mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-02 03:22:09 +00:00
pkg/security no longer contains SQL. Every provider calls a store interface
from lookup, implemented by a procedure backend (Postgres stored procedures,
the default there) and a direct backend (dialect-driven SQL for postgres,
sqlite, mysql and mssql with configurable table and column names).
- add sectypes, lookup, lookup/{dialect,procedure,direct,backends,ddl,conformance}
- split totp and providers sub packages out of the core package
- replace SQLNames/TableNames/QueryMode with lookup.Config (see breaking_changes.md)
- direct backend now covers column/row security and API-key login
- move txsettings SQL to lookup.ApplyTxSettings; remove password.go
- move schema scripts under lookup/, add reference DDL per dialect
- add a shared conformance suite; run it on sqlite, and on Postgres in a
podman/docker container (RESOLVESPEC_TEST_CONTAINERS=1)
- fix procedure schema bugs found on real Postgres: duplicate p_data
parameter, JSON null arrays, expires_at timezone casts, passkey list
GROUP BY, missing resolvespec_passkey_login; accept zone-less timestamps
36 lines
1.4 KiB
Go
36 lines
1.4 KiB
Go
package security
|
|
|
|
import (
|
|
"context"
|
|
)
|
|
|
|
// OAuthRegisterClient persists an OAuth2 client registration.
|
|
func (a *DatabaseAuthenticator) OAuthRegisterClient(ctx context.Context, client *OAuthServerClient) (*OAuthServerClient, error) {
|
|
return a.src.get().OAuthClient.RegisterClient(ctx, client)
|
|
}
|
|
|
|
// OAuthGetClient retrieves a registered client by ID.
|
|
func (a *DatabaseAuthenticator) OAuthGetClient(ctx context.Context, clientID string) (*OAuthServerClient, error) {
|
|
return a.src.get().OAuthClient.GetClient(ctx, clientID)
|
|
}
|
|
|
|
// OAuthSaveCode persists an authorization code.
|
|
func (a *DatabaseAuthenticator) OAuthSaveCode(ctx context.Context, code *OAuthCode) error {
|
|
return a.src.get().OAuthClient.SaveCode(ctx, code)
|
|
}
|
|
|
|
// OAuthExchangeCode retrieves and deletes an authorization code (single use).
|
|
func (a *DatabaseAuthenticator) OAuthExchangeCode(ctx context.Context, code string) (*OAuthCode, error) {
|
|
return a.src.get().OAuthClient.ExchangeCode(ctx, code)
|
|
}
|
|
|
|
// OAuthIntrospectToken validates a token and returns its metadata (RFC 7662).
|
|
func (a *DatabaseAuthenticator) OAuthIntrospectToken(ctx context.Context, token string) (*OAuthTokenInfo, error) {
|
|
return a.src.get().OAuthClient.Introspect(ctx, token)
|
|
}
|
|
|
|
// OAuthRevokeToken revokes a token by deleting the session (RFC 7009).
|
|
func (a *DatabaseAuthenticator) OAuthRevokeToken(ctx context.Context, token string) error {
|
|
return a.src.get().OAuthClient.Revoke(ctx, token)
|
|
}
|