Documentation
¶
Overview ¶
Package authhttp serves the four site-user auth endpoints and ties together the provider registry (internal/auth), the Redis session store (internal/session), and the durable users table (internal/store):
GET /auth/login?provider=… begin OAuth/OIDC (redirect to the provider)
GET /auth/callback complete login: verify state, Exchange, upsert
user, issue session, set cookie
GET /api/v1/auth/session the current user, or 401
POST /api/v1/auth/logout revoke the session and clear the cookie
The first two are public (state is the CSRF guard); the last two sit behind the session middleware in the /api/v1 group.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Handler ¶
type Handler struct {
// contains filtered or unexported fields
}
Handler serves the auth endpoints.
func New ¶
func New(reg *auth.Registry, sessions sessionStore, users userUpserter, stateSecret []byte) *Handler
New builds a Handler. stateSecret (the session secret) signs the OAuth state.
func (*Handler) MountAPI ¶
MountAPI registers /auth/session and /auth/logout on r, which the caller has already placed inside the session-gated /api/v1 group.
func (*Handler) MountPublic ¶
MountPublic registers /auth/login and /auth/callback on the root router: they run without the session gate (login has no session yet; callback is authenticated by its signed state).