MCPcopy Create free account

hub / github.com/zitadel/oidc / functions

Functions1,804 in github.com/zitadel/oidc

↓ 1 callersFunctionWithAuthStyle
(oauthAuthStyle oauth2.AuthStyle)
pkg/client/rp/relying_party.go:361
↓ 1 callersFunctionWithAuthTimeMaxAge
WithAuthTimeMaxAge provides the ability to define the maximum duration between auth_time and now
pkg/client/rp/verifier.go:179
↓ 1 callersFunctionWithClientAssertionJWT
WithClientAssertionJWT sets the `client_assertion` param in the token request
pkg/client/rp/relying_party.go:811
↓ 1 callersFunctionWithCodeChallenge
WithCodeChallenge sets the `code_challenge` params in the auth request
pkg/client/rp/relying_party.go:787
↓ 1 callersFunctionWithCodeVerifier
WithCodeVerifier sets the `code_verifier` param in the token request
pkg/client/rp/relying_party.go:804
↓ 1 callersFunctionWithCustomEndpoints
WithCustomEndpoints sets multiple endpoints at once. None of the endpoints may be nil, or an error will be returned when the Option used by the Provid
pkg/op/op.go:609
↓ 1 callersFunctionWithDecoder
WithDecoder overrides the default decoder, which is a [schema.Decoder] with IgnoreUnknownKeys set to true.
pkg/op/server_http.go:65
↓ 1 callersFunctionWithFallbackLogger
WithFallbackLogger is retained for source compatibility. Deprecated: use [slog.SetDefault]. This option has no effect.
pkg/op/server_http.go:80
↓ 1 callersFunctionWithHTTPClient
WithHTTPClient provides the ability to set an http client to be used for the relaying party and verifier
pkg/client/rp/relying_party.go:340
↓ 1 callersFunctionWithHTTPMiddleware
WithHTTPMiddleware sets the passed middleware chain to the root of the Server's router.
pkg/op/server_http.go:50
↓ 1 callersFunctionWithHttpInterceptors
(interceptors ...HttpInterceptor)
pkg/op/op.go:626
↓ 1 callersFunctionWithIDTokenHintKeySet
WithIDTokenHintKeySet allows passing a KeySet with public keys for ID Token Hint verification. The default KeySet uses the [Storage] interface.
pkg/op/op.go:651
↓ 1 callersFunctionWithIssuedAtMaxAge
WithIssuedAtMaxAge provides the ability to define the maximum duration between iat and now
pkg/client/rp/verifier.go:151
↓ 1 callersFunctionWithIssuerFromCustomHeaders
WithIssuerFromCustomHeaders can be used to customize the header names used. The same rules apply where the first successful host is returned.
pkg/op/config.go:68
↓ 1 callersFunctionWithLogger
WithLogger sets the logger returned by [RelyingParty.Logger]. OIDC package logging uses the global [slog] default; prefer [slog.SetDefault]. Deprecate
pkg/client/rp/relying_party.go:399
↓ 1 callersFunctionWithLogger
WithLogger is retained for source compatibility. Deprecated: use [slog.SetDefault]. This option has no effect.
pkg/op/op.go:674
↓ 1 callersMethodWithReturnParentToClient
WithReturnParentToClient allows returning the set parent error to the HTTP client. Currently, it only supports setting the parent inside JSON response
pkg/oidc/error.go:198
↓ 1 callersFunctionWithSetRouter
WithSetRouter allows customization or the Server's router.
pkg/op/server_http.go:57
↓ 1 callersFunctionWithStaticEndpoints
WithStaticEndpoints provides the ability to set static token and introspect URL
pkg/client/rs/resource_server.go:112
↓ 1 callersFunctionWithSupportedAccessTokenSigningAlgorithms
(algs ...string)
pkg/op/verifier_access_token.go:13
↓ 1 callersFunctionWithSupportedIDTokenHintSigningAlgorithms
(algs ...string)
pkg/op/verifier_id_token_hint.go:14
↓ 1 callersFunctionWithUnsecure
()
pkg/http/cookie.go:51
↓ 1 callersFunctionabsoluteEndpoint
(host, endpoint string)
pkg/op/endpoint.go:47
↓ 1 callersFunctionalgToKeyType
(key any, alg string)
pkg/oidc/keyset.go:95
↓ 1 callersMethodapply
(*deviceAuthorizationOptions)
pkg/client/client.go:265
↓ 1 callersFunctionauthCallbackPath
(o OpenIDProvider)
pkg/op/op.go:158
↓ 1 callersFunctionauthRequestToInternal
(authReq *oidc.AuthRequest, userID string)
example/server/storage/oidc.go:145
↓ 1 callersMethodauthenticateResourceClient
(ctx context.Context, cc *ClientCredentials)
pkg/op/server_legacy.go:360
↓ 1 callersFunctionauthorizeHandler
(authorizer Authorizer)
pkg/op/auth_request.go:72
↓ 1 callersMethodauthorizeHandler
(w http.ResponseWriter, r *http.Request)
pkg/op/server_http.go:203
↓ 1 callersFunctioncallExampleEndpoint
(client *http.Client, testURL string)
example/client/service/service.go:156
↓ 1 callersFunctioncheckToken
(w http.ResponseWriter, r *http.Request)
example/client/api/api.go:96
↓ 1 callersFunctioncreateDiscoveryConfigV2
(ctx context.Context, config Configuration, storage DiscoverStorage, endpoints *Endpoints)
pkg/op/discovery.go:70
↓ 1 callersMethodcreateRouter
(issuerInterceptor *op.IssuerInterceptor)
example/server/exampleop/login.go:27
↓ 1 callersMethodcreateRouter
(issuerInterceptor *op.IssuerInterceptor)
example/server/dynamic/login.go:59
↓ 1 callersMethodcreateRouter
()
pkg/op/server_http.go:98
↓ 1 callersFunctioncreateTokens
createTokens delegates token creation to the appropriate storage method based on the request type and requirements. It returns an access token ID and
pkg/op/token.go:79
↓ 1 callersFunctiondevLocalAllowed
(url *url.URL, allowInsecure bool)
pkg/op/config.go:168
↓ 1 callersFunctiondeviceAccessToken
(w http.ResponseWriter, r *http.Request, exchanger Exchanger)
pkg/op/device.go:210
↓ 1 callersFunctiondiscoveryHandler
(c Configuration, s DiscoverStorage)
pkg/op/discovery.go:26
↓ 1 callersMethoddone
done can only be called by a single goroutine. It records the result of the inflight request and signals other goroutines that the result is safe to i
pkg/client/rp/jwks.go:76
↓ 1 callersFunctiondynamicIssuer
(issuer, path string, allowInsecure bool)
pkg/op/config.go:175
↓ 1 callersFunctionendSessionHandler
(ender SessionEnder)
pkg/op/session.go:24
↓ 1 callersMethodendpointRoute
(e *Endpoint, hf http.HandlerFunc)
pkg/op/server_http.go:113
↓ 1 callersMethodexactMatch
(jwkID, jwsID string)
pkg/client/rp/jwks.go:135
↓ 1 callersMethodexchangeRefreshToken
(ctx context.Context, request op.TokenExchangeRequest)
example/server/storage/storage.go:316
↓ 1 callersMethodfetchRemoteKeys
(ctx context.Context)
pkg/client/rp/jwks.go:217
↓ 1 callersFunctiongetInfoFromRequest
getInfoFromRequest returns the clientID, authTime and amr depending on the op.TokenRequest type / implementation
example/server/storage/storage.go:789
↓ 1 callersFunctiongetTokenIDAndClaims
(ctx context.Context, userinfoProvider UserinfoProvider, accessToken string)
pkg/op/token_exchange.go:421
↓ 1 callersFunctiongetUserStore
(cfg *config.Config)
example/server/main.go:14
↓ 1 callersFunctionhandleFormPostResponse
handleFormPostResponse processes the authentication response using form post method
pkg/op/auth_request.go:519
↓ 1 callersFunctionhandleRedirectResponse
handleRedirectResponse processes the authentication response using the redirect method
pkg/op/auth_request.go:528
↓ 1 callersFunctionhostFromForwarded
(r *http.Request, headers []string)
pkg/op/config.go:117
↓ 1 callersFunctionintrospectionHandler
(introspector Introspector)
pkg/op/token_intospection.go:24
↓ 1 callersFunctionisAsymmetricKeyBindingAlgorithm
(alg jose.SignatureAlgorithm)
pkg/client/rp/key_binding.go:185
↓ 1 callersFunctionjwtProfile
()
pkg/op/server_http_routes_test.go:24
↓ 1 callersMethodjwtProfileHandler
(w http.ResponseWriter, r *http.Request)
pkg/op/server_http.go:283
↓ 1 callersMethodkeysFromCache
()
pkg/client/rp/jwks.go:161
↓ 1 callersMethodkeysFromRemote
keysFromRemote syncs the key set from the remote set, records the values in the cache, and returns the key set.
pkg/client/rp/jwks.go:169
↓ 1 callersFunctionkeysHandler
(k KeyProvider)
pkg/op/keys.go:16
↓ 1 callersFunctionneedsRefreshToken
(tokenRequest TokenRequest, client AccessTokenClient)
pkg/op/token.go:90
↓ 1 callersFunctionnewDeviceClientCredentialsRequest
(scopes []string, rp RelyingParty)
pkg/client/rp/device.go:15
↓ 1 callersFunctionnewDynamicOP
newDynamicOP will create an OpenID Provider for localhost on a specified port with a given encryption key and a predefined default logout uri it will
example/server/dynamic/op.go:104
↓ 1 callersFunctionnewInflight
()
pkg/client/rp/jwks.go:63
↓ 1 callersFunctionnewOP
newOP will create an OpenID Provider for localhost on a specified port and a predefined default logout uri it will enable all options (see description
example/server/exampleop/op.go:115
↓ 1 callersMethodpath
()
pkg/op/server.go:167
↓ 1 callersMethodproof
(method, tokenEndpoint, code string)
pkg/client/rp/key_binding.go:230
↓ 1 callersFunctionreadyHandler
(probes []ProbesFn)
pkg/op/probes.go:17
↓ 1 callersFunctionregisterDeviceAuth
(storage deviceAuthenticate, router chi.Router)
example/server/exampleop/device.go:39
↓ 1 callersFunctionrenderConfirmPage
(w http.ResponseWriter, username, clientID string, scopes []string)
example/server/exampleop/device.go:75
↓ 1 callersFunctionrenderDeviceLogin
(w http.ResponseWriter, userCode string, err error)
example/server/exampleop/device.go:62
↓ 1 callersFunctionrenderUserCode
(w io.Writer, err error)
example/server/exampleop/device.go:50
↓ 1 callersMethodrenewRefreshToken
renewRefreshToken checks the provided refresh_token and creates a new one based on the current [Refresh Token Rotation] is implemented. [Refresh Tok
example/server/storage/storage.go:618
↓ 1 callersFunctionrequestLoggingMiddleware
requestLoggingMiddleware demonstrates request IDs and structured incoming request logs using only the standard library.
example/client/app/app.go:188
↓ 1 callersMethodresult
result cannot be called until the wait() channel has returned a value.
pkg/client/rp/jwks.go:83
↓ 1 callersFunctionrevocationHandler
(revoker Revoker)
pkg/op/token_revocation.go:28
↓ 1 callersFunctionrsaPublicKeyOfBits
rsaPublicKeyOfBits builds a public key of an exact size, avoiding slow keygen.
pkg/oidc/dpop_test.go:21
↓ 1 callersFunctionsetFragment
(uri *url.URL, params url.Values)
pkg/op/auth_request.go:680
↓ 1 callersFunctionsignKeyBoundIDToken
(t *testing.T, opKey crypto.Signer, typ string, cnfKey crypto.PublicKey)
pkg/client/rp/key_binding_test.go:195
↓ 1 callersFunctiontestRelyingPartySession
(t *testing.T, wrapServer bool, cookieSpec cookieSpec)
pkg/client/integration_test.go:128
↓ 1 callersFunctiontestResourceServerTokenExchange
(t *testing.T, wrapServer bool)
pkg/client/integration_test.go:273
↓ 1 callersFunctiontoJoseSignatureAlgorithms
TODO(v4): Use the new jose.SignatureAlgorithm type directly, instead of string.
pkg/oidc/verifier.go:234
↓ 1 callersFunctiontokenHandler
(exchanger Exchanger)
pkg/op/token_request.go:30
↓ 1 callersFunctiontryReadStateCookie
(w http.ResponseWriter, r *http.Request, rp RelyingParty)
pkg/client/rp/relying_party.go:709
↓ 1 callersFunctiontrySetStateCookie
(r *http.Request, w http.ResponseWriter, state string, rp RelyingParty)
pkg/client/rp/relying_party.go:693
↓ 1 callersMethodupdateKeys
(ctx context.Context)
pkg/client/rp/jwks.go:195
↓ 1 callersFunctionuserinfoHandler
(userinfoProvider UserinfoProvider)
pkg/op/userinfo.go:20
↓ 1 callersFunctionvalidateAuthReqRedirectURINative
ValidateAuthReqRedirectURINative validates the passed redirect_uri and response_type to the registered uris and client type
pkg/op/auth_request.go:366
↓ 1 callersFunctionverifyDeviceKeyBinding
verifyDeviceKeyBinding checks that the ID Token returned by the device token endpoint is actually bound to the expected RP's key.
pkg/client/rp/device.go:124
↓ 1 callersMethodverifySignatureCached
verifySignatureCached checks for a matching key in the cached key list if there is only one possible, it tries to verify the signature and will retur
pkg/client/rp/jwks.go:114
↓ 1 callersMethodverifySignatureRemote
(ctx context.Context, jws *jose.JSONWebSignature, keyID, alg string)
pkg/client/rp/jwks.go:142
↓ 1 callersFunctionverifyTokenResponse
(ctx context.Context, token *oauth2.Token, rp RelyingParty)
pkg/client/rp/relying_party.go:517
↓ 1 callersMethodwait
wait returns a channel that multiple goroutines can receive on. Once it returns a value, the inflight request is done and result() can be inspected.
pkg/client/rp/jwks.go:69
↓ 1 callersFunctionwriteError
(w http.ResponseWriter, r *http.Request, err *oidc.Error, statusCode int)
pkg/op/error.go:200
FunctionACRVerify
ACRVerify is a oidc.ACRVerifier func.
internal/testutil/token.go:175
MethodAccessTokenLifetime
()
pkg/op/server_http_test.go:125
MethodAccessTokenLifetime
()
pkg/op/mock/storage.mock.impl.go:124
MethodAccessTokenType
AccessTokenType must return the type of access token the client uses (Bearer (opaque) or JWT)
example/server/storage/client.go:82
MethodAccessTokenType
()
pkg/op/server_http_test.go:133
MethodAccessTokenType
AccessTokenType mocks base method.
pkg/op/mock/client.mock.go:40
← previousnext →701–800 of 1,804, ranked by callers