store refuses to redirect rather than redirecting insecurely. Stateless exists for the case where the caller genuinely has nowhere to keep it, and it is a decision made in the open at the call site rather than a default.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type UserData

type UserData struct {
	// contains filtered or unexported fields
}

UserData is whatever the provider said about the person who just signed in.

It is a map with methods. UserData.All is the whole of it, for a caller that wants to range over the fields rather than ask for them by name.

The contents are the provider's, not this package's. GitHub calls the handle "login" and Google calls it "name"; neither is normalised here, because a mapping that guessed would be wrong for the fifth provider somebody adds. Ask for what the provider documents:

user, err := provider.User(r)
id := user.String("id")

func NewUserData

func NewUserData(params map[string]any) UserData

NewUserData wraps the provider's parameters.

The map is kept, not copied: it comes straight off a decoded JSON body that nothing else holds.

func (UserData) All

func (u UserData) All() map[string]any

All is every parameter the provider sent.

func (UserData) Get

func (u UserData) Get(key string, fallback ...any) any

Get is the value, or the fallback when the provider did not send that key.

func (UserData) Has

func (u UserData) Has(key string) bool

Has reports whether the provider sent this key.

func (UserData) Keys

func (u UserData) Keys() []string

Keys is the parameter names, sorted, so that a log line or a test listing them reads the same twice.

func (UserData) String

func (u UserData) String(key string, fallback ...string) string

String is Get for the common case, where the answer goes into a column.

A JSON number arrives as a float64, and an id printed with %v would come out as 1.234568e+06, so the conversion happens once, in the place that knows it is a conversion.

Directories

Path Synopsis
Package providers is the OAuth 2 authorization code flow, out to the provider and back, with one type per provider on top of it.
Package providers is the OAuth 2 authorization code flow, out to the provider and back, with one type per provider on top of it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL