auth

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 16, 2026 License: MIT Imports: 13 Imported by: 0

Documentation

Overview

Package auth provides primitives to interact with the openapi HTTP API.

Code generated by github.com/oapi-codegen/oapi-codegen/v2 version v2.8.0 DO NOT EDIT.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func NewApproveAuthorizationRequestWithBody

func NewApproveAuthorizationRequestWithBody(server string, contentType string, body io.Reader) (*http.Request, error)

NewApproveAuthorizationRequestWithBody constructs an http.Request for the ApproveAuthorization method, with any body, and a specified content type

func NewApproveAuthorizationRequestWithFormdataBody

func NewApproveAuthorizationRequestWithFormdataBody(server string, body ApproveAuthorizationFormdataRequestBody) (*http.Request, error)

NewApproveAuthorizationRequestWithFormdataBody calls the generic ApproveAuthorization builder with application/x-www-form-urlencoded body

func NewAuthorizeRequest

func NewAuthorizeRequest(server string, params *AuthorizeParams) (*http.Request, error)

NewAuthorizeRequest constructs an http.Request for the Authorize method

func NewDenyAuthorizationRequestWithBody

func NewDenyAuthorizationRequestWithBody(server string, contentType string, body io.Reader) (*http.Request, error)

NewDenyAuthorizationRequestWithBody constructs an http.Request for the DenyAuthorization method, with any body, and a specified content type

func NewDenyAuthorizationRequestWithFormdataBody

func NewDenyAuthorizationRequestWithFormdataBody(server string, body DenyAuthorizationFormdataRequestBody) (*http.Request, error)

NewDenyAuthorizationRequestWithFormdataBody calls the generic DenyAuthorization builder with application/x-www-form-urlencoded body

func NewGetAuthorizationServerMetadataForPathRequest

func NewGetAuthorizationServerMetadataForPathRequest(server string, path string) (*http.Request, error)

NewGetAuthorizationServerMetadataForPathRequest constructs an http.Request for the GetAuthorizationServerMetadataForPath method

func NewGetAuthorizationServerMetadataRequest

func NewGetAuthorizationServerMetadataRequest(server string) (*http.Request, error)

NewGetAuthorizationServerMetadataRequest constructs an http.Request for the GetAuthorizationServerMetadata method

func NewGetJSONWebKeySetRequest

func NewGetJSONWebKeySetRequest(server string) (*http.Request, error)

NewGetJSONWebKeySetRequest constructs an http.Request for the GetJSONWebKeySet method

func NewGetProtectedResourceMetadataForPathRequest

func NewGetProtectedResourceMetadataForPathRequest(server string, path string) (*http.Request, error)

NewGetProtectedResourceMetadataForPathRequest constructs an http.Request for the GetProtectedResourceMetadataForPath method

func NewGetProtectedResourceMetadataRequest

func NewGetProtectedResourceMetadataRequest(server string) (*http.Request, error)

NewGetProtectedResourceMetadataRequest constructs an http.Request for the GetProtectedResourceMetadata method

func NewGetProviderMetadataRequest

func NewGetProviderMetadataRequest(server string) (*http.Request, error)

NewGetProviderMetadataRequest constructs an http.Request for the GetProviderMetadata method

func NewGetUserInfoRequest

func NewGetUserInfoRequest(server string) (*http.Request, error)

NewGetUserInfoRequest constructs an http.Request for the GetUserInfo method

func NewIntrospectTokenRequestWithBody

func NewIntrospectTokenRequestWithBody(server string, contentType string, body io.Reader) (*http.Request, error)

NewIntrospectTokenRequestWithBody constructs an http.Request for the IntrospectToken method, with any body, and a specified content type

func NewIntrospectTokenRequestWithFormdataBody

func NewIntrospectTokenRequestWithFormdataBody(server string, body IntrospectTokenFormdataRequestBody) (*http.Request, error)

NewIntrospectTokenRequestWithFormdataBody calls the generic IntrospectToken builder with application/x-www-form-urlencoded body

func NewIssueTokenRequestWithBody

func NewIssueTokenRequestWithBody(server string, contentType string, body io.Reader) (*http.Request, error)

NewIssueTokenRequestWithBody constructs an http.Request for the IssueToken method, with any body, and a specified content type

func NewIssueTokenRequestWithFormdataBody

func NewIssueTokenRequestWithFormdataBody(server string, body IssueTokenFormdataRequestBody) (*http.Request, error)

NewIssueTokenRequestWithFormdataBody calls the generic IssueToken builder with application/x-www-form-urlencoded body

func NewLogoutRequest

func NewLogoutRequest(server string, params *LogoutParams) (*http.Request, error)

NewLogoutRequest constructs an http.Request for the Logout method

func NewPostUserInfoRequest

func NewPostUserInfoRequest(server string) (*http.Request, error)

NewPostUserInfoRequest constructs an http.Request for the PostUserInfo method

func NewRegisterClientRequest

func NewRegisterClientRequest(server string, body RegisterClientJSONRequestBody) (*http.Request, error)

NewRegisterClientRequest calls the generic RegisterClient builder with application/json body

func NewRegisterClientRequestWithBody

func NewRegisterClientRequestWithBody(server string, contentType string, body io.Reader) (*http.Request, error)

NewRegisterClientRequestWithBody constructs an http.Request for the RegisterClient method, with any body, and a specified content type

func NewRevokeTokenRequestWithBody

func NewRevokeTokenRequestWithBody(server string, contentType string, body io.Reader) (*http.Request, error)

NewRevokeTokenRequestWithBody constructs an http.Request for the RevokeToken method, with any body, and a specified content type

func NewRevokeTokenRequestWithFormdataBody

func NewRevokeTokenRequestWithFormdataBody(server string, body RevokeTokenFormdataRequestBody) (*http.Request, error)

NewRevokeTokenRequestWithFormdataBody calls the generic RevokeToken builder with application/x-www-form-urlencoded body

func NewSubmitAuthorizationRequestWithBody

func NewSubmitAuthorizationRequestWithBody(server string, contentType string, body io.Reader) (*http.Request, error)

NewSubmitAuthorizationRequestWithBody constructs an http.Request for the SubmitAuthorization method, with any body, and a specified content type

func NewSubmitAuthorizationRequestWithFormdataBody

func NewSubmitAuthorizationRequestWithFormdataBody(server string, body SubmitAuthorizationFormdataRequestBody) (*http.Request, error)

NewSubmitAuthorizationRequestWithFormdataBody calls the generic SubmitAuthorization builder with application/x-www-form-urlencoded body

func NewSubmitLogoutRequestWithBody

func NewSubmitLogoutRequestWithBody(server string, contentType string, body io.Reader) (*http.Request, error)

NewSubmitLogoutRequestWithBody constructs an http.Request for the SubmitLogout method, with any body, and a specified content type

func NewSubmitLogoutRequestWithFormdataBody

func NewSubmitLogoutRequestWithFormdataBody(server string, body SubmitLogoutFormdataRequestBody) (*http.Request, error)

NewSubmitLogoutRequestWithFormdataBody calls the generic SubmitLogout builder with application/x-www-form-urlencoded body

Types

type APIError

type APIError = lock.APIError

type ApproveAuthorizationFormdataRequestBody

type ApproveAuthorizationFormdataRequestBody = OAuthConsentRequest

ApproveAuthorizationFormdataRequestBody defines body for ApproveAuthorization for application/x-www-form-urlencoded ContentType.

type AuthorizationCodeRequest

type AuthorizationCodeRequest struct {
	// ClientID Required for form-secret and public-client authentication. Omit when using HTTP Basic.
	ClientID *string `json:"client_id,omitempty"`

	// ClientSecret Required only for client_secret_post. Never combine with HTTP Basic.
	ClientSecret *string                           `json:"client_secret,omitempty"`
	Code         string                            `json:"code"`
	CodeVerifier string                            `json:"code_verifier"`
	GrantType    AuthorizationCodeRequestGrantType `json:"grant_type"`

	// RedirectURI Required if supplied in the authorization request; must match it exactly.
	RedirectURI *string `json:"redirect_uri,omitempty"`

	// Resource Absolute protected-resource URI without a fragment, or an array of such URIs using resource[] fields. Authorization and client-credentials requests default to the realm audience. Code and refresh grants preserve the original audiences when omitted, or narrow them when supplied.
	Resource *AuthorizationCodeRequest_Resource `json:"resource,omitempty"`

	// Scope Space-delimited scopes for client credentials, refresh or exchange. Refresh and exchange can only narrow granted scopes; authorization-code redemption uses the approved scopes.
	Scope *string `json:"scope,omitempty"`
}

AuthorizationCodeRequest defines model for AuthorizationCodeRequest.

type AuthorizationCodeRequestGrantType

type AuthorizationCodeRequestGrantType string

AuthorizationCodeRequestGrantType defines model for AuthorizationCodeRequest.GrantType.

const (
	AuthorizationCodeRequestGrantTypeAuthorizationCode AuthorizationCodeRequestGrantType = "authorization_code"
)

Defines values for AuthorizationCodeRequestGrantType.

func (AuthorizationCodeRequestGrantType) Valid

Valid indicates whether the value is a known member of the AuthorizationCodeRequestGrantType enum.

type AuthorizationCodeRequestResource0

type AuthorizationCodeRequestResource0 = string

AuthorizationCodeRequestResource0 defines model for AuthorizationCodeRequest.Resource.0.

type AuthorizationCodeRequestResource1

type AuthorizationCodeRequestResource1 = []string

AuthorizationCodeRequestResource1 defines model for AuthorizationCodeRequest.Resource.1.

type AuthorizationCodeRequest_Resource

type AuthorizationCodeRequest_Resource struct {
	// contains filtered or unexported fields
}

AuthorizationCodeRequest_Resource Absolute protected-resource URI without a fragment, or an array of such URIs using resource[] fields. Authorization and client-credentials requests default to the realm audience. Code and refresh grants preserve the original audiences when omitted, or narrow them when supplied.

func (AuthorizationCodeRequest_Resource) AsAuthorizationCodeRequestResource0

func (t AuthorizationCodeRequest_Resource) AsAuthorizationCodeRequestResource0() (AuthorizationCodeRequestResource0, error)

AsAuthorizationCodeRequestResource0 returns the union data inside the AuthorizationCodeRequest_Resource as a AuthorizationCodeRequestResource0

func (AuthorizationCodeRequest_Resource) AsAuthorizationCodeRequestResource1

func (t AuthorizationCodeRequest_Resource) AsAuthorizationCodeRequestResource1() (AuthorizationCodeRequestResource1, error)

AsAuthorizationCodeRequestResource1 returns the union data inside the AuthorizationCodeRequest_Resource as a AuthorizationCodeRequestResource1

func (*AuthorizationCodeRequest_Resource) FromAuthorizationCodeRequestResource0

func (t *AuthorizationCodeRequest_Resource) FromAuthorizationCodeRequestResource0(v AuthorizationCodeRequestResource0) error

FromAuthorizationCodeRequestResource0 overwrites any union data inside the AuthorizationCodeRequest_Resource as the provided AuthorizationCodeRequestResource0

func (*AuthorizationCodeRequest_Resource) FromAuthorizationCodeRequestResource1

func (t *AuthorizationCodeRequest_Resource) FromAuthorizationCodeRequestResource1(v AuthorizationCodeRequestResource1) error

FromAuthorizationCodeRequestResource1 overwrites any union data inside the AuthorizationCodeRequest_Resource as the provided AuthorizationCodeRequestResource1

func (AuthorizationCodeRequest_Resource) MarshalJSON

func (t AuthorizationCodeRequest_Resource) MarshalJSON() ([]byte, error)

func (*AuthorizationCodeRequest_Resource) MergeAuthorizationCodeRequestResource0

func (t *AuthorizationCodeRequest_Resource) MergeAuthorizationCodeRequestResource0(v AuthorizationCodeRequestResource0) error

MergeAuthorizationCodeRequestResource0 performs a merge with any union data inside the AuthorizationCodeRequest_Resource, using the provided AuthorizationCodeRequestResource0

func (*AuthorizationCodeRequest_Resource) MergeAuthorizationCodeRequestResource1

func (t *AuthorizationCodeRequest_Resource) MergeAuthorizationCodeRequestResource1(v AuthorizationCodeRequestResource1) error

MergeAuthorizationCodeRequestResource1 performs a merge with any union data inside the AuthorizationCodeRequest_Resource, using the provided AuthorizationCodeRequestResource1

func (*AuthorizationCodeRequest_Resource) UnmarshalJSON

func (t *AuthorizationCodeRequest_Resource) UnmarshalJSON(b []byte) error

type AuthorizeParams

type AuthorizeParams struct {
	ClientID     string                      `form:"client_id" json:"client_id"`
	ResponseType AuthorizeParamsResponseType `form:"response_type" json:"response_type"`
	RedirectURI  *string                     `form:"redirect_uri,omitempty" json:"redirect_uri,omitempty"`
	Scope        *string                     `form:"scope,omitempty" json:"scope,omitempty"`
	State        *string                     `form:"state,omitempty" json:"state,omitempty"`
	Resource     *struct {
		// contains filtered or unexported fields
	} `form:"resource,omitempty" json:"resource,omitempty"`
	CodeChallenge       string                             `form:"code_challenge" json:"code_challenge"`
	CodeChallengeMethod AuthorizeParamsCodeChallengeMethod `form:"code_challenge_method" json:"code_challenge_method"`
	Nonce               *string                            `form:"nonce,omitempty" json:"nonce,omitempty"`
	Prompt              *string                            `form:"prompt,omitempty" json:"prompt,omitempty"`
	MaxAge              *int                               `form:"max_age,omitempty" json:"max_age,omitempty"`
	AcrValues           *string                            `form:"acr_values,omitempty" json:"acr_values,omitempty"`
	IDTokenHint         *string                            `form:"id_token_hint,omitempty" json:"id_token_hint,omitempty"`
	ResponseMode        *AuthorizeParamsResponseMode       `form:"response_mode,omitempty" json:"response_mode,omitempty"`
}

AuthorizeParams defines parameters for Authorize.

type AuthorizeParamsCodeChallengeMethod

type AuthorizeParamsCodeChallengeMethod string

AuthorizeParamsCodeChallengeMethod defines parameters for Authorize.

const (
	AuthorizeParamsCodeChallengeMethodS256 AuthorizeParamsCodeChallengeMethod = "S256"
)

Defines values for AuthorizeParamsCodeChallengeMethod.

func (AuthorizeParamsCodeChallengeMethod) Valid

Valid indicates whether the value is a known member of the AuthorizeParamsCodeChallengeMethod enum.

type AuthorizeParamsResource0

type AuthorizeParamsResource0 = string

AuthorizeParamsResource0 defines parameters for Authorize.

type AuthorizeParamsResource1

type AuthorizeParamsResource1 = []string

AuthorizeParamsResource1 defines parameters for Authorize.

type AuthorizeParamsResponseMode

type AuthorizeParamsResponseMode string

AuthorizeParamsResponseMode defines parameters for Authorize.

const (
	AuthorizeParamsResponseModeQuery AuthorizeParamsResponseMode = "query"
)

Defines values for AuthorizeParamsResponseMode.

func (AuthorizeParamsResponseMode) Valid

Valid indicates whether the value is a known member of the AuthorizeParamsResponseMode enum.

type AuthorizeParamsResponseType

type AuthorizeParamsResponseType string

AuthorizeParamsResponseType defines parameters for Authorize.

const (
	AuthorizeParamsResponseTypeCode AuthorizeParamsResponseType = "code"
)

Defines values for AuthorizeParamsResponseType.

func (AuthorizeParamsResponseType) Valid

Valid indicates whether the value is a known member of the AuthorizeParamsResponseType enum.

type Client

type Client struct {
	// The endpoint of the server conforming to this interface, with scheme,
	// https://api.deepmap.com for example. This can contain a path relative
	// to the server, such as https://api.deepmap.com/dev-test, and all the
	// paths in the swagger spec will be appended to the server.
	Server string

	// Doer for performing requests, typically a *http.Client with any
	// customized settings, such as certificate chains.
	Client HttpRequestDoer

	// A list of callbacks for modifying requests which are generated before sending over
	// the network.
	RequestEditors []RequestEditorFn
}

Client which conforms to the OpenAPI3 specification for this service.

func NewClient

func NewClient(server string, opts ...ClientOption) (*Client, error)

Creates a new Client, with reasonable defaults

func (*Client) ApproveAuthorization

func (c *Client) ApproveAuthorization(ctx context.Context, body ApproveAuthorizationFormdataRequestBody, reqEditors ...RequestEditorFn) (*Response, error)

ApproveAuthorization Approve authorization consent

Browser consent submission. Requires the signed-in identity session, its CSRF token and the single-use auth_token from the consent page. Approval redirects with an authorization code; denial redirects with access_denied.

Takes a body of the `application/x-www-form-urlencoded` content type.

Corresponds with POST /oauth/authorize/consent (the `ApproveAuthorization` operationId).

func (*Client) ApproveAuthorizationWithBody

func (c *Client) ApproveAuthorizationWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*Response, error)

ApproveAuthorizationWithBody Approve authorization consent

Browser consent submission. Requires the signed-in identity session, its CSRF token and the single-use auth_token from the consent page. Approval redirects with an authorization code; denial redirects with access_denied.

Takes any type of body and a specified content type.

Corresponds with POST /oauth/authorize/consent (the `ApproveAuthorization` operationId).

func (*Client) Authorize

func (c *Client) Authorize(ctx context.Context, params *AuthorizeParams, reqEditors ...RequestEditorFn) (*Response, error)

Authorize Authorize a client

Browser authorization-code flow with S256 PKCE. Uses the identity session and may redirect to sign-in, required actions or consent. Success redirects to the registered callback with code, iss and the original state. After validating the client and callback, protocol errors also redirect there with error, error_description, iss and state. request and request_uri are unsupported; only response_mode=query is supported. POST requires the browser’s CSRF token.

Corresponds with GET /oauth/authorize (the `Authorize` operationId).

func (*Client) DenyAuthorization

func (c *Client) DenyAuthorization(ctx context.Context, body DenyAuthorizationFormdataRequestBody, reqEditors ...RequestEditorFn) (*Response, error)

DenyAuthorization Deny authorization consent

Browser consent submission. Requires the signed-in identity session, its CSRF token and the single-use auth_token from the consent page. Approval redirects with an authorization code; denial redirects with access_denied.

Takes a body of the `application/x-www-form-urlencoded` content type.

Corresponds with DELETE /oauth/authorize/consent (the `DenyAuthorization` operationId).

func (*Client) DenyAuthorizationWithBody

func (c *Client) DenyAuthorizationWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*Response, error)

DenyAuthorizationWithBody Deny authorization consent

Browser consent submission. Requires the signed-in identity session, its CSRF token and the single-use auth_token from the consent page. Approval redirects with an authorization code; denial redirects with access_denied.

Takes any type of body and a specified content type.

Corresponds with DELETE /oauth/authorize/consent (the `DenyAuthorization` operationId).

func (*Client) GetAuthorizationServerMetadata

func (c *Client) GetAuthorizationServerMetadata(ctx context.Context, reqEditors ...RequestEditorFn) (*OidcProviderMetadata, error)

GetAuthorizationServerMetadata Discover provider capabilities

The request host selects the realm. Endpoint URLs, scopes and optional capabilities describe that realm. The registration endpoint is advertised only when dynamic registration is enabled.

Corresponds with GET /.well-known/oauth-authorization-server (the `GetAuthorizationServerMetadata` operationId).

func (*Client) GetAuthorizationServerMetadataForPath

func (c *Client) GetAuthorizationServerMetadataForPath(ctx context.Context, path string, reqEditors ...RequestEditorFn) (*OidcProviderMetadata, error)

GetAuthorizationServerMetadataForPath Discover provider capabilities

The request host selects the realm. Endpoint URLs, scopes and optional capabilities describe that realm. The registration endpoint is advertised only when dynamic registration is enabled.

Corresponds with GET /.well-known/oauth-authorization-server/{path} (the `GetAuthorizationServerMetadataForPath` operationId).

func (*Client) GetJSONWebKeySet

func (c *Client) GetJSONWebKeySet(ctx context.Context, reqEditors ...RequestEditorFn) (*OidcJwks, error)

GetJSONWebKeySet Get public signing keys

Public RSA keys for validating tokens issued by this realm.

Corresponds with GET /.well-known/jwks.json (the `GetJSONWebKeySet` operationId).

func (*Client) GetProtectedResourceMetadata

func (c *Client) GetProtectedResourceMetadata(ctx context.Context, reqEditors ...RequestEditorFn) (*OAuthProtectedResource, error)

GetProtectedResourceMetadata Discover a protected resource

Discover a configured resource at the issuer root or a path relative to it. Unknown resources return 404.

Corresponds with GET /.well-known/oauth-protected-resource (the `GetProtectedResourceMetadata` operationId).

func (*Client) GetProtectedResourceMetadataForPath

func (c *Client) GetProtectedResourceMetadataForPath(ctx context.Context, path string, reqEditors ...RequestEditorFn) (*OAuthProtectedResource, error)

GetProtectedResourceMetadataForPath Discover a protected resource

Discover a configured resource at the issuer root or a path relative to it. Unknown resources return 404.

Corresponds with GET /.well-known/oauth-protected-resource/{path} (the `GetProtectedResourceMetadataForPath` operationId).

func (*Client) GetProviderMetadata

func (c *Client) GetProviderMetadata(ctx context.Context, reqEditors ...RequestEditorFn) (*OidcProviderMetadata, error)

GetProviderMetadata Discover provider capabilities

The request host selects the realm. Endpoint URLs, scopes and optional capabilities describe that realm. The registration endpoint is advertised only when dynamic registration is enabled.

Corresponds with GET /.well-known/openid-configuration (the `GetProviderMetadata` operationId).

func (*Client) GetUserInfo

func (c *Client) GetUserInfo(ctx context.Context, reqEditors ...RequestEditorFn) (*OidcUserinfo, error)

GetUserInfo Read the authenticated user’s claims

Send a user access token in the Authorization: Bearer header. The token must include the openid scope. Service tokens are rejected. Additional claims depend on the granted scopes and the realm’s claim resolvers. Compare sub with the ID token’s subject.

Corresponds with GET /oauth/userinfo (the `GetUserInfo` operationId).

func (*Client) IntrospectToken

func (c *Client) IntrospectToken(ctx context.Context, body IntrospectTokenFormdataRequestBody, reqEditors ...RequestEditorFn) (*OAuthIntrospection, error)

IntrospectToken Inspect a token

Requires a confidential client using its registered client_secret_basic or client_secret_post method. Unknown, expired, revoked and inaccessible tokens return active: false.

Takes a body of the `application/x-www-form-urlencoded` content type.

Corresponds with POST /oauth/introspect (the `IntrospectToken` operationId).

func (*Client) IntrospectTokenWithBody

func (c *Client) IntrospectTokenWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*OAuthIntrospection, error)

IntrospectTokenWithBody Inspect a token

Requires a confidential client using its registered client_secret_basic or client_secret_post method. Unknown, expired, revoked and inaccessible tokens return active: false.

Takes any type of body and a specified content type.

Corresponds with POST /oauth/introspect (the `IntrospectToken` operationId).

func (*Client) IssueToken

func (c *Client) IssueToken(ctx context.Context, body IssueTokenFormdataRequestBody, reqEditors ...RequestEditorFn) (*OAuthTokenResponse, error)

IssueToken Issue or exchange tokens

Use the realm host as the issuer. Authenticate with the client’s registered method: HTTP Basic (URL-encode the identifier and secret before Base64 encoding), client_id/client_secret in the form, or client_id alone for public clients. Do not combine Basic and a form secret. Token exchange requires realm support and an eligible confidential or trusted first-party client.

Takes a body of the `application/x-www-form-urlencoded` content type.

Corresponds with POST /oauth/token (the `IssueToken` operationId).

func (*Client) IssueTokenWithBody

func (c *Client) IssueTokenWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*OAuthTokenResponse, error)

IssueTokenWithBody Issue or exchange tokens

Use the realm host as the issuer. Authenticate with the client’s registered method: HTTP Basic (URL-encode the identifier and secret before Base64 encoding), client_id/client_secret in the form, or client_id alone for public clients. Do not combine Basic and a form secret. Token exchange requires realm support and an eligible confidential or trusted first-party client.

Takes any type of body and a specified content type.

Corresponds with POST /oauth/token (the `IssueToken` operationId).

func (*Client) Logout

func (c *Client) Logout(ctx context.Context, params *LogoutParams, reqEditors ...RequestEditorFn) (*Response, error)

Logout End the identity session

Browser logout, optionally with a confirmation page. A post-logout redirect is used only when registered to the identified client; state is echoed on that redirect. Invalid ID token hints are ignored. POST requires the browser’s CSRF token.

Corresponds with GET /oauth/logout (the `Logout` operationId).

func (*Client) PostUserInfo

func (c *Client) PostUserInfo(ctx context.Context, reqEditors ...RequestEditorFn) (*OidcUserinfo, error)

PostUserInfo Read the authenticated user’s claims

Send a user access token in the Authorization: Bearer header. The token must include the openid scope. Service tokens are rejected. Additional claims depend on the granted scopes and the realm’s claim resolvers. Compare sub with the ID token’s subject.

Corresponds with POST /oauth/userinfo (the `PostUserInfo` operationId).

func (*Client) RegisterClient

func (c *Client) RegisterClient(ctx context.Context, body RegisterClientJSONRequestBody, reqEditors ...RequestEditorFn) (*OAuthRegisteredClient, error)

RegisterClient Register an OAuth client

Dynamic client registration must be enabled for the realm. Registers authorization-code clients, optionally with refresh tokens. Unknown metadata is ignored.

Takes a body of the `application/json` content type.

Corresponds with POST /oauth/register (the `RegisterClient` operationId).

func (*Client) RegisterClientWithBody

func (c *Client) RegisterClientWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*OAuthRegisteredClient, error)

RegisterClientWithBody Register an OAuth client

Dynamic client registration must be enabled for the realm. Registers authorization-code clients, optionally with refresh tokens. Unknown metadata is ignored.

Takes any type of body and a specified content type.

Corresponds with POST /oauth/register (the `RegisterClient` operationId).

func (*Client) RevokeToken

func (c *Client) RevokeToken(ctx context.Context, body RevokeTokenFormdataRequestBody, reqEditors ...RequestEditorFn) (*Response, error)

RevokeToken Revoke a token

Authenticate with the registered Basic, form-secret or public-client method. Unknown tokens and tokens owned by another client also return an empty success response.

Takes a body of the `application/x-www-form-urlencoded` content type.

Corresponds with POST /oauth/revoke (the `RevokeToken` operationId).

func (*Client) RevokeTokenWithBody

func (c *Client) RevokeTokenWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*Response, error)

RevokeTokenWithBody Revoke a token

Authenticate with the registered Basic, form-secret or public-client method. Unknown tokens and tokens owned by another client also return an empty success response.

Takes any type of body and a specified content type.

Corresponds with POST /oauth/revoke (the `RevokeToken` operationId).

func (*Client) SubmitAuthorization

func (c *Client) SubmitAuthorization(ctx context.Context, body SubmitAuthorizationFormdataRequestBody, reqEditors ...RequestEditorFn) (*Response, error)

SubmitAuthorization Authorize a client

Browser authorization-code flow with S256 PKCE. Uses the identity session and may redirect to sign-in, required actions or consent. Success redirects to the registered callback with code, iss and the original state. After validating the client and callback, protocol errors also redirect there with error, error_description, iss and state. request and request_uri are unsupported; only response_mode=query is supported. POST requires the browser’s CSRF token.

Takes a body of the `application/x-www-form-urlencoded` content type.

Corresponds with POST /oauth/authorize (the `SubmitAuthorization` operationId).

func (*Client) SubmitAuthorizationWithBody

func (c *Client) SubmitAuthorizationWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*Response, error)

SubmitAuthorizationWithBody Authorize a client

Browser authorization-code flow with S256 PKCE. Uses the identity session and may redirect to sign-in, required actions or consent. Success redirects to the registered callback with code, iss and the original state. After validating the client and callback, protocol errors also redirect there with error, error_description, iss and state. request and request_uri are unsupported; only response_mode=query is supported. POST requires the browser’s CSRF token.

Takes any type of body and a specified content type.

Corresponds with POST /oauth/authorize (the `SubmitAuthorization` operationId).

func (*Client) SubmitLogout

func (c *Client) SubmitLogout(ctx context.Context, body SubmitLogoutFormdataRequestBody, reqEditors ...RequestEditorFn) (*Response, error)

SubmitLogout End the identity session

Browser logout, optionally with a confirmation page. A post-logout redirect is used only when registered to the identified client; state is echoed on that redirect. Invalid ID token hints are ignored. POST requires the browser’s CSRF token.

Takes a body of the `application/x-www-form-urlencoded` content type.

Corresponds with POST /oauth/logout (the `SubmitLogout` operationId).

func (*Client) SubmitLogoutWithBody

func (c *Client) SubmitLogoutWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*Response, error)

SubmitLogoutWithBody End the identity session

Browser logout, optionally with a confirmation page. A post-logout redirect is used only when registered to the identified client; state is echoed on that redirect. Invalid ID token hints are ignored. POST requires the browser’s CSRF token.

Takes any type of body and a specified content type.

Corresponds with POST /oauth/logout (the `SubmitLogout` operationId).

type ClientCredentialsRequest

type ClientCredentialsRequest struct {
	// ClientID Required for form-secret and public-client authentication. Omit when using HTTP Basic.
	ClientID *string `json:"client_id,omitempty"`

	// ClientSecret Required only for client_secret_post. Never combine with HTTP Basic.
	ClientSecret *string                           `json:"client_secret,omitempty"`
	GrantType    ClientCredentialsRequestGrantType `json:"grant_type"`

	// Resource Absolute protected-resource URI without a fragment, or an array of such URIs using resource[] fields. Authorization and client-credentials requests default to the realm audience. Code and refresh grants preserve the original audiences when omitted, or narrow them when supplied.
	Resource *ClientCredentialsRequest_Resource `json:"resource,omitempty"`

	// Scope Space-delimited scopes for client credentials, refresh or exchange. Refresh and exchange can only narrow granted scopes; authorization-code redemption uses the approved scopes.
	Scope *string `json:"scope,omitempty"`
}

ClientCredentialsRequest defines model for ClientCredentialsRequest.

type ClientCredentialsRequestGrantType

type ClientCredentialsRequestGrantType string

ClientCredentialsRequestGrantType defines model for ClientCredentialsRequest.GrantType.

const (
	ClientCredentials ClientCredentialsRequestGrantType = "client_credentials"
)

Defines values for ClientCredentialsRequestGrantType.

func (ClientCredentialsRequestGrantType) Valid

Valid indicates whether the value is a known member of the ClientCredentialsRequestGrantType enum.

type ClientCredentialsRequestResource0

type ClientCredentialsRequestResource0 = string

ClientCredentialsRequestResource0 defines model for ClientCredentialsRequest.Resource.0.

type ClientCredentialsRequestResource1

type ClientCredentialsRequestResource1 = []string

ClientCredentialsRequestResource1 defines model for ClientCredentialsRequest.Resource.1.

type ClientCredentialsRequest_Resource

type ClientCredentialsRequest_Resource struct {
	// contains filtered or unexported fields
}

ClientCredentialsRequest_Resource Absolute protected-resource URI without a fragment, or an array of such URIs using resource[] fields. Authorization and client-credentials requests default to the realm audience. Code and refresh grants preserve the original audiences when omitted, or narrow them when supplied.

func (ClientCredentialsRequest_Resource) AsClientCredentialsRequestResource0

func (t ClientCredentialsRequest_Resource) AsClientCredentialsRequestResource0() (ClientCredentialsRequestResource0, error)

AsClientCredentialsRequestResource0 returns the union data inside the ClientCredentialsRequest_Resource as a ClientCredentialsRequestResource0

func (ClientCredentialsRequest_Resource) AsClientCredentialsRequestResource1

func (t ClientCredentialsRequest_Resource) AsClientCredentialsRequestResource1() (ClientCredentialsRequestResource1, error)

AsClientCredentialsRequestResource1 returns the union data inside the ClientCredentialsRequest_Resource as a ClientCredentialsRequestResource1

func (*ClientCredentialsRequest_Resource) FromClientCredentialsRequestResource0

func (t *ClientCredentialsRequest_Resource) FromClientCredentialsRequestResource0(v ClientCredentialsRequestResource0) error

FromClientCredentialsRequestResource0 overwrites any union data inside the ClientCredentialsRequest_Resource as the provided ClientCredentialsRequestResource0

func (*ClientCredentialsRequest_Resource) FromClientCredentialsRequestResource1

func (t *ClientCredentialsRequest_Resource) FromClientCredentialsRequestResource1(v ClientCredentialsRequestResource1) error

FromClientCredentialsRequestResource1 overwrites any union data inside the ClientCredentialsRequest_Resource as the provided ClientCredentialsRequestResource1

func (ClientCredentialsRequest_Resource) MarshalJSON

func (t ClientCredentialsRequest_Resource) MarshalJSON() ([]byte, error)

func (*ClientCredentialsRequest_Resource) MergeClientCredentialsRequestResource0

func (t *ClientCredentialsRequest_Resource) MergeClientCredentialsRequestResource0(v ClientCredentialsRequestResource0) error

MergeClientCredentialsRequestResource0 performs a merge with any union data inside the ClientCredentialsRequest_Resource, using the provided ClientCredentialsRequestResource0

func (*ClientCredentialsRequest_Resource) MergeClientCredentialsRequestResource1

func (t *ClientCredentialsRequest_Resource) MergeClientCredentialsRequestResource1(v ClientCredentialsRequestResource1) error

MergeClientCredentialsRequestResource1 performs a merge with any union data inside the ClientCredentialsRequest_Resource, using the provided ClientCredentialsRequestResource1

func (*ClientCredentialsRequest_Resource) UnmarshalJSON

func (t *ClientCredentialsRequest_Resource) UnmarshalJSON(b []byte) error

type ClientInterface

type ClientInterface interface {

	// GetJSONWebKeySet Get public signing keys
	//
	// Public RSA keys for validating tokens issued by this realm.
	//
	// Corresponds with GET /.well-known/jwks.json (the `GetJSONWebKeySet` operationId).
	GetJSONWebKeySet(ctx context.Context, reqEditors ...RequestEditorFn) (*OidcJwks, error)

	// GetAuthorizationServerMetadata Discover provider capabilities
	//
	// The request host selects the realm. Endpoint URLs, scopes and optional capabilities describe that realm. The registration endpoint is advertised only when dynamic registration is enabled.
	//
	// Corresponds with GET /.well-known/oauth-authorization-server (the `GetAuthorizationServerMetadata` operationId).
	GetAuthorizationServerMetadata(ctx context.Context, reqEditors ...RequestEditorFn) (*OidcProviderMetadata, error)

	// GetAuthorizationServerMetadataForPath Discover provider capabilities
	//
	// The request host selects the realm. Endpoint URLs, scopes and optional capabilities describe that realm. The registration endpoint is advertised only when dynamic registration is enabled.
	//
	// Corresponds with GET /.well-known/oauth-authorization-server/{path} (the `GetAuthorizationServerMetadataForPath` operationId).
	GetAuthorizationServerMetadataForPath(ctx context.Context, path string, reqEditors ...RequestEditorFn) (*OidcProviderMetadata, error)

	// GetProtectedResourceMetadata Discover a protected resource
	//
	// Discover a configured resource at the issuer root or a path relative to it. Unknown resources return 404.
	//
	// Corresponds with GET /.well-known/oauth-protected-resource (the `GetProtectedResourceMetadata` operationId).
	GetProtectedResourceMetadata(ctx context.Context, reqEditors ...RequestEditorFn) (*OAuthProtectedResource, error)

	// GetProtectedResourceMetadataForPath Discover a protected resource
	//
	// Discover a configured resource at the issuer root or a path relative to it. Unknown resources return 404.
	//
	// Corresponds with GET /.well-known/oauth-protected-resource/{path} (the `GetProtectedResourceMetadataForPath` operationId).
	GetProtectedResourceMetadataForPath(ctx context.Context, path string, reqEditors ...RequestEditorFn) (*OAuthProtectedResource, error)

	// GetProviderMetadata Discover provider capabilities
	//
	// The request host selects the realm. Endpoint URLs, scopes and optional capabilities describe that realm. The registration endpoint is advertised only when dynamic registration is enabled.
	//
	// Corresponds with GET /.well-known/openid-configuration (the `GetProviderMetadata` operationId).
	GetProviderMetadata(ctx context.Context, reqEditors ...RequestEditorFn) (*OidcProviderMetadata, error)

	// Authorize Authorize a client
	//
	// Browser authorization-code flow with S256 PKCE. Uses the identity session and may redirect to sign-in, required actions or consent. Success redirects to the registered callback with code, iss and the original state. After validating the client and callback, protocol errors also redirect there with error, error_description, iss and state. request and request_uri are unsupported; only response_mode=query is supported. POST requires the browser’s CSRF token.
	//
	// Corresponds with GET /oauth/authorize (the `Authorize` operationId).
	Authorize(ctx context.Context, params *AuthorizeParams, reqEditors ...RequestEditorFn) (*Response, error)

	// SubmitAuthorizationWithBody Authorize a client
	//
	// Browser authorization-code flow with S256 PKCE. Uses the identity session and may redirect to sign-in, required actions or consent. Success redirects to the registered callback with code, iss and the original state. After validating the client and callback, protocol errors also redirect there with error, error_description, iss and state. request and request_uri are unsupported; only response_mode=query is supported. POST requires the browser’s CSRF token.
	//
	// Takes any type of body and a specified content type.
	//
	// Corresponds with POST /oauth/authorize (the `SubmitAuthorization` operationId).
	SubmitAuthorizationWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*Response, error)

	// SubmitAuthorization Authorize a client
	//
	// Browser authorization-code flow with S256 PKCE. Uses the identity session and may redirect to sign-in, required actions or consent. Success redirects to the registered callback with code, iss and the original state. After validating the client and callback, protocol errors also redirect there with error, error_description, iss and state. request and request_uri are unsupported; only response_mode=query is supported. POST requires the browser’s CSRF token.
	//
	// Takes a body of the `application/x-www-form-urlencoded` content type.
	//
	// Corresponds with POST /oauth/authorize (the `SubmitAuthorization` operationId).
	SubmitAuthorization(ctx context.Context, body SubmitAuthorizationFormdataRequestBody, reqEditors ...RequestEditorFn) (*Response, error)

	// DenyAuthorizationWithBody Deny authorization consent
	//
	// Browser consent submission. Requires the signed-in identity session, its CSRF token and the single-use auth_token from the consent page. Approval redirects with an authorization code; denial redirects with access_denied.
	//
	// Takes any type of body and a specified content type.
	//
	// Corresponds with DELETE /oauth/authorize/consent (the `DenyAuthorization` operationId).
	DenyAuthorizationWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*Response, error)

	// DenyAuthorization Deny authorization consent
	//
	// Browser consent submission. Requires the signed-in identity session, its CSRF token and the single-use auth_token from the consent page. Approval redirects with an authorization code; denial redirects with access_denied.
	//
	// Takes a body of the `application/x-www-form-urlencoded` content type.
	//
	// Corresponds with DELETE /oauth/authorize/consent (the `DenyAuthorization` operationId).
	DenyAuthorization(ctx context.Context, body DenyAuthorizationFormdataRequestBody, reqEditors ...RequestEditorFn) (*Response, error)

	// ApproveAuthorizationWithBody Approve authorization consent
	//
	// Browser consent submission. Requires the signed-in identity session, its CSRF token and the single-use auth_token from the consent page. Approval redirects with an authorization code; denial redirects with access_denied.
	//
	// Takes any type of body and a specified content type.
	//
	// Corresponds with POST /oauth/authorize/consent (the `ApproveAuthorization` operationId).
	ApproveAuthorizationWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*Response, error)

	// ApproveAuthorization Approve authorization consent
	//
	// Browser consent submission. Requires the signed-in identity session, its CSRF token and the single-use auth_token from the consent page. Approval redirects with an authorization code; denial redirects with access_denied.
	//
	// Takes a body of the `application/x-www-form-urlencoded` content type.
	//
	// Corresponds with POST /oauth/authorize/consent (the `ApproveAuthorization` operationId).
	ApproveAuthorization(ctx context.Context, body ApproveAuthorizationFormdataRequestBody, reqEditors ...RequestEditorFn) (*Response, error)

	// IntrospectTokenWithBody Inspect a token
	//
	// Requires a confidential client using its registered client_secret_basic or client_secret_post method. Unknown, expired, revoked and inaccessible tokens return active: false.
	//
	// Takes any type of body and a specified content type.
	//
	// Corresponds with POST /oauth/introspect (the `IntrospectToken` operationId).
	IntrospectTokenWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*OAuthIntrospection, error)

	// IntrospectToken Inspect a token
	//
	// Requires a confidential client using its registered client_secret_basic or client_secret_post method. Unknown, expired, revoked and inaccessible tokens return active: false.
	//
	// Takes a body of the `application/x-www-form-urlencoded` content type.
	//
	// Corresponds with POST /oauth/introspect (the `IntrospectToken` operationId).
	IntrospectToken(ctx context.Context, body IntrospectTokenFormdataRequestBody, reqEditors ...RequestEditorFn) (*OAuthIntrospection, error)

	// Logout End the identity session
	//
	// Browser logout, optionally with a confirmation page. A post-logout redirect is used only when registered to the identified client; state is echoed on that redirect. Invalid ID token hints are ignored. POST requires the browser’s CSRF token.
	//
	// Corresponds with GET /oauth/logout (the `Logout` operationId).
	Logout(ctx context.Context, params *LogoutParams, reqEditors ...RequestEditorFn) (*Response, error)

	// SubmitLogoutWithBody End the identity session
	//
	// Browser logout, optionally with a confirmation page. A post-logout redirect is used only when registered to the identified client; state is echoed on that redirect. Invalid ID token hints are ignored. POST requires the browser’s CSRF token.
	//
	// Takes any type of body and a specified content type.
	//
	// Corresponds with POST /oauth/logout (the `SubmitLogout` operationId).
	SubmitLogoutWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*Response, error)

	// SubmitLogout End the identity session
	//
	// Browser logout, optionally with a confirmation page. A post-logout redirect is used only when registered to the identified client; state is echoed on that redirect. Invalid ID token hints are ignored. POST requires the browser’s CSRF token.
	//
	// Takes a body of the `application/x-www-form-urlencoded` content type.
	//
	// Corresponds with POST /oauth/logout (the `SubmitLogout` operationId).
	SubmitLogout(ctx context.Context, body SubmitLogoutFormdataRequestBody, reqEditors ...RequestEditorFn) (*Response, error)

	// RegisterClientWithBody Register an OAuth client
	//
	// Dynamic client registration must be enabled for the realm. Registers authorization-code clients, optionally with refresh tokens. Unknown metadata is ignored.
	//
	// Takes any type of body and a specified content type.
	//
	// Corresponds with POST /oauth/register (the `RegisterClient` operationId).
	RegisterClientWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*OAuthRegisteredClient, error)

	// RegisterClient Register an OAuth client
	//
	// Dynamic client registration must be enabled for the realm. Registers authorization-code clients, optionally with refresh tokens. Unknown metadata is ignored.
	//
	// Takes a body of the `application/json` content type.
	//
	// Corresponds with POST /oauth/register (the `RegisterClient` operationId).
	RegisterClient(ctx context.Context, body RegisterClientJSONRequestBody, reqEditors ...RequestEditorFn) (*OAuthRegisteredClient, error)

	// RevokeTokenWithBody Revoke a token
	//
	// Authenticate with the registered Basic, form-secret or public-client method. Unknown tokens and tokens owned by another client also return an empty success response.
	//
	// Takes any type of body and a specified content type.
	//
	// Corresponds with POST /oauth/revoke (the `RevokeToken` operationId).
	RevokeTokenWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*Response, error)

	// RevokeToken Revoke a token
	//
	// Authenticate with the registered Basic, form-secret or public-client method. Unknown tokens and tokens owned by another client also return an empty success response.
	//
	// Takes a body of the `application/x-www-form-urlencoded` content type.
	//
	// Corresponds with POST /oauth/revoke (the `RevokeToken` operationId).
	RevokeToken(ctx context.Context, body RevokeTokenFormdataRequestBody, reqEditors ...RequestEditorFn) (*Response, error)

	// IssueTokenWithBody Issue or exchange tokens
	//
	// Use the realm host as the issuer. Authenticate with the client’s registered method: HTTP Basic (URL-encode the identifier and secret before Base64 encoding), client_id/client_secret in the form, or client_id alone for public clients. Do not combine Basic and a form secret. Token exchange requires realm support and an eligible confidential or trusted first-party client.
	//
	// Takes any type of body and a specified content type.
	//
	// Corresponds with POST /oauth/token (the `IssueToken` operationId).
	IssueTokenWithBody(ctx context.Context, contentType string, body io.Reader, reqEditors ...RequestEditorFn) (*OAuthTokenResponse, error)

	// IssueToken Issue or exchange tokens
	//
	// Use the realm host as the issuer. Authenticate with the client’s registered method: HTTP Basic (URL-encode the identifier and secret before Base64 encoding), client_id/client_secret in the form, or client_id alone for public clients. Do not combine Basic and a form secret. Token exchange requires realm support and an eligible confidential or trusted first-party client.
	//
	// Takes a body of the `application/x-www-form-urlencoded` content type.
	//
	// Corresponds with POST /oauth/token (the `IssueToken` operationId).
	IssueToken(ctx context.Context, body IssueTokenFormdataRequestBody, reqEditors ...RequestEditorFn) (*OAuthTokenResponse, error)

	// GetUserInfo Read the authenticated user’s claims
	//
	// Send a user access token in the Authorization: Bearer header. The token must include the openid scope. Service tokens are rejected. Additional claims depend on the granted scopes and the realm’s claim resolvers. Compare sub with the ID token’s subject.
	//
	// Corresponds with GET /oauth/userinfo (the `GetUserInfo` operationId).
	GetUserInfo(ctx context.Context, reqEditors ...RequestEditorFn) (*OidcUserinfo, error)

	// PostUserInfo Read the authenticated user’s claims
	//
	// Send a user access token in the Authorization: Bearer header. The token must include the openid scope. Service tokens are rejected. Additional claims depend on the granted scopes and the realm’s claim resolvers. Compare sub with the ID token’s subject.
	//
	// Corresponds with POST /oauth/userinfo (the `PostUserInfo` operationId).
	PostUserInfo(ctx context.Context, reqEditors ...RequestEditorFn) (*OidcUserinfo, error)
}

The interface specification for the client above.

type ClientOption

type ClientOption func(*Client) error

ClientOption allows setting custom parameters during construction

func WithHTTPClient

func WithHTTPClient(doer HttpRequestDoer) ClientOption

WithHTTPClient allows overriding the default Doer, which is automatically created using http.Client. This is useful for tests.

func WithRequestEditorFn

func WithRequestEditorFn(fn RequestEditorFn) ClientOption

WithRequestEditorFn allows setting up a callback function, which will be called right before sending the request. This can be used to mutate the request.

func WithToken

func WithToken(token string) ClientOption

type DenyAuthorizationFormdataRequestBody

type DenyAuthorizationFormdataRequestBody = OAuthConsentRequest

DenyAuthorizationFormdataRequestBody defines body for DenyAuthorization for application/x-www-form-urlencoded ContentType.

type HttpRequestDoer

type HttpRequestDoer interface {
	Do(req *http.Request) (*http.Response, error)
}

Doer performs HTTP requests.

The standard http.Client implements this interface.

type IntrospectTokenFormdataRequestBody

type IntrospectTokenFormdataRequestBody = OAuthPresentedToken

IntrospectTokenFormdataRequestBody defines body for IntrospectToken for application/x-www-form-urlencoded ContentType.

type IssueTokenFormdataRequestBody

type IssueTokenFormdataRequestBody = OAuthTokenRequest

IssueTokenFormdataRequestBody defines body for IssueToken for application/x-www-form-urlencoded ContentType.

type LogoutParams

type LogoutParams struct {
	IDTokenHint           *string `form:"id_token_hint,omitempty" json:"id_token_hint,omitempty"`
	ClientID              *string `form:"client_id,omitempty" json:"client_id,omitempty"`
	PostLogoutRedirectURI *string `form:"post_logout_redirect_uri,omitempty" json:"post_logout_redirect_uri,omitempty"`
	State                 *string `form:"state,omitempty" json:"state,omitempty"`
	LogoutHint            *string `form:"logout_hint,omitempty" json:"logout_hint,omitempty"`
	UILocales             *string `form:"ui_locales,omitempty" json:"ui_locales,omitempty"`
}

LogoutParams defines parameters for Logout.

type OAuthAuthorizationRequest

type OAuthAuthorizationRequest struct {
	// UnderscoreToken Browser CSRF token, alternatively sent using X-CSRF-TOKEN.
	UnderscoreToken *string `json:"_token,omitempty"`

	// AcrValues Space-delimited requested authentication context values.
	AcrValues *string `json:"acr_values,omitempty"`
	ClientID  string  `json:"client_id"`

	// CodeChallenge Base64url-encoded SHA-256 digest of the PKCE verifier.
	CodeChallenge       string                                       `json:"code_challenge"`
	CodeChallengeMethod OAuthAuthorizationRequestCodeChallengeMethod `json:"code_challenge_method"`
	IDTokenHint         *string                                      `json:"id_token_hint,omitempty"`

	// MaxAge Maximum acceptable age of authentication in seconds.
	MaxAge *int `json:"max_age,omitempty"`

	// Nonce Nonce bound to the issued ID token.
	Nonce *string `json:"nonce,omitempty"`

	// Prompt Space-delimited none, login, consent or select_account. none must be used alone.
	Prompt *string `json:"prompt,omitempty"`

	// RedirectURI Registered callback. May be omitted only when the client has exactly one registered redirect URI.
	RedirectURI *string `json:"redirect_uri,omitempty"`

	// Resource Absolute protected-resource URI without a fragment, or an array of such URIs using resource[] fields. Authorization and client-credentials requests default to the realm audience. Code and refresh grants preserve the original audiences when omitted, or narrow them when supplied.
	Resource     *OAuthAuthorizationRequest_Resource    `json:"resource,omitempty"`
	ResponseMode *OAuthAuthorizationRequestResponseMode `json:"response_mode,omitempty"`
	ResponseType OAuthAuthorizationRequestResponseType  `json:"response_type"`

	// Scope Space-delimited scopes; include openid for OpenID Connect.
	Scope *string `json:"scope,omitempty"`

	// State Opaque client state echoed on the callback.
	State *string `json:"state,omitempty"`
}

OAuthAuthorizationRequest defines model for OAuthAuthorizationRequest.

type OAuthAuthorizationRequestCodeChallengeMethod

type OAuthAuthorizationRequestCodeChallengeMethod string

OAuthAuthorizationRequestCodeChallengeMethod defines model for OAuthAuthorizationRequest.CodeChallengeMethod.

const (
	OAuthAuthorizationRequestCodeChallengeMethodS256 OAuthAuthorizationRequestCodeChallengeMethod = "S256"
)

Defines values for OAuthAuthorizationRequestCodeChallengeMethod.

func (OAuthAuthorizationRequestCodeChallengeMethod) Valid

Valid indicates whether the value is a known member of the OAuthAuthorizationRequestCodeChallengeMethod enum.

type OAuthAuthorizationRequestResource0

type OAuthAuthorizationRequestResource0 = string

OAuthAuthorizationRequestResource0 defines model for OAuthAuthorizationRequest.Resource.0.

type OAuthAuthorizationRequestResource1

type OAuthAuthorizationRequestResource1 = []string

OAuthAuthorizationRequestResource1 defines model for OAuthAuthorizationRequest.Resource.1.

type OAuthAuthorizationRequestResponseMode

type OAuthAuthorizationRequestResponseMode string

OAuthAuthorizationRequestResponseMode defines model for OAuthAuthorizationRequest.ResponseMode.

const (
	OAuthAuthorizationRequestResponseModeQuery OAuthAuthorizationRequestResponseMode = "query"
)

Defines values for OAuthAuthorizationRequestResponseMode.

func (OAuthAuthorizationRequestResponseMode) Valid

Valid indicates whether the value is a known member of the OAuthAuthorizationRequestResponseMode enum.

type OAuthAuthorizationRequestResponseType

type OAuthAuthorizationRequestResponseType string

OAuthAuthorizationRequestResponseType defines model for OAuthAuthorizationRequest.ResponseType.

const (
	OAuthAuthorizationRequestResponseTypeCode OAuthAuthorizationRequestResponseType = "code"
)

Defines values for OAuthAuthorizationRequestResponseType.

func (OAuthAuthorizationRequestResponseType) Valid

Valid indicates whether the value is a known member of the OAuthAuthorizationRequestResponseType enum.

type OAuthAuthorizationRequest_Resource

type OAuthAuthorizationRequest_Resource struct {
	// contains filtered or unexported fields
}

OAuthAuthorizationRequest_Resource Absolute protected-resource URI without a fragment, or an array of such URIs using resource[] fields. Authorization and client-credentials requests default to the realm audience. Code and refresh grants preserve the original audiences when omitted, or narrow them when supplied.

func (OAuthAuthorizationRequest_Resource) AsOAuthAuthorizationRequestResource0

func (t OAuthAuthorizationRequest_Resource) AsOAuthAuthorizationRequestResource0() (OAuthAuthorizationRequestResource0, error)

AsOAuthAuthorizationRequestResource0 returns the union data inside the OAuthAuthorizationRequest_Resource as a OAuthAuthorizationRequestResource0

func (OAuthAuthorizationRequest_Resource) AsOAuthAuthorizationRequestResource1

func (t OAuthAuthorizationRequest_Resource) AsOAuthAuthorizationRequestResource1() (OAuthAuthorizationRequestResource1, error)

AsOAuthAuthorizationRequestResource1 returns the union data inside the OAuthAuthorizationRequest_Resource as a OAuthAuthorizationRequestResource1

func (*OAuthAuthorizationRequest_Resource) FromOAuthAuthorizationRequestResource0

func (t *OAuthAuthorizationRequest_Resource) FromOAuthAuthorizationRequestResource0(v OAuthAuthorizationRequestResource0) error

FromOAuthAuthorizationRequestResource0 overwrites any union data inside the OAuthAuthorizationRequest_Resource as the provided OAuthAuthorizationRequestResource0

func (*OAuthAuthorizationRequest_Resource) FromOAuthAuthorizationRequestResource1

func (t *OAuthAuthorizationRequest_Resource) FromOAuthAuthorizationRequestResource1(v OAuthAuthorizationRequestResource1) error

FromOAuthAuthorizationRequestResource1 overwrites any union data inside the OAuthAuthorizationRequest_Resource as the provided OAuthAuthorizationRequestResource1

func (OAuthAuthorizationRequest_Resource) MarshalJSON

func (t OAuthAuthorizationRequest_Resource) MarshalJSON() ([]byte, error)

func (*OAuthAuthorizationRequest_Resource) MergeOAuthAuthorizationRequestResource0

func (t *OAuthAuthorizationRequest_Resource) MergeOAuthAuthorizationRequestResource0(v OAuthAuthorizationRequestResource0) error

MergeOAuthAuthorizationRequestResource0 performs a merge with any union data inside the OAuthAuthorizationRequest_Resource, using the provided OAuthAuthorizationRequestResource0

func (*OAuthAuthorizationRequest_Resource) MergeOAuthAuthorizationRequestResource1

func (t *OAuthAuthorizationRequest_Resource) MergeOAuthAuthorizationRequestResource1(v OAuthAuthorizationRequestResource1) error

MergeOAuthAuthorizationRequestResource1 performs a merge with any union data inside the OAuthAuthorizationRequest_Resource, using the provided OAuthAuthorizationRequestResource1

func (*OAuthAuthorizationRequest_Resource) UnmarshalJSON

func (t *OAuthAuthorizationRequest_Resource) UnmarshalJSON(b []byte) error

type OAuthClientRegistration

type OAuthClientRegistration struct {
	BackchannelLogoutSessionRequired *bool `json:"backchannel_logout_session_required,omitempty"`

	// BackchannelLogoutURI HTTPS URI without a fragment.
	BackchannelLogoutURI *string `json:"backchannel_logout_uri,omitempty"`
	ClientName           *string `json:"client_name,omitempty"`

	// GrantTypes Must include authorization_code.
	GrantTypes              *[]OAuthClientRegistrationGrantTypes            `json:"grant_types,omitempty"`
	PostLogoutRedirectUris  *[]string                                       `json:"post_logout_redirect_uris,omitempty"`
	RedirectUris            []string                                        `json:"redirect_uris"`
	ResponseTypes           *[]OAuthClientRegistrationResponseTypes         `json:"response_types,omitempty"`
	TokenEndpointAuthMethod *OAuthClientRegistrationTokenEndpointAuthMethod `json:"token_endpoint_auth_method,omitempty"`
}

OAuthClientRegistration defines model for OAuthClientRegistration.

type OAuthClientRegistrationGrantTypes

type OAuthClientRegistrationGrantTypes string

OAuthClientRegistrationGrantTypes defines model for OAuthClientRegistration.GrantTypes.

const (
	OAuthClientRegistrationGrantTypesAuthorizationCode OAuthClientRegistrationGrantTypes = "authorization_code"
	OAuthClientRegistrationGrantTypesRefreshToken      OAuthClientRegistrationGrantTypes = "refresh_token"
)

Defines values for OAuthClientRegistrationGrantTypes.

func (OAuthClientRegistrationGrantTypes) Valid

Valid indicates whether the value is a known member of the OAuthClientRegistrationGrantTypes enum.

type OAuthClientRegistrationResponseTypes

type OAuthClientRegistrationResponseTypes string

OAuthClientRegistrationResponseTypes defines model for OAuthClientRegistration.ResponseTypes.

const (
	OAuthClientRegistrationResponseTypesCode OAuthClientRegistrationResponseTypes = "code"
)

Defines values for OAuthClientRegistrationResponseTypes.

func (OAuthClientRegistrationResponseTypes) Valid

Valid indicates whether the value is a known member of the OAuthClientRegistrationResponseTypes enum.

type OAuthClientRegistrationTokenEndpointAuthMethod

type OAuthClientRegistrationTokenEndpointAuthMethod string

OAuthClientRegistrationTokenEndpointAuthMethod defines model for OAuthClientRegistration.TokenEndpointAuthMethod.

const (
	OAuthClientRegistrationTokenEndpointAuthMethodClientSecretBasic OAuthClientRegistrationTokenEndpointAuthMethod = "client_secret_basic"
	OAuthClientRegistrationTokenEndpointAuthMethodClientSecretPost  OAuthClientRegistrationTokenEndpointAuthMethod = "client_secret_post"
	OAuthClientRegistrationTokenEndpointAuthMethodNone              OAuthClientRegistrationTokenEndpointAuthMethod = "none"
)

Defines values for OAuthClientRegistrationTokenEndpointAuthMethod.

func (OAuthClientRegistrationTokenEndpointAuthMethod) Valid

Valid indicates whether the value is a known member of the OAuthClientRegistrationTokenEndpointAuthMethod enum.

type OAuthConsentRequest

type OAuthConsentRequest struct {
	// UnderscoreToken Browser CSRF token, alternatively sent using X-CSRF-TOKEN.
	UnderscoreToken *string `json:"_token,omitempty"`

	// AuthToken Single-use token from the consent page, bound to the identity session.
	AuthToken string `json:"auth_token"`
}

OAuthConsentRequest defines model for OAuthConsentRequest.

type OAuthError

type OAuthError struct {
	Error            string `json:"error"`
	ErrorDescription string `json:"error_description"`
}

OAuthError defines model for OAuthError.

type OAuthIntrospection

type OAuthIntrospection struct {
	Active    bool                         `json:"active"`
	Aud       *[]string                    `json:"aud,omitempty"`
	ClientID  *string                      `json:"client_id,omitempty"`
	Exp       *int                         `json:"exp,omitempty"`
	Iat       *int                         `json:"iat,omitempty"`
	Iss       *string                      `json:"iss,omitempty"`
	Jti       *string                      `json:"jti,omitempty"`
	Nbf       *int                         `json:"nbf,omitempty"`
	Scope     *string                      `json:"scope,omitempty"`
	Sub       *string                      `json:"sub,omitempty"`
	TokenType *OAuthIntrospectionTokenType `json:"token_type,omitempty"`
}

OAuthIntrospection Inactive responses contain only active=false. Other fields are present only for an active token when applicable; service tokens have no sub.

type OAuthIntrospectionTokenType

type OAuthIntrospectionTokenType string

OAuthIntrospectionTokenType defines model for OAuthIntrospection.TokenType.

const (
	OAuthIntrospectionTokenTypeBearer OAuthIntrospectionTokenType = "Bearer"
)

Defines values for OAuthIntrospectionTokenType.

func (OAuthIntrospectionTokenType) Valid

Valid indicates whether the value is a known member of the OAuthIntrospectionTokenType enum.

type OAuthLogoutRequest

type OAuthLogoutRequest struct {
	// UnderscoreToken Browser CSRF token, alternatively sent using X-CSRF-TOKEN.
	UnderscoreToken *string `json:"_token,omitempty"`

	// ClientID Client identifier; must agree with a valid ID token hint.
	ClientID *string `json:"client_id,omitempty"`

	// IDTokenHint Previously issued ID token identifying the client and session.
	IDTokenHint *string `json:"id_token_hint,omitempty"`

	// LogoutConfirmation Confirmation token returned by the logout page.
	LogoutConfirmation *string `json:"logout_confirmation,omitempty"`

	// LogoutHint Accepted but currently ignored.
	LogoutHint *string `json:"logout_hint,omitempty"`

	// PostLogoutRedirectURI Must be registered for the identified client.
	PostLogoutRedirectURI *string `json:"post_logout_redirect_uri,omitempty"`

	// State Echoed on an accepted post-logout redirect.
	State *string `json:"state,omitempty"`

	// UILocales Accepted but currently ignored.
	UILocales *string `json:"ui_locales,omitempty"`
}

OAuthLogoutRequest defines model for OAuthLogoutRequest.

type OAuthPresentedToken

type OAuthPresentedToken struct {
	// ClientID Required for form-secret and public-client authentication. Omit when using HTTP Basic.
	ClientID *string `json:"client_id,omitempty"`

	// ClientSecret Required only for client_secret_post. Never combine with HTTP Basic.
	ClientSecret *string `json:"client_secret,omitempty"`
	Token        string  `json:"token"`

	// TokenTypeHint access_token or refresh_token; unrecognized hints are ignored.
	TokenTypeHint *string `json:"token_type_hint,omitempty"`
}

OAuthPresentedToken defines model for OAuthPresentedToken.

type OAuthProtectedResource

type OAuthProtectedResource struct {
	AuthorizationServers   []string                                       `json:"authorization_servers"`
	BearerMethodsSupported []OAuthProtectedResourceBearerMethodsSupported `json:"bearer_methods_supported"`
	Resource               string                                         `json:"resource"`
	ScopesSupported        []string                                       `json:"scopes_supported"`
}

OAuthProtectedResource defines model for OAuthProtectedResource.

type OAuthProtectedResourceBearerMethodsSupported

type OAuthProtectedResourceBearerMethodsSupported string

OAuthProtectedResourceBearerMethodsSupported defines model for OAuthProtectedResource.BearerMethodsSupported.

const (
	Header OAuthProtectedResourceBearerMethodsSupported = "header"
)

Defines values for OAuthProtectedResourceBearerMethodsSupported.

func (OAuthProtectedResourceBearerMethodsSupported) Valid

Valid indicates whether the value is a known member of the OAuthProtectedResourceBearerMethodsSupported enum.

type OAuthRegisteredClient

type OAuthRegisteredClient struct {
	BackchannelLogoutSessionRequired *bool `json:"backchannel_logout_session_required,omitempty"`

	// BackchannelLogoutURI HTTPS URI without a fragment.
	BackchannelLogoutURI *string `json:"backchannel_logout_uri,omitempty"`
	ClientID             string  `json:"client_id"`
	ClientIDIssuedAt     int     `json:"client_id_issued_at"`
	ClientName           string  `json:"client_name"`

	// ClientSecret Returned only for a confidential client; store securely.
	ClientSecret *string `json:"client_secret,omitempty"`

	// ClientSecretExpiresAt Returned with a client secret; zero means it does not expire.
	ClientSecretExpiresAt *OAuthRegisteredClientClientSecretExpiresAt `json:"client_secret_expires_at,omitempty"`

	// GrantTypes Must include authorization_code.
	GrantTypes             []OAuthRegisteredClientGrantTypes    `json:"grant_types"`
	PostLogoutRedirectUris []string                             `json:"post_logout_redirect_uris"`
	RedirectUris           []string                             `json:"redirect_uris"`
	ResponseTypes          []OAuthRegisteredClientResponseTypes `json:"response_types"`

	// Scope Assigned scopes, when the registered client has a concrete nonempty scope set.
	Scope                   *string                                      `json:"scope,omitempty"`
	TokenEndpointAuthMethod OAuthRegisteredClientTokenEndpointAuthMethod `json:"token_endpoint_auth_method"`
}

OAuthRegisteredClient defines model for OAuthRegisteredClient.

type OAuthRegisteredClientClientSecretExpiresAt

type OAuthRegisteredClientClientSecretExpiresAt int

OAuthRegisteredClientClientSecretExpiresAt Returned with a client secret; zero means it does not expire.

Defines values for OAuthRegisteredClientClientSecretExpiresAt.

func (OAuthRegisteredClientClientSecretExpiresAt) Valid

Valid indicates whether the value is a known member of the OAuthRegisteredClientClientSecretExpiresAt enum.

type OAuthRegisteredClientGrantTypes

type OAuthRegisteredClientGrantTypes string

OAuthRegisteredClientGrantTypes defines model for OAuthRegisteredClient.GrantTypes.

const (
	OAuthRegisteredClientGrantTypesAuthorizationCode OAuthRegisteredClientGrantTypes = "authorization_code"
	OAuthRegisteredClientGrantTypesRefreshToken      OAuthRegisteredClientGrantTypes = "refresh_token"
)

Defines values for OAuthRegisteredClientGrantTypes.

func (OAuthRegisteredClientGrantTypes) Valid

Valid indicates whether the value is a known member of the OAuthRegisteredClientGrantTypes enum.

type OAuthRegisteredClientResponseTypes

type OAuthRegisteredClientResponseTypes string

OAuthRegisteredClientResponseTypes defines model for OAuthRegisteredClient.ResponseTypes.

const (
	OAuthRegisteredClientResponseTypesCode OAuthRegisteredClientResponseTypes = "code"
)

Defines values for OAuthRegisteredClientResponseTypes.

func (OAuthRegisteredClientResponseTypes) Valid

Valid indicates whether the value is a known member of the OAuthRegisteredClientResponseTypes enum.

type OAuthRegisteredClientTokenEndpointAuthMethod

type OAuthRegisteredClientTokenEndpointAuthMethod string

OAuthRegisteredClientTokenEndpointAuthMethod defines model for OAuthRegisteredClient.TokenEndpointAuthMethod.

const (
	OAuthRegisteredClientTokenEndpointAuthMethodClientSecretBasic OAuthRegisteredClientTokenEndpointAuthMethod = "client_secret_basic"
	OAuthRegisteredClientTokenEndpointAuthMethodClientSecretPost  OAuthRegisteredClientTokenEndpointAuthMethod = "client_secret_post"
	OAuthRegisteredClientTokenEndpointAuthMethodNone              OAuthRegisteredClientTokenEndpointAuthMethod = "none"
)

Defines values for OAuthRegisteredClientTokenEndpointAuthMethod.

func (OAuthRegisteredClientTokenEndpointAuthMethod) Valid

Valid indicates whether the value is a known member of the OAuthRegisteredClientTokenEndpointAuthMethod enum.

type OAuthTokenRequest

type OAuthTokenRequest struct {
	// contains filtered or unexported fields
}

OAuthTokenRequest defines model for OAuthTokenRequest.

func (OAuthTokenRequest) AsAuthorizationCodeRequest

func (t OAuthTokenRequest) AsAuthorizationCodeRequest() (AuthorizationCodeRequest, error)

AsAuthorizationCodeRequest returns the union data inside the OAuthTokenRequest as a AuthorizationCodeRequest

func (OAuthTokenRequest) AsClientCredentialsRequest

func (t OAuthTokenRequest) AsClientCredentialsRequest() (ClientCredentialsRequest, error)

AsClientCredentialsRequest returns the union data inside the OAuthTokenRequest as a ClientCredentialsRequest

func (OAuthTokenRequest) AsRefreshTokenRequest

func (t OAuthTokenRequest) AsRefreshTokenRequest() (RefreshTokenRequest, error)

AsRefreshTokenRequest returns the union data inside the OAuthTokenRequest as a RefreshTokenRequest

func (OAuthTokenRequest) AsTokenExchangeRequest

func (t OAuthTokenRequest) AsTokenExchangeRequest() (TokenExchangeRequest, error)

AsTokenExchangeRequest returns the union data inside the OAuthTokenRequest as a TokenExchangeRequest

func (OAuthTokenRequest) Discriminator

func (t OAuthTokenRequest) Discriminator() (string, error)

func (*OAuthTokenRequest) FromAuthorizationCodeRequest

func (t *OAuthTokenRequest) FromAuthorizationCodeRequest(v AuthorizationCodeRequest) error

FromAuthorizationCodeRequest overwrites any union data inside the OAuthTokenRequest as the provided AuthorizationCodeRequest

func (*OAuthTokenRequest) FromClientCredentialsRequest

func (t *OAuthTokenRequest) FromClientCredentialsRequest(v ClientCredentialsRequest) error

FromClientCredentialsRequest overwrites any union data inside the OAuthTokenRequest as the provided ClientCredentialsRequest

func (*OAuthTokenRequest) FromRefreshTokenRequest

func (t *OAuthTokenRequest) FromRefreshTokenRequest(v RefreshTokenRequest) error

FromRefreshTokenRequest overwrites any union data inside the OAuthTokenRequest as the provided RefreshTokenRequest

func (*OAuthTokenRequest) FromTokenExchangeRequest

func (t *OAuthTokenRequest) FromTokenExchangeRequest(v TokenExchangeRequest) error

FromTokenExchangeRequest overwrites any union data inside the OAuthTokenRequest as the provided TokenExchangeRequest

func (OAuthTokenRequest) MarshalJSON

func (t OAuthTokenRequest) MarshalJSON() ([]byte, error)

func (*OAuthTokenRequest) MergeAuthorizationCodeRequest

func (t *OAuthTokenRequest) MergeAuthorizationCodeRequest(v AuthorizationCodeRequest) error

MergeAuthorizationCodeRequest performs a merge with any union data inside the OAuthTokenRequest, using the provided AuthorizationCodeRequest

func (*OAuthTokenRequest) MergeClientCredentialsRequest

func (t *OAuthTokenRequest) MergeClientCredentialsRequest(v ClientCredentialsRequest) error

MergeClientCredentialsRequest performs a merge with any union data inside the OAuthTokenRequest, using the provided ClientCredentialsRequest

func (*OAuthTokenRequest) MergeRefreshTokenRequest

func (t *OAuthTokenRequest) MergeRefreshTokenRequest(v RefreshTokenRequest) error

MergeRefreshTokenRequest performs a merge with any union data inside the OAuthTokenRequest, using the provided RefreshTokenRequest

func (*OAuthTokenRequest) MergeTokenExchangeRequest

func (t *OAuthTokenRequest) MergeTokenExchangeRequest(v TokenExchangeRequest) error

MergeTokenExchangeRequest performs a merge with any union data inside the OAuthTokenRequest, using the provided TokenExchangeRequest

func (*OAuthTokenRequest) UnmarshalJSON

func (t *OAuthTokenRequest) UnmarshalJSON(b []byte) error

func (OAuthTokenRequest) ValueByDiscriminator

func (t OAuthTokenRequest) ValueByDiscriminator() (interface{}, error)

type OAuthTokenResponse

type OAuthTokenResponse struct {
	AccessToken string `json:"access_token"`

	// ExpiresIn Access-token lifetime in seconds.
	ExpiresIn int `json:"expires_in"`

	// IDToken Present when the grant issues an OpenID Connect ID token.
	IDToken *string `json:"id_token,omitempty"`

	// IssuedTokenType Present for token exchange.
	IssuedTokenType *OAuthTokenResponseIssuedTokenType `json:"issued_token_type,omitempty"`

	// RefreshToken Present when a refresh token is issued or rotated.
	RefreshToken *string `json:"refresh_token,omitempty"`

	// Scope Space-delimited granted scopes; omitted when empty.
	Scope                *string                     `json:"scope,omitempty"`
	TokenType            OAuthTokenResponseTokenType `json:"token_type"`
	AdditionalProperties map[string]interface{}      `json:"-"`
}

OAuthTokenResponse defines model for OAuthTokenResponse.

func (OAuthTokenResponse) Get

func (a OAuthTokenResponse) Get(fieldName string) (value interface{}, found bool)

Getter for additional properties for OAuthTokenResponse. Returns the specified element and whether it was found

func (OAuthTokenResponse) MarshalJSON

func (a OAuthTokenResponse) MarshalJSON() ([]byte, error)

Override default JSON handling for OAuthTokenResponse to handle AdditionalProperties

func (*OAuthTokenResponse) Set

func (a *OAuthTokenResponse) Set(fieldName string, value interface{})

Setter for additional properties for OAuthTokenResponse

func (*OAuthTokenResponse) UnmarshalJSON

func (a *OAuthTokenResponse) UnmarshalJSON(b []byte) error

Override default JSON handling for OAuthTokenResponse to handle AdditionalProperties

type OAuthTokenResponseIssuedTokenType

type OAuthTokenResponseIssuedTokenType string

OAuthTokenResponseIssuedTokenType Present for token exchange.

const (
	OAuthTokenResponseIssuedTokenTypeUrnIetfParamsOauthTokenTypeAccessToken OAuthTokenResponseIssuedTokenType = "urn:ietf:params:oauth:token-type:access_token"
)

Defines values for OAuthTokenResponseIssuedTokenType.

func (OAuthTokenResponseIssuedTokenType) Valid

Valid indicates whether the value is a known member of the OAuthTokenResponseIssuedTokenType enum.

type OAuthTokenResponseTokenType

type OAuthTokenResponseTokenType string

OAuthTokenResponseTokenType defines model for OAuthTokenResponse.TokenType.

const (
	OAuthTokenResponseTokenTypeBearer OAuthTokenResponseTokenType = "Bearer"
)

Defines values for OAuthTokenResponseTokenType.

func (OAuthTokenResponseTokenType) Valid

Valid indicates whether the value is a known member of the OAuthTokenResponseTokenType enum.

type OidcJwks

type OidcJwks struct {
	Keys []struct {
		Alg OidcJwksKeysAlg `json:"alg"`

		// E Base64url-encoded RSA exponent.
		E   string          `json:"e"`
		Kid string          `json:"kid"`
		Kty OidcJwksKeysKty `json:"kty"`

		// N Base64url-encoded RSA modulus.
		N   string          `json:"n"`
		Use OidcJwksKeysUse `json:"use"`
	} `json:"keys"`
}

OidcJwks defines model for OidcJwks.

type OidcJwksKeysAlg

type OidcJwksKeysAlg string

OidcJwksKeysAlg defines model for OidcJwks.Keys.Alg.

const (
	RS256 OidcJwksKeysAlg = "RS256"
)

Defines values for OidcJwksKeysAlg.

func (OidcJwksKeysAlg) Valid

func (e OidcJwksKeysAlg) Valid() bool

Valid indicates whether the value is a known member of the OidcJwksKeysAlg enum.

type OidcJwksKeysKty

type OidcJwksKeysKty string

OidcJwksKeysKty defines model for OidcJwks.Keys.Kty.

const (
	RSA OidcJwksKeysKty = "RSA"
)

Defines values for OidcJwksKeysKty.

func (OidcJwksKeysKty) Valid

func (e OidcJwksKeysKty) Valid() bool

Valid indicates whether the value is a known member of the OidcJwksKeysKty enum.

type OidcJwksKeysUse

type OidcJwksKeysUse string

OidcJwksKeysUse defines model for OidcJwks.Keys.Use.

const (
	Sig OidcJwksKeysUse = "sig"
)

Defines values for OidcJwksKeysUse.

func (OidcJwksKeysUse) Valid

func (e OidcJwksKeysUse) Valid() bool

Valid indicates whether the value is a known member of the OidcJwksKeysUse enum.

type OidcProviderMetadata

type OidcProviderMetadata struct {
	AcrValuesSupported                         []string                                                       `json:"acr_values_supported"`
	AuthorizationEndpoint                      string                                                         `json:"authorization_endpoint"`
	AuthorizationResponseIssParameterSupported OidcProviderMetadataAuthorizationResponseIssParameterSupported `json:"authorization_response_iss_parameter_supported"`
	BackchannelLogoutSessionSupported          OidcProviderMetadataBackchannelLogoutSessionSupported          `json:"backchannel_logout_session_supported"`
	BackchannelLogoutSupported                 OidcProviderMetadataBackchannelLogoutSupported                 `json:"backchannel_logout_supported"`
	ClaimsParameterSupported                   OidcProviderMetadataClaimsParameterSupported                   `json:"claims_parameter_supported"`
	ClaimsSupported                            []string                                                       `json:"claims_supported"`
	CodeChallengeMethodsSupported              []string                                                       `json:"code_challenge_methods_supported"`
	EndSessionEndpoint                         *string                                                        `json:"end_session_endpoint,omitempty"`
	GrantTypesSupported                        []string                                                       `json:"grant_types_supported"`
	IDTokenSigningAlgValuesSupported           []string                                                       `json:"id_token_signing_alg_values_supported"`
	IntrospectionEndpoint                      *string                                                        `json:"introspection_endpoint,omitempty"`
	IntrospectionEndpointAuthMethodsSupported  *[]string                                                      `json:"introspection_endpoint_auth_methods_supported,omitempty"`
	Issuer                                     string                                                         `json:"issuer"`
	JwksURI                                    string                                                         `json:"jwks_uri"`
	RegistrationEndpoint                       *string                                                        `json:"registration_endpoint,omitempty"`
	RequestParameterSupported                  OidcProviderMetadataRequestParameterSupported                  `json:"request_parameter_supported"`
	RequestURIParameterSupported               OidcProviderMetadataRequestURIParameterSupported               `json:"request_uri_parameter_supported"`
	ResponseModesSupported                     []string                                                       `json:"response_modes_supported"`
	ResponseTypesSupported                     []string                                                       `json:"response_types_supported"`
	RevocationEndpoint                         *string                                                        `json:"revocation_endpoint,omitempty"`
	RevocationEndpointAuthMethodsSupported     *[]string                                                      `json:"revocation_endpoint_auth_methods_supported,omitempty"`
	ScopesSupported                            []string                                                       `json:"scopes_supported"`
	SubjectTypesSupported                      []string                                                       `json:"subject_types_supported"`
	TokenEndpoint                              string                                                         `json:"token_endpoint"`
	TokenEndpointAuthMethodsSupported          []string                                                       `json:"token_endpoint_auth_methods_supported"`
	UserinfoEndpoint                           *string                                                        `json:"userinfo_endpoint,omitempty"`
}

OidcProviderMetadata defines model for OidcProviderMetadata.

type OidcProviderMetadataAuthorizationResponseIssParameterSupported

type OidcProviderMetadataAuthorizationResponseIssParameterSupported bool

OidcProviderMetadataAuthorizationResponseIssParameterSupported defines model for OidcProviderMetadata.AuthorizationResponseIssParameterSupported.

const (
	OidcProviderMetadataAuthorizationResponseIssParameterSupportedTrue OidcProviderMetadataAuthorizationResponseIssParameterSupported = true
)

Defines values for OidcProviderMetadataAuthorizationResponseIssParameterSupported.

func (OidcProviderMetadataAuthorizationResponseIssParameterSupported) Valid

Valid indicates whether the value is a known member of the OidcProviderMetadataAuthorizationResponseIssParameterSupported enum.

type OidcProviderMetadataBackchannelLogoutSessionSupported

type OidcProviderMetadataBackchannelLogoutSessionSupported bool

OidcProviderMetadataBackchannelLogoutSessionSupported defines model for OidcProviderMetadata.BackchannelLogoutSessionSupported.

const (
	OidcProviderMetadataBackchannelLogoutSessionSupportedTrue OidcProviderMetadataBackchannelLogoutSessionSupported = true
)

Defines values for OidcProviderMetadataBackchannelLogoutSessionSupported.

func (OidcProviderMetadataBackchannelLogoutSessionSupported) Valid

Valid indicates whether the value is a known member of the OidcProviderMetadataBackchannelLogoutSessionSupported enum.

type OidcProviderMetadataBackchannelLogoutSupported

type OidcProviderMetadataBackchannelLogoutSupported bool

OidcProviderMetadataBackchannelLogoutSupported defines model for OidcProviderMetadata.BackchannelLogoutSupported.

const (
	OidcProviderMetadataBackchannelLogoutSupportedTrue OidcProviderMetadataBackchannelLogoutSupported = true
)

Defines values for OidcProviderMetadataBackchannelLogoutSupported.

func (OidcProviderMetadataBackchannelLogoutSupported) Valid

Valid indicates whether the value is a known member of the OidcProviderMetadataBackchannelLogoutSupported enum.

type OidcProviderMetadataClaimsParameterSupported

type OidcProviderMetadataClaimsParameterSupported bool

OidcProviderMetadataClaimsParameterSupported defines model for OidcProviderMetadata.ClaimsParameterSupported.

const (
	OidcProviderMetadataClaimsParameterSupportedFalse OidcProviderMetadataClaimsParameterSupported = false
)

Defines values for OidcProviderMetadataClaimsParameterSupported.

func (OidcProviderMetadataClaimsParameterSupported) Valid

Valid indicates whether the value is a known member of the OidcProviderMetadataClaimsParameterSupported enum.

type OidcProviderMetadataRequestParameterSupported

type OidcProviderMetadataRequestParameterSupported bool

OidcProviderMetadataRequestParameterSupported defines model for OidcProviderMetadata.RequestParameterSupported.

const (
	OidcProviderMetadataRequestParameterSupportedFalse OidcProviderMetadataRequestParameterSupported = false
)

Defines values for OidcProviderMetadataRequestParameterSupported.

func (OidcProviderMetadataRequestParameterSupported) Valid

Valid indicates whether the value is a known member of the OidcProviderMetadataRequestParameterSupported enum.

type OidcProviderMetadataRequestURIParameterSupported

type OidcProviderMetadataRequestURIParameterSupported bool

OidcProviderMetadataRequestURIParameterSupported defines model for OidcProviderMetadata.RequestURIParameterSupported.

const (
	OidcProviderMetadataRequestURIParameterSupportedFalse OidcProviderMetadataRequestURIParameterSupported = false
)

Defines values for OidcProviderMetadataRequestURIParameterSupported.

func (OidcProviderMetadataRequestURIParameterSupported) Valid

Valid indicates whether the value is a known member of the OidcProviderMetadataRequestURIParameterSupported enum.

type OidcUserinfo

type OidcUserinfo struct {
	Email             *openapi_types.Email `json:"email,omitempty"`
	EmailVerified     *bool                `json:"email_verified,omitempty"`
	FamilyName        *string              `json:"family_name,omitempty"`
	GivenName         *string              `json:"given_name,omitempty"`
	Name              *string              `json:"name,omitempty"`
	Picture           *string              `json:"picture,omitempty"`
	PreferredUsername *string              `json:"preferred_username,omitempty"`

	// Sub Stable subject identifier in this realm.
	Sub                  string                 `json:"sub"`
	AdditionalProperties map[string]interface{} `json:"-"`
}

OidcUserinfo Only sub is unconditional. Profile, email and custom claims depend on scopes and the configured resolvers.

func (OidcUserinfo) Get

func (a OidcUserinfo) Get(fieldName string) (value interface{}, found bool)

Getter for additional properties for OidcUserinfo. Returns the specified element and whether it was found

func (OidcUserinfo) MarshalJSON

func (a OidcUserinfo) MarshalJSON() ([]byte, error)

Override default JSON handling for OidcUserinfo to handle AdditionalProperties

func (*OidcUserinfo) Set

func (a *OidcUserinfo) Set(fieldName string, value interface{})

Setter for additional properties for OidcUserinfo

func (*OidcUserinfo) UnmarshalJSON

func (a *OidcUserinfo) UnmarshalJSON(b []byte) error

Override default JSON handling for OidcUserinfo to handle AdditionalProperties

type RefreshTokenRequest

type RefreshTokenRequest struct {
	// ClientID Required for form-secret and public-client authentication. Omit when using HTTP Basic.
	ClientID *string `json:"client_id,omitempty"`

	// ClientSecret Required only for client_secret_post. Never combine with HTTP Basic.
	ClientSecret *string                      `json:"client_secret,omitempty"`
	GrantType    RefreshTokenRequestGrantType `json:"grant_type"`
	RefreshToken string                       `json:"refresh_token"`

	// Resource Absolute protected-resource URI without a fragment, or an array of such URIs using resource[] fields. Authorization and client-credentials requests default to the realm audience. Code and refresh grants preserve the original audiences when omitted, or narrow them when supplied.
	Resource *RefreshTokenRequest_Resource `json:"resource,omitempty"`

	// Scope Space-delimited scopes for client credentials, refresh or exchange. Refresh and exchange can only narrow granted scopes; authorization-code redemption uses the approved scopes.
	Scope *string `json:"scope,omitempty"`
}

RefreshTokenRequest defines model for RefreshTokenRequest.

type RefreshTokenRequestGrantType

type RefreshTokenRequestGrantType string

RefreshTokenRequestGrantType defines model for RefreshTokenRequest.GrantType.

const (
	RefreshTokenRequestGrantTypeRefreshToken RefreshTokenRequestGrantType = "refresh_token"
)

Defines values for RefreshTokenRequestGrantType.

func (RefreshTokenRequestGrantType) Valid

Valid indicates whether the value is a known member of the RefreshTokenRequestGrantType enum.

type RefreshTokenRequestResource0

type RefreshTokenRequestResource0 = string

RefreshTokenRequestResource0 defines model for RefreshTokenRequest.Resource.0.

type RefreshTokenRequestResource1

type RefreshTokenRequestResource1 = []string

RefreshTokenRequestResource1 defines model for RefreshTokenRequest.Resource.1.

type RefreshTokenRequest_Resource

type RefreshTokenRequest_Resource struct {
	// contains filtered or unexported fields
}

RefreshTokenRequest_Resource Absolute protected-resource URI without a fragment, or an array of such URIs using resource[] fields. Authorization and client-credentials requests default to the realm audience. Code and refresh grants preserve the original audiences when omitted, or narrow them when supplied.

func (RefreshTokenRequest_Resource) AsRefreshTokenRequestResource0

func (t RefreshTokenRequest_Resource) AsRefreshTokenRequestResource0() (RefreshTokenRequestResource0, error)

AsRefreshTokenRequestResource0 returns the union data inside the RefreshTokenRequest_Resource as a RefreshTokenRequestResource0

func (RefreshTokenRequest_Resource) AsRefreshTokenRequestResource1

func (t RefreshTokenRequest_Resource) AsRefreshTokenRequestResource1() (RefreshTokenRequestResource1, error)

AsRefreshTokenRequestResource1 returns the union data inside the RefreshTokenRequest_Resource as a RefreshTokenRequestResource1

func (*RefreshTokenRequest_Resource) FromRefreshTokenRequestResource0

func (t *RefreshTokenRequest_Resource) FromRefreshTokenRequestResource0(v RefreshTokenRequestResource0) error

FromRefreshTokenRequestResource0 overwrites any union data inside the RefreshTokenRequest_Resource as the provided RefreshTokenRequestResource0

func (*RefreshTokenRequest_Resource) FromRefreshTokenRequestResource1

func (t *RefreshTokenRequest_Resource) FromRefreshTokenRequestResource1(v RefreshTokenRequestResource1) error

FromRefreshTokenRequestResource1 overwrites any union data inside the RefreshTokenRequest_Resource as the provided RefreshTokenRequestResource1

func (RefreshTokenRequest_Resource) MarshalJSON

func (t RefreshTokenRequest_Resource) MarshalJSON() ([]byte, error)

func (*RefreshTokenRequest_Resource) MergeRefreshTokenRequestResource0

func (t *RefreshTokenRequest_Resource) MergeRefreshTokenRequestResource0(v RefreshTokenRequestResource0) error

MergeRefreshTokenRequestResource0 performs a merge with any union data inside the RefreshTokenRequest_Resource, using the provided RefreshTokenRequestResource0

func (*RefreshTokenRequest_Resource) MergeRefreshTokenRequestResource1

func (t *RefreshTokenRequest_Resource) MergeRefreshTokenRequestResource1(v RefreshTokenRequestResource1) error

MergeRefreshTokenRequestResource1 performs a merge with any union data inside the RefreshTokenRequest_Resource, using the provided RefreshTokenRequestResource1

func (*RefreshTokenRequest_Resource) UnmarshalJSON

func (t *RefreshTokenRequest_Resource) UnmarshalJSON(b []byte) error

type RegisterClientJSONRequestBody

type RegisterClientJSONRequestBody = OAuthClientRegistration

RegisterClientJSONRequestBody defines body for RegisterClient for application/json ContentType.

type RequestEditorFn

type RequestEditorFn func(ctx context.Context, req *http.Request) error

RequestEditorFn is the function signature for the RequestEditor callback function

type Response

type Response = lock.Response

type RevokeTokenFormdataRequestBody

type RevokeTokenFormdataRequestBody = OAuthPresentedToken

RevokeTokenFormdataRequestBody defines body for RevokeToken for application/x-www-form-urlencoded ContentType.

type SubmitAuthorizationFormdataRequestBody

type SubmitAuthorizationFormdataRequestBody = OAuthAuthorizationRequest

SubmitAuthorizationFormdataRequestBody defines body for SubmitAuthorization for application/x-www-form-urlencoded ContentType.

type SubmitLogoutFormdataRequestBody

type SubmitLogoutFormdataRequestBody = OAuthLogoutRequest

SubmitLogoutFormdataRequestBody defines body for SubmitLogout for application/x-www-form-urlencoded ContentType.

type TokenExchangeRequest

type TokenExchangeRequest struct {
	// Audience Required unless resource is supplied; when both are supplied, they must match.
	Audience *string `json:"audience,omitempty"`

	// ClientID Required for form-secret and public-client authentication. Omit when using HTTP Basic.
	ClientID *string `json:"client_id,omitempty"`

	// ClientSecret Required only for client_secret_post. Never combine with HTTP Basic.
	ClientSecret       *string                                 `json:"client_secret,omitempty"`
	GrantType          TokenExchangeRequestGrantType           `json:"grant_type"`
	RequestedTokenType *TokenExchangeRequestRequestedTokenType `json:"requested_token_type,omitempty"`

	// Resource Single target audience. Must agree with audience when both are supplied.
	Resource *string `json:"resource,omitempty"`

	// Scope Space-delimited scopes for client credentials, refresh or exchange. Refresh and exchange can only narrow granted scopes; authorization-code redemption uses the approved scopes.
	Scope            *string                              `json:"scope,omitempty"`
	SubjectToken     string                               `json:"subject_token"`
	SubjectTokenType TokenExchangeRequestSubjectTokenType `json:"subject_token_type"`
	// contains filtered or unexported fields
}

TokenExchangeRequest actor_token and actor_token_type are unsupported. Additional grant parameters may be consumed by configured token-exchange extensions.

func (TokenExchangeRequest) AsTokenExchangeRequest0

func (t TokenExchangeRequest) AsTokenExchangeRequest0() (TokenExchangeRequest0, error)

AsTokenExchangeRequest0 returns the union data inside the TokenExchangeRequest as a TokenExchangeRequest0

func (TokenExchangeRequest) AsTokenExchangeRequest1

func (t TokenExchangeRequest) AsTokenExchangeRequest1() (TokenExchangeRequest1, error)

AsTokenExchangeRequest1 returns the union data inside the TokenExchangeRequest as a TokenExchangeRequest1

func (*TokenExchangeRequest) FromTokenExchangeRequest0

func (t *TokenExchangeRequest) FromTokenExchangeRequest0(v TokenExchangeRequest0) error

FromTokenExchangeRequest0 overwrites any union data inside the TokenExchangeRequest as the provided TokenExchangeRequest0

func (*TokenExchangeRequest) FromTokenExchangeRequest1

func (t *TokenExchangeRequest) FromTokenExchangeRequest1(v TokenExchangeRequest1) error

FromTokenExchangeRequest1 overwrites any union data inside the TokenExchangeRequest as the provided TokenExchangeRequest1

func (TokenExchangeRequest) MarshalJSON

func (t TokenExchangeRequest) MarshalJSON() ([]byte, error)

func (*TokenExchangeRequest) MergeTokenExchangeRequest0

func (t *TokenExchangeRequest) MergeTokenExchangeRequest0(v TokenExchangeRequest0) error

MergeTokenExchangeRequest0 performs a merge with any union data inside the TokenExchangeRequest, using the provided TokenExchangeRequest0

func (*TokenExchangeRequest) MergeTokenExchangeRequest1

func (t *TokenExchangeRequest) MergeTokenExchangeRequest1(v TokenExchangeRequest1) error

MergeTokenExchangeRequest1 performs a merge with any union data inside the TokenExchangeRequest, using the provided TokenExchangeRequest1

func (*TokenExchangeRequest) UnmarshalJSON

func (t *TokenExchangeRequest) UnmarshalJSON(b []byte) error

type TokenExchangeRequest0

type TokenExchangeRequest0 = interface{}

TokenExchangeRequest0 defines model for TokenExchangeRequest.0.

type TokenExchangeRequest1

type TokenExchangeRequest1 = interface{}

TokenExchangeRequest1 defines model for TokenExchangeRequest.1.

type TokenExchangeRequestGrantType

type TokenExchangeRequestGrantType string

TokenExchangeRequestGrantType defines model for TokenExchangeRequest.GrantType.

const (
	UrnIetfParamsOauthGrantTypeTokenExchange TokenExchangeRequestGrantType = "urn:ietf:params:oauth:grant-type:token-exchange"
)

Defines values for TokenExchangeRequestGrantType.

func (TokenExchangeRequestGrantType) Valid

Valid indicates whether the value is a known member of the TokenExchangeRequestGrantType enum.

type TokenExchangeRequestRequestedTokenType

type TokenExchangeRequestRequestedTokenType string

TokenExchangeRequestRequestedTokenType defines model for TokenExchangeRequest.RequestedTokenType.

const (
	TokenExchangeRequestRequestedTokenTypeUrnIetfParamsOauthTokenTypeAccessToken TokenExchangeRequestRequestedTokenType = "urn:ietf:params:oauth:token-type:access_token"
)

Defines values for TokenExchangeRequestRequestedTokenType.

func (TokenExchangeRequestRequestedTokenType) Valid

Valid indicates whether the value is a known member of the TokenExchangeRequestRequestedTokenType enum.

type TokenExchangeRequestSubjectTokenType

type TokenExchangeRequestSubjectTokenType string

TokenExchangeRequestSubjectTokenType defines model for TokenExchangeRequest.SubjectTokenType.

const (
	TokenExchangeRequestSubjectTokenTypeUrnIetfParamsOauthTokenTypeAccessToken TokenExchangeRequestSubjectTokenType = "urn:ietf:params:oauth:token-type:access_token"
)

Defines values for TokenExchangeRequestSubjectTokenType.

func (TokenExchangeRequestSubjectTokenType) Valid

Valid indicates whether the value is a known member of the TokenExchangeRequestSubjectTokenType enum.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL