MCPcopy Create free account

hub / github.com/zitadel/oidc / functions

Functions1,804 in github.com/zitadel/oidc

↓ 2 callersMethodSupportedUILocales
()
pkg/op/config.go:51
↓ 2 callersMethodTerminateSessionFromRequest
(ctx context.Context, endSessionRequest *EndSessionRequest)
pkg/op/storage.go:77
↓ 2 callersMethodToken
()
pkg/client/profile/jwt_profile.go:114
↓ 2 callersMethodTokenEndpointSigningAlgorithmsSupported
()
pkg/op/config.go:38
↓ 2 callersFunctionTracer
(name string)
internal/otel/shim.go:12
↓ 2 callersFunctionTryErrorRedirect
TryErrorRedirect tries to handle an error by redirecting a client. If this attempt fails, an error is returned that must be returned to the client ins
pkg/op/error.go:86
↓ 2 callersMethodUnauthorizedHandler
()
pkg/client/rp/relying_party.go:187
↓ 2 callersFunctionValidateAuthRequestClient
ValidateAuthRequestClient validates the Auth request against the passed client. If id_token_hint is part of the request, the subject of the token is r
pkg/op/auth_request.go:260
↓ 2 callersFunctionValidateDPoPKeyStrength
ValidateDPoPKeyStrength enforces minimum key strength for a DPoP proof-of-possession key: RSA 2048-8192 bits, EC curve P-256, P-384 or P-521, and Ed25
pkg/oidc/dpop.go:126
↓ 2 callersFunctionValidateEndSessionPostLogoutRedirectURI
(postLogoutRedirectURI string, client Client)
pkg/op/session.go:115
↓ 2 callersFunctionValidateEndSessionRequest
(ctx context.Context, req *oidc.EndSessionRequest, ender SessionEnder)
pkg/op/session.go:71
↓ 2 callersFunctionValidateIssuer
(issuer string, allowInsecure bool)
pkg/op/config.go:142
↓ 2 callersFunctionValidateRefreshTokenScopes
ValidateRefreshTokenScopes validates that the requested scope is a subset of the original auth request scope it will set the requested scopes as curre
pkg/op/token_refresh.go:84
↓ 2 callersFunctionVerifyAccessToken
VerifyAccessToken validates the access token according to https://openid.net/specs/openid-connect-core-1_0.html#CodeFlowTokenValidation
pkg/client/rp/verifier.go:97
↓ 2 callersFunctionWithCookieHandler
WithCookieHandler set a `CookieHandler` for securing the various redirects
pkg/client/rp/relying_party.go:309
↓ 2 callersFunctionWithCustomAuthEndpoint
(endpoint *Endpoint)
pkg/op/op.go:526
↓ 2 callersFunctionWithDPoPJKT
WithDPoPJKT adds the `dpop_jkt` parameter from OpenID Connect Key Binding 1.0, Section 3.1 to a device authorization request. Experimental: OpenID Co
pkg/client/client.go:273
↓ 2 callersFunctionWithNonce
WithNonce sets the function to check the nonce
pkg/client/rp/verifier.go:158
↓ 2 callersFunctionWithPKCEFromDiscovery
WithPKCEFromDiscovery enables Oauth2 Code Challenge if support is found in the discovery response from the OP. Passing this option to an Oauth2-only R
pkg/client/rp/relying_party.go:331
↓ 2 callersFunctionWithResponseModeURLParam
WithResponseModeURLParam sets the `response_mode` parameter in a URL.
pkg/client/rp/relying_party.go:780
↓ 2 callersFunctionWithSigningAlgsFromDiscovery
WithSigningAlgsFromDiscovery appends the [WithSupportedSigningAlgorithms] option to the Verifier Options. The algorithms returned in the `id_token_sig
pkg/client/rp/relying_party.go:408
↓ 2 callersFunctionWithURLParam
WithURLParam allows setting custom key-vale pairs to an OAuth2 URL.
pkg/client/rp/relying_party.go:770
↓ 2 callersFunctionassertDeviceStorage
(s Storage)
pkg/op/storage.go:205
↓ 2 callersMethodauthorize
(ctx context.Context, r *Request[oidc.AuthRequest])
pkg/op/server_http.go:217
↓ 2 callersFunctioncallbackServerConfig
(redirectURI, callbackPath, port string)
pkg/client/rp/cli/cli.go:47
↓ 2 callersFunctioncheckURIAgainstRedirects
checkURIAgainstRedirects just checks against the valid redirect URIs and ignores other factors.
pkg/op/auth_request.go:316
↓ 2 callersFunctionclaimsMap
(claims any)
internal/testutil/token.go:75
↓ 2 callersFunctioncreateDeviceAuthorization
(ctx context.Context, req *oidc.DeviceAuthorizationRequest, clientID string, o OpenIDProvider)
pkg/op/device.go:84
↓ 2 callersMethodcreateRefreshToken
createRefreshToken will store a refresh_token in-memory based on the provided information
example/server/storage/storage.go:594
↓ 2 callersFunctioncustomClaim
customClaim demonstrates how to return custom claims based on provided information
example/server/storage/storage.go:802
↓ 2 callersFunctionencodeJSON
(t *testing.T, w io.Writer, obj any)
pkg/oidc/regression_test.go:28
↓ 2 callersFunctionequalURI
(url1, url2 *url.URL)
pkg/op/auth_request.go:397
↓ 2 callersFunctionfillForm
(t *testing.T, desc string, httpClient *http.Client, body []byte, uri *url.URL, opts ...gosubmit.Option)
pkg/client/integration_test.go:637
↓ 2 callersFunctiongetAccessToken
(r *http.Request)
pkg/op/userinfo.go:71
↓ 2 callersFunctiongetForm
(t *testing.T, desc string, httpClient *http.Client, uri *url.URL)
pkg/client/integration_test.go:622
↓ 2 callersMethodgetPrivateClaimsFromScopes
(ctx context.Context, userID, clientID string, scopes []string)
example/server/storage/storage.go:546
↓ 2 callersMethodgetTokenExchangeClaims
(ctx context.Context, request op.TokenExchangeRequest)
example/server/storage/storage.go:767
↓ 2 callersFunctiongetTokenIDAndSubjectForRevocation
(ctx context.Context, userinfoProvider UserinfoProvider, accessToken string)
pkg/op/token_revocation.go:158
↓ 2 callersFunctionhtuKey
htuKey returns a normalized version of the token endpoint URI for comparison per RFC 3986, sections 6.2.2 and 6.2.3.
pkg/client/rp/key_binding.go:272
↓ 2 callersFunctionintercept
(i IssuerFromRequest, interceptors ...HttpInterceptor)
pkg/op/op.go:690
↓ 2 callersFunctionissuerFromForwardedOrHost
(path string, c *issuerConfig)
pkg/op/config.go:99
↓ 2 callersFunctionjsonFilename
jsonFilename builds a filename for the regression testdata. dataDir/<type_name>.json
pkg/oidc/regression_test.go:20
↓ 2 callersFunctionkeyBindingAlgMatchesKey
keyBindingAlgMatchesKey reports whether alg can be produced by the public key pub. For the standard Go key types the pairing is fully determined (an E
pkg/client/rp/key_binding.go:203
↓ 2 callersFunctionmapAsValues
(m map[string]string)
pkg/op/op_test.go:92
↓ 2 callersFunctionmergeQueryParams
(uri *url.URL, params url.Values)
pkg/op/auth_request.go:688
↓ 2 callersFunctionmustRSAKey
(t *testing.T, bits int)
pkg/client/rp/key_binding_test.go:77
↓ 2 callersFunctionnewJWTProfileVerifier
(storage JWTProfileKeyStorage, keySet oidc.KeySet, issuer string, maxAgeIAT, offset time.Duration, opts ...JWT
pkg/op/verifier_jwt_profile.go:33
↓ 2 callersFunctionnilCryptoSigner
(signer crypto.Signer)
pkg/client/rp/key_binding.go:143
↓ 2 callersFunctionok
(w http.ResponseWriter)
pkg/op/probes.go:43
↓ 2 callersMethodparseClientCredentials
(r *http.Request)
pkg/op/server_http.go:163
↓ 2 callersFunctionredirectBack
(w http.ResponseWriter, r *http.Request, prompt string)
example/server/exampleop/device.go:109
↓ 2 callersFunctionrelativeEndpoint
(endpoint string)
pkg/op/endpoint.go:51
↓ 2 callersFunctionremoveUserinfoScopes
(scopes []string)
pkg/op/token.go:269
↓ 2 callersFunctionrenderLogin
(w http.ResponseWriter, id string, err error)
example/server/exampleop/login.go:48
↓ 2 callersFunctionrenderLogin
(w http.ResponseWriter, id string, err error)
example/server/dynamic/login.go:80
↓ 2 callersMethodsetIssuerCtx
(w http.ResponseWriter, r *http.Request, next http.Handler)
pkg/op/context.go:50
↓ 2 callersFunctionsimpleHandler
(s *webServer, method func(context.Context, *Request[struct{}]) (*Response, error))
pkg/op/server_http.go:496
↓ 2 callersMethodverifyRequestClient
(r *http.Request)
pkg/op/server_http.go:149
↓ 2 callersFunctionwithPrompt
withPrompt sets the `prompt` params in the auth request This is the generalized, unexported, function used by both URLParamOpt and AuthURLOpt.
pkg/client/rp/relying_party.go:762
↓ 1 callersMethodAccessTokenVerifier
(context.Context)
pkg/op/token_revocation.go:18
↓ 1 callersMethodAccessTokenVerifier
(context.Context)
pkg/op/op.go:109
↓ 1 callersMethodAccessTokenVerifier
(context.Context)
pkg/op/userinfo.go:17
↓ 1 callersFunctionAppendClientIDToAudience
(clientID string, audience []string)
pkg/oidc/token.go:340
↓ 1 callersMethodAuthCallbackURL
()
pkg/op/server_legacy.go:22
↓ 1 callersMethodAuthFn
()
pkg/client/rs/resource_server.go:18
↓ 1 callersMethodAuthFn
()
pkg/client/tokenexchange/tokenexchange.go:18
↓ 1 callersMethodAuthMethodPostSupported
()
pkg/op/token_revocation.go:20
↓ 1 callersMethodAuthMethodPrivateKeyJWTSupported
()
pkg/op/token_revocation.go:19
↓ 1 callersMethodAuthRequestByID
AuthRequestByID implements the op.Storage interface it will be called after the Login UI redirects back to the OIDC endpoint
example/server/storage/storage.go:200
↓ 1 callersFunctionAuthResponse
AuthResponse creates the successful authentication response (either code or tokens)
pkg/op/auth_request.go:483
↓ 1 callersFunctionAuthResponseToken
AuthResponseToken creates the successful token(s) authentication response
pkg/op/auth_request.go:567
↓ 1 callersMethodAuthorize
Authorize initiates the authorization flow and redirects to a login page. See the various https://openid.net/specs/openid-connect-core-1_0.html author
pkg/op/server.go:67
↓ 1 callersFunctionAuthorizeCallback
AuthorizeCallback handles the callback after authentication in the Login UI
pkg/op/auth_request.go:447
↓ 1 callersFunctionAuthorizeClientCredentialsClient
(ctx context.Context, request *oidc.ClientCredentialsRequest, storage ClientCredentialsStorage)
pkg/op/token_client_credentials.go:95
↓ 1 callersFunctionAuthorizeCodeClient
AuthorizeCodeClient checks the authorization of the client and that the used method was the one previously registered. It than returns the auth reques
pkg/op/token_code.go:74
↓ 1 callersFunctionAuthorizeRefreshClient
AuthorizeRefreshClient checks the authorization of the client and that the used method was the one previously registered. It than returns the data rep
pkg/op/token_refresh.go:99
↓ 1 callersFunctionAuthorizeTokenExchangeClient
AuthorizeTokenExchangeClient authorizes a client by validating the client_id and client_secret
pkg/op/token_exchange.go:357
↓ 1 callersFunctionBuildAuthRequestCode
BuildAuthRequestCode builds the string representation of the auth code
pkg/op/auth_request.go:613
↓ 1 callersMethodCORSOptions
()
pkg/op/op.go:123
↓ 1 callersFunctionCallTokenEndpoint
(ctx context.Context, request any, caller TokenEndpointCaller)
pkg/client/client.go:69
↓ 1 callersFunctionCallTokenExchangeEndpoint
(ctx context.Context, request any, authFn any, caller TokenEndpointCaller)
pkg/client/client.go:206
↓ 1 callersFunctionCheckIssuer
Deprecated: Use CheckIssuerWithISSVerifier instead
pkg/oidc/verifier.go:135
↓ 1 callersMethodCheckQueryCookie
(r *http.Request, name string)
pkg/http/cookie.go:107
↓ 1 callersMethodCheckSessionIframe
()
pkg/op/config.go:33
↓ 1 callersMethodCheckUsernamePasswordSimple
(username, password string)
example/server/exampleop/device.go:18
↓ 1 callersFunctionClientAssertionCodeOptions
(assertion string)
pkg/client/jwt_profile.go:18
↓ 1 callersFunctionClientCredentials
ClientCredentials requests an access token using the `client_credentials` grant, as defined in [RFC 6749, section 4.4]. As there is no user associate
pkg/client/rp/relying_party.go:576
↓ 1 callersFunctionClientCredentialsExchange
ClientCredentialsExchange handles the OAuth 2.0 client_credentials grant, including parsing, validating, authorizing the client and finally returning
pkg/op/token_client_credentials.go:14
↓ 1 callersMethodClientCredentialsExchange
ClientCredentialsExchange handles the OAuth 2.0 client credentials grant It is called by the Token endpoint handler when grant_type has the value clie
pkg/op/server.go:115
↓ 1 callersFunctionClientCredentialsGrantBasic
ClientCredentialsGrantBasic creates an oauth2 `Client Credentials` Grant sending client_id and client_secret as basic auth header
pkg/oidc/grants/client_credentials.go:18
↓ 1 callersFunctionCodeChallengeToOIDC
(challenge *OIDCCodeChallenge)
example/server/storage/oidc.go:186
↓ 1 callersFunctionCodeExchange
CodeExchange handles the OAuth 2.0 authorization_code grant, including parsing, validating, authorizing the client and finally exchanging the code for
pkg/op/token_code.go:13
↓ 1 callersMethodCodeExchange
CodeExchange returns Tokens after an authorization code is obtained in a successful Authorize flow. It is called by the Token endpoint handler when gr
pkg/op/server.go:87
↓ 1 callersFunctionCodeFlow
(ctx context.Context, relyingParty rp.RelyingParty, callbackPath, port string, stateProvider func() string)
pkg/client/rp/cli/cli.go:21
↓ 1 callersFunctionConcatenateJSON
(first, second []byte)
pkg/http/marshal.go:27
↓ 1 callersFunctionContains
Deprecated: Use standard library [slices.Contains] instead.
pkg/strings/strings.go:6
↓ 1 callersFunctionContainsResponseType
(types []oidc.ResponseType, responseType oidc.ResponseType)
pkg/op/client.go:71
↓ 1 callersFunctionCopyRequestObjectToAuthRequest
CopyRequestObjectToAuthRequest overwrites present values from the Request Object into the auth request and clears the `RequestParam` of the auth reque
pkg/op/auth_request.go:198
↓ 1 callersFunctionCreateAuthRequestCode
CreateAuthRequestCode creates and stores a code for the auth code response
pkg/op/auth_request.go:598
↓ 1 callersFunctionCreateBearerToken
(tokenID, subject string, crypto Encrypter)
pkg/op/token.go:137
← previousnext →401–500 of 1,804, ranked by callers