Add OAuth2/OpenID Connect authorization server
Implement a full OAuth2 2.0 and OpenID Connect 1.0 authorization server with support for authorization code flow (with PKCE), refresh token rotation, device authorization grant, dynamic client registration, token introspection, and token revocation. Includes database schema, coredata layer, service logic, HTTP handlers, OIDC discovery endpoint, and JWKS publishing. Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
@@ -15,6 +15,7 @@
|
||||
package cmdutil
|
||||
|
||||
import (
|
||||
"go.probo.inc/probo/pkg/cli/api"
|
||||
"go.probo.inc/probo/pkg/cli/config"
|
||||
"go.probo.inc/probo/pkg/cmd/iostreams"
|
||||
)
|
||||
@@ -24,3 +25,28 @@ type Factory struct {
|
||||
Version string
|
||||
Config func() (*config.Config, error)
|
||||
}
|
||||
|
||||
// TokenRefreshOption returns an api.Option that enables automatic access
|
||||
// token refresh using the stored OAuth2 refresh token. If the host config
|
||||
// has no refresh token or token endpoint, a no-op option is returned.
|
||||
func TokenRefreshOption(
|
||||
cfg *config.Config,
|
||||
host string,
|
||||
hc *config.HostConfig,
|
||||
) api.Option {
|
||||
if hc.RefreshToken == "" || hc.TokenEndpoint == "" {
|
||||
return func(*api.Client) {}
|
||||
}
|
||||
|
||||
return api.WithTokenRefresher(&api.TokenRefresher{
|
||||
RefreshToken: hc.RefreshToken,
|
||||
TokenEndpoint: hc.TokenEndpoint,
|
||||
ClientID: config.CLIClientID,
|
||||
OnRefresh: func(accessToken, refreshToken string) error {
|
||||
hc.Token = accessToken
|
||||
hc.RefreshToken = refreshToken
|
||||
cfg.Hosts[host] = hc
|
||||
return cfg.Save()
|
||||
},
|
||||
})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user