authentification OpenID Connect (Keycloak) : flux authorization code, state signé, validation du token ID via JWKS, provisioning automatique des utilisateurs
This commit is contained in:
1 parent
51bbb45b32
commit
bedb6c98e7
15 files changed
+1057
-23
No files matched your search
@@ -9,10 +9,12 @@ import (
|
||||
)
|
||||
|
||||
type Credentials struct {
|
||||
Method string // "password" ou "oidc"
|
||||
Email string
|
||||
Password string
|
||||
OIDCCode string
|
||||
Method string // "password" ou "oidc"
|
||||
Email string
|
||||
Password string
|
||||
OIDCCode string
|
||||
OIDCState string
|
||||
RedirectURI string
|
||||
}
|
||||
|
||||
type Registration struct {
|
||||
@@ -45,6 +47,15 @@ type Authenticator interface {
|
||||
type TokenManager interface {
|
||||
GenerateAccessToken(user *domain.User) (string, time.Time, error)
|
||||
GenerateRefreshToken(userID string) (string, time.Time, error)
|
||||
GenerateStateToken(data string) (string, error)
|
||||
ParseStateToken(state string) (string, error)
|
||||
ParseAndValidate(tokenString string) (*domain.User, error)
|
||||
TokenMiddleware(next echo.HandlerFunc) echo.HandlerFunc
|
||||
}
|
||||
|
||||
// OIDCManager est le port implémenté par l'adaptateur OpenID Connect.
|
||||
// Il gère la redirection vers le fournisseur et l'échange du code d'autorisation.
|
||||
type OIDCManager interface {
|
||||
AuthorizeURL(ctx context.Context, provider *domain.OIDCProvider, redirectURI string, state string) (string, error)
|
||||
ExchangeCode(ctx context.Context, provider *domain.OIDCProvider, code string, redirectURI string) (*Session, error)
|
||||
}
|
||||
Reference in new issue
Block a user