MCPcopy Create free account

hub / github.com/zitadel/oidc / functions

Functions1,804 in github.com/zitadel/oidc

↓ 1 callersFunctionNewAccessToken
NewAcccessToken creates a new AccessTokenClaims with passed data and returns a signed token and claims.
internal/testutil/token.go:116
↓ 1 callersFunctionNewAccessTokenCustom
(issuer, subject string, audience []string, expiration time.Time, jwtid, clientID string, skew time.Duration,
internal/testutil/token.go:104
↓ 1 callersFunctionNewAuthorizer
(t *testing.T)
pkg/op/mock/authorizer.mock.impl.go:15
↓ 1 callersFunctionNewCookieHandler
(hashKey, encryptKey []byte, opts ...CookieHandlerOpt)
pkg/http/cookie.go:20
↓ 1 callersFunctionNewDynamicOpenIDProvider
NewForwardedOpenIDProvider tries to establish the issuer from the request Host. Deprecated: use [NewProvider] with an issuer function direct.
pkg/op/op.go:222
↓ 1 callersFunctionNewHasRedirectGlobs
(t *testing.T)
pkg/op/mock/glob.go:11
↓ 1 callersFunctionNewHasRedirectGlobsWithConfig
(t *testing.T, uri []string, appType op.ApplicationType, responseTypes []oidc.ResponseType, devMode bool)
pkg/op/mock/glob.go:15
↓ 1 callersFunctionNewIDToken
NewIDToken creates a new IDTokenClaims with passed data and returns a signed token and claims.
internal/testutil/token.go:100
↓ 1 callersFunctionNewIDTokenCustom
(issuer, subject string, audience []string, expiration, authTime time.Time, nonce string, acr string, amr []st
internal/testutil/token.go:87
↓ 1 callersFunctionNewJWTProfileAssertion
(issuer, clientID string, audience []string, issuedAt, expiration time.Time)
internal/testutil/token.go:120
↓ 1 callersFunctionNewJWTProfileAssertionFromFileData
(data []byte, audience []string, opts ...AssertionOption)
pkg/oidc/token.go:297
↓ 1 callersFunctionNewJWTProfileGrantRequest
NewJWTProfileGrantRequest creates an oauth2 `JSON Web Token (JWT) Profile` Grant `urn:ietf:params:oauth:grant-type:jwt-bearer` sending a self-signed j
pkg/oidc/jwt_profile.go:12
↓ 1 callersFunctionNewJWTProfileTokenSourceFromKeyFile
NewJWTProfileTokenSourceFromKeyFile returns an implementation of TokenSource It will request a token using the OAuth2 JWT Profile Grant, therefore sen
pkg/client/profile/jwt_profile.go:40
↓ 1 callersFunctionNewJWTProfileTokenSourceFromKeyFileData
NewJWTProfileTokenSourceFromKeyFileData returns an implementation of oauth2.TokenSource It will request a token using the OAuth2 JWT Profile Grant, th
pkg/client/profile/jwt_profile.go:56
↓ 1 callersFunctionNewLogin
(authenticate authenticate, callback func(context.Context, string) string, issuerInterceptor *op.IssuerInterce
example/server/exampleop/login.go:18
↓ 1 callersFunctionNewLogin
(authenticate authenticate, callback func(context.Context, string) string, issuerInterceptor *op.IssuerInterce
example/server/dynamic/login.go:50
↓ 1 callersFunctionNewLogoutTokenClaims
(issuer, subject string, audience Audience, expiration time.Time, jwtID, sessionID string, skew time.Duration)
pkg/oidc/token.go:409
↓ 1 callersFunctionNewMockDiscoverStorage
NewMockDiscoverStorage creates a new mock instance.
pkg/op/mock/discovery.mock.go:27
↓ 1 callersFunctionNewMockKey
NewMockKey creates a new mock instance.
pkg/op/mock/signer.mock.go:91
↓ 1 callersFunctionNewMockKeyProvider
NewMockKeyProvider creates a new mock instance.
pkg/op/mock/key.mock.go:27
↓ 1 callersFunctionNewMockStorageAny
(t *testing.T)
pkg/op/mock/storage.mock.impl.go:31
↓ 1 callersFunctionNewMockStorageExpectValidClientID
(t *testing.T)
pkg/op/mock/storage.mock.impl.go:19
↓ 1 callersFunctionNewRemoteKeySet
(client *http.Client, jwksURL string, opts ...func(*remoteKeySet))
pkg/client/rp/jwks.go:18
↓ 1 callersFunctionNewResourceServerFromKeyFile
(ctx context.Context, issuer, path string, options ...Option)
pkg/client/rs/resource_server.go:94
↓ 1 callersFunctionNewResourceServerJWTProfile
(ctx context.Context, issuer, clientID, keyID string, key []byte, options ...Option)
pkg/client/rs/resource_server.go:52
↓ 1 callersFunctionNewStorageWithClients
(userStore UserStore, clients map[string]*Client)
example/server/storage/storage.go:96
↓ 1 callersFunctionNewTokenExchangeRequest
(subjectToken, subjectTokenType string, opts ...TokenExchangeOption)
pkg/oidc/grants/tokenexchange/tokenexchange.go:25
↓ 1 callersFunctionOpenBrowser
(url string)
pkg/client/rp/cli/browser.go:10
↓ 1 callersFunctionParseAccessTokenRequest
ParseAccessTokenRequest parsed the http request into an oidc.AccessTokenRequest
pkg/op/token_code.go:41
↓ 1 callersFunctionParseClientCredentialsRequest
ParseClientCredentialsRequest parsed the http request into a oidc.ClientCredentialsRequest
pkg/op/token_client_credentials.go:41
↓ 1 callersFunctionParseDeviceAccessTokenRequest
(r *http.Request, exchanger Exchanger)
pkg/op/device.go:249
↓ 1 callersFunctionParseEndSessionRequest
(r *http.Request, decoder httphelper.Decoder)
pkg/op/session.go:58
↓ 1 callersFunctionParseRefreshTokenRequest
ParseRefreshTokenRequest parsed the http request into an oidc.RefreshTokenRequest
pkg/op/token_refresh.go:50
↓ 1 callersFunctionParseTokenExchangeRequest
ParseTokenExchangeRequest parses the http request into oidc.TokenExchangeRequest
pkg/op/token_exchange.go:161
↓ 1 callersFunctionParseTokenIntrospectionRequest
(r *http.Request, introspector Introspector)
pkg/op/token_intospection.go:55
↓ 1 callersFunctionParseTokenRevocationRequest
(r *http.Request, revoker Revoker)
pkg/op/token_revocation.go:74
↓ 1 callersFunctionParseUserinfoRequest
(r *http.Request, decoder httphelper.Decoder)
pkg/op/userinfo.go:50
↓ 1 callersFunctionPromptToInternal
(oidcPrompt oidc.SpaceDelimitedArray)
example/server/storage/oidc.go:123
↓ 1 callersMethodProvider
()
pkg/op/server_legacy.go:20
↓ 1 callersFunctionReadiness
(w http.ResponseWriter, r *http.Request, probes ...ProbesFn)
pkg/op/probes.go:23
↓ 1 callersFunctionReadyStorage
(s Storage)
pkg/op/probes.go:34
↓ 1 callersFunctionRedirectGlobsClient
RedirectGlobsClient wraps the client in an op.HasRedirectGlobs only if DevMode is enabled.
example/server/storage/client.go:230
↓ 1 callersMethodRefreshToken
RefreshToken returns new Tokens after verifying a Refresh token. It is called by the Token endpoint handler when grant_type has the value refresh_toke
pkg/op/server.go:94
↓ 1 callersFunctionRefreshTokenExchange
RefreshTokenExchange handles the OAuth 2.0 refresh_token grant, including parsing, validating, authorizing the client and finally exchanging the refre
pkg/op/token_refresh.go:26
↓ 1 callersFunctionRefreshTokenRequestFromBusiness
RefreshTokenRequestFromBusiness will simply wrap the storage RefreshToken to implement the op.RefreshTokenRequest interface
example/server/storage/oidc.go:201
↓ 1 callersMethodRequestObjectSupported
()
pkg/op/auth_request.go:54
↓ 1 callersMethodRestrictAdditionalAccessTokenScopes
()
pkg/op/token.go:26
↓ 1 callersMethodRestrictAdditionalIdTokenScopes
()
pkg/op/client.go:47
↓ 1 callersMethodRevocation
Revocation handles token revocation using an access or refresh token. https://datatracker.ietf.org/doc/html/rfc7009 There are no response requirements
pkg/op/server.go:140
↓ 1 callersFunctionRevocationRequestError
(w http.ResponseWriter, r *http.Request, err error)
pkg/op/token_revocation.go:141
↓ 1 callersFunctionRevoke
(w http.ResponseWriter, r *http.Request, revoker Revoker)
pkg/op/token_revocation.go:34
↓ 1 callersFunctionRevokeToken
RevokeToken requires a RelyingParty that is also a client.RevokeCaller. The RelyingParty returned by NewRelyingPartyOIDC() meets that criteria, but t
pkg/client/rp/relying_party.go:933
↓ 1 callersMethodRoundTrip
(r *http.Request)
pkg/client/rp/key_binding_test.go:40
↓ 1 callersMethodSetClientID
(string)
pkg/op/token_request.go:85
↓ 1 callersMethodSetClientSecret
(string)
pkg/op/token_request.go:86
↓ 1 callersMethodSetRequestedTokenType
(tt oidc.TokenType)
pkg/op/token_exchange.go:35
↓ 1 callersMethodSetSubject
(subject string)
pkg/op/token_exchange.go:36
↓ 1 callersMethodSetUserinfoFromTokenExchangeRequest
SetUserinfoFromTokenExchangeRequest will be called during id token creation. Claims evaluation can be based on all validated request data available, i
pkg/op/storage.go:114
↓ 1 callersFunctionSignPayload
(payload []byte, signer jose.Signer)
pkg/crypto/sign.go:18
↓ 1 callersMethodSignatureAlgorithms
(context.Context)
pkg/op/discovery.go:14
↓ 1 callersFunctionSignerFromKeyPath
Deprecated: use [SignerFromKeyAndKeyID] instead. The function will be removed in the next major release.
pkg/client/rp/relying_party.go:419
↓ 1 callersMethodStorage
()
pkg/op/token_intospection.go:15
↓ 1 callersMethodStorage
()
pkg/op/userinfo.go:16
↓ 1 callersMethodStorage
()
pkg/op/token_request.go:14
↓ 1 callersMethodStorage
()
pkg/op/client.go:134
↓ 1 callersMethodString
()
pkg/oidc/types.go:206
↓ 1 callersFunctionSubjectCheck
SubjectCheck sets a custom function to check the subject. Defaults to SubjectIsIssuer()
pkg/op/verifier_jwt_profile.go:56
↓ 1 callersMethodTokenCtx
(ctx context.Context)
pkg/client/profile/jwt_profile.go:118
↓ 1 callersFunctionTokenExchange
TokenExchange handles the OAuth 2.0 token exchange grant ("urn:ietf:params:oauth:grant-type:token-exchange")
pkg/op/token_exchange.go:136
↓ 1 callersMethodTokenExchange
TokenExchange handles the OAuth 2.0 token exchange grant It is called by the Token endpoint handler when grant_type has the value urn:ietf:params:oaut
pkg/op/server.go:108
↓ 1 callersMethodUnauthorizedHandler
UnauthorizedHandler returns the handler used for unauthorized errors
pkg/client/rp/relying_party.go:90
↓ 1 callersMethodUnmarshalJSON
UnmarshalJSON overrides the default jose.JSONWebKeySet method to ignore any error which might occur because of unknown key types (kty)
pkg/client/rp/jwks.go:238
↓ 1 callersMethodUnmarshalJSON
UnmarshalJSON implements the [json.Unmarshaler] interface. It decodes a json array or a space separated string into Locales. Undefined language tags i
pkg/oidc/types.go:166
↓ 1 callersMethodUnmarshalJSON
(data []byte)
pkg/oidc/types.go:293
↓ 1 callersMethodUnmarshalJSON
(data []byte)
pkg/oidc/device_authorization.go:34
↓ 1 callersMethodUnmarshalText
(text []byte)
pkg/oidc/types.go:65
↓ 1 callersMethodUnmarshalText
UnmarshalText implements the [encoding.TextUnmarshaler] interface. It decodes an unquoted space separated string into Locales. Undefined language tags
pkg/oidc/types.go:155
↓ 1 callersMethodUnmarshalText
(text []byte)
pkg/oidc/types.go:210
↓ 1 callersMethodUnwrap
()
pkg/op/error.go:165
↓ 1 callersMethodUserInfo
UserInfo handles the UserInfo endpoint and returns Claims about the authenticated End-User. https://openid.net/specs/openid-connect-core-1_0.html#User
pkg/op/server.go:135
↓ 1 callersFunctionUserinfo
(w http.ResponseWriter, r *http.Request, userinfoProvider UserinfoProvider)
pkg/op/userinfo.go:26
↓ 1 callersMethodUserinfoEndpoint
UserinfoEndpoint returns the userinfo
pkg/client/rp/relying_party.go:71
↓ 1 callersFunctionValidateAccessTokenRequest
ValidateAccessTokenRequest validates the token request parameters including authorization check of the client and returns the previous created auth re
pkg/op/token_code.go:52
↓ 1 callersFunctionValidateAuthRequest
ValidateAuthRequest validates the authorize parameters and returns the userID of the id_token_hint if passed. Deprecated: Use [ValidateAuthRequestCli
pkg/op/auth_request.go:247
↓ 1 callersFunctionValidateClientCredentialsRequest
ValidateClientCredentialsRequest validates the client_credentials request parameters including authorization check of the client and returns a TokenRe
pkg/op/token_client_credentials.go:73
↓ 1 callersFunctionValidateRefreshTokenRequest
ValidateRefreshTokenRequest validates the refresh_token request parameters including authorization check of the client and returns the data representi
pkg/op/token_refresh.go:61
↓ 1 callersFunctionValidateTokenExchangeRequest
ValidateTokenExchangeRequest validates the token exchange request parameters including authorization check of the client, subject_token and actor_toke
pkg/op/token_exchange.go:191
↓ 1 callersMethodValidateTokenExchangeRequest
ValidateTokenExchangeRequest will be called to validate parsed (including tokens) Token Exchange Grant request. Important validations can include: -
pkg/op/storage.go:101
↓ 1 callersMethodValue
()
pkg/op/applicationtype_enumer.go:134
↓ 1 callersMethodValue
()
pkg/oidc/types.go:256
↓ 1 callersMethodVerifyAuthRequest
VerifyAuthRequest verifies the Auth Request and adds the Client to the request. When the `request` field is populated with a "Request Object" JWT, it
pkg/op/server.go:62
↓ 1 callersMethodVerifyClient
VerifyClient is called on most oauth/token handlers to authenticate, using either a secret (POST, Basic) or assertion (JWT). If no secrets are provide
pkg/op/server.go:79
↓ 1 callersFunctionVerifyCodeChallenge
(c *CodeChallenge, codeVerifier string)
pkg/oidc/code_challenge.go:25
↓ 1 callersMethodVerifyExchangeActorToken
(ctx context.Context, token string, tokenType oidc.TokenType)
pkg/op/storage.go:121
↓ 1 callersMethodVerifyExchangeSubjectToken
(ctx context.Context, token string, tokenType oidc.TokenType)
pkg/op/storage.go:120
↓ 1 callersMethodVerifySignature
VerifySignature verifies the signature with the given keyset and returns the raw payload
pkg/oidc/keyset.go:29
↓ 1 callersFunctionVerifyTokens
VerifyTokens implement the Token Response Validation as defined in OIDC specification https://openid.net/specs/openid-connect-core-1_0.html#TokenRespo
pkg/client/rp/verifier.go:15
↓ 1 callersFunctionWithACRVerifier
WithACRVerifier sets the verifier for the acr claim
pkg/client/rp/verifier.go:165
↓ 1 callersFunctionWithAZPVerifier
WithAZPVerifier sets the verifier for the azp claim
pkg/client/rp/verifier.go:172
↓ 1 callersFunctionWithAccessTokenKeySet
WithAccessTokenKeySet allows passing a KeySet with public keys for Access Token verification. The default KeySet uses the [Storage] interface
pkg/op/op.go:635
← previousnext →601–700 of 1,804, ranked by callers