mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-05 13:01:58 +00:00
feat(security): full OAuth 2.1 / OpenID Connect server and OIDC relying-party client
Authorization server: consent and scopes, OIDC (nonce, auth_time, acr, sid, at_hash, signed userinfo, RP-initiated and back-channel logout), managed refresh tokens with rotation and reuse detection, RFC 9068 JWT access tokens, DPoP, PAR, device grant, token exchange, private_key_jwt, RFC 7591/7592 registration, RFC 9207 iss, signing keyring with rotation. State is DB-backed through a new lookup.OAuthGrantStore (procedure and direct backends, four dialect DDLs, conformance cases). Client side: WithOIDC discovery, PKCE, nonce, id_token validation, OAuth2LogoutURL. PeekRefresh now returns already rotated tokens so RotateRefresh can detect reuse. Docs: OAUTH2_SERVER.md, oauth2_full_example.go, breaking_changes.md step 8.
This commit is contained in:
@@ -62,6 +62,10 @@ type OAuthClientStore interface {
|
||||
ExchangeCode(ctx context.Context, code string) (*sectypes.OAuthCode, error)
|
||||
Introspect(ctx context.Context, token string) (*sectypes.OAuthTokenInfo, error)
|
||||
Revoke(ctx context.Context, token string) error
|
||||
// UpdateClient rewrites the registration fields of an existing client (RFC 7592).
|
||||
UpdateClient(ctx context.Context, client *sectypes.OAuthServerClient) error
|
||||
// DeleteClient deactivates a client.
|
||||
DeleteClient(ctx context.Context, clientID string) error
|
||||
}
|
||||
|
||||
// OAuthSession is the session row written after an OAuth2 client login.
|
||||
@@ -147,6 +151,7 @@ type Provider struct {
|
||||
Keys KeyStore
|
||||
OAuthClient OAuthClientStore
|
||||
OAuthUser OAuthUserStore
|
||||
OAuthGrant OAuthGrantStore
|
||||
Passkey PasskeyStore
|
||||
TOTP TOTPStore
|
||||
Policy PolicyStore
|
||||
|
||||
Reference in New Issue
Block a user