Documentation
¶
Overview ¶
Package oauth signs somebody in with an account they already have.
It holds UserData -- what a provider says about the person who just signed in -- and the providers subpackage, which is the flow that gets it: Google, GitHub, Facebook and Twitter today.
What it is not ¶
It is not an OAuth 2 authorization SERVER. This package is the client half: it sends somebody to a provider and reads back who they are. Issuing tokens for other applications to consume is a separate thing and is not here.
It is also not golang.org/x/oauth2. That library is the token exchange and nothing above it. What this adds is the part every application writes by hand otherwise: the state parameter and its verification, the redirect, the provider endpoints, and one shape for the user across providers that each describe a person differently.
The state parameter is not optional ¶
A provider calls back with a code, and without a state parameter that the application issued and verified, anybody can trigger that callback with a code of their own -- which signs the victim into the attacker's account, or the reverse. See github.com/arandu-io/hesape/oauth/providers.Verify.
A provider built without a state store refuses to redirect rather than redirecting insecurely. Stateless exists for the case where the caller genuinely has nowhere to keep it, and it is a decision made in the open at the call site rather than a default.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type UserData ¶
type UserData struct {
// contains filtered or unexported fields
}
UserData is whatever the provider said about the person who just signed in.
It is a map with methods. UserData.All is the whole of it, for a caller that wants to range over the fields rather than ask for them by name.
The contents are the provider's, not this package's. GitHub calls the handle "login" and Google calls it "name"; neither is normalised here, because a mapping that guessed would be wrong for the fifth provider somebody adds. Ask for what the provider documents:
user, err := provider.User(r)
id := user.String("id")
func NewUserData ¶
NewUserData wraps the provider's parameters.
The map is kept, not copied: it comes straight off a decoded JSON body that nothing else holds.
func (UserData) Keys ¶
Keys is the parameter names, sorted, so that a log line or a test listing them reads the same twice.