Code
Hub
Workspaces
Following
Trending
Connect
MCP
copy
Create free account
hub
/
github.com/zitadel/oidc
/ functions
Functions
1,804 in github.com/zitadel/oidc
⨍
Functions
1,804
◇
Types & classes
360
↓ 1 callers
Function
WithAuthStyle
(oauthAuthStyle oauth2.AuthStyle)
pkg/client/rp/relying_party.go:361
↓ 1 callers
Function
WithAuthTimeMaxAge
WithAuthTimeMaxAge provides the ability to define the maximum duration between auth_time and now
pkg/client/rp/verifier.go:179
↓ 1 callers
Function
WithClientAssertionJWT
WithClientAssertionJWT sets the `client_assertion` param in the token request
pkg/client/rp/relying_party.go:811
↓ 1 callers
Function
WithCodeChallenge
WithCodeChallenge sets the `code_challenge` params in the auth request
pkg/client/rp/relying_party.go:787
↓ 1 callers
Function
WithCodeVerifier
WithCodeVerifier sets the `code_verifier` param in the token request
pkg/client/rp/relying_party.go:804
↓ 1 callers
Function
WithCustomEndpoints
WithCustomEndpoints sets multiple endpoints at once. None of the endpoints may be nil, or an error will be returned when the Option used by the Provid
pkg/op/op.go:609
↓ 1 callers
Function
WithDecoder
WithDecoder overrides the default decoder, which is a [schema.Decoder] with IgnoreUnknownKeys set to true.
pkg/op/server_http.go:65
↓ 1 callers
Function
WithFallbackLogger
WithFallbackLogger is retained for source compatibility. Deprecated: use [slog.SetDefault]. This option has no effect.
pkg/op/server_http.go:80
↓ 1 callers
Function
WithHTTPClient
WithHTTPClient provides the ability to set an http client to be used for the relaying party and verifier
pkg/client/rp/relying_party.go:340
↓ 1 callers
Function
WithHTTPMiddleware
WithHTTPMiddleware sets the passed middleware chain to the root of the Server's router.
pkg/op/server_http.go:50
↓ 1 callers
Function
WithHttpInterceptors
(interceptors ...HttpInterceptor)
pkg/op/op.go:626
↓ 1 callers
Function
WithIDTokenHintKeySet
WithIDTokenHintKeySet allows passing a KeySet with public keys for ID Token Hint verification. The default KeySet uses the [Storage] interface.
pkg/op/op.go:651
↓ 1 callers
Function
WithIssuedAtMaxAge
WithIssuedAtMaxAge provides the ability to define the maximum duration between iat and now
pkg/client/rp/verifier.go:151
↓ 1 callers
Function
WithIssuerFromCustomHeaders
WithIssuerFromCustomHeaders can be used to customize the header names used. The same rules apply where the first successful host is returned.
pkg/op/config.go:68
↓ 1 callers
Function
WithLogger
WithLogger sets the logger returned by [RelyingParty.Logger]. OIDC package logging uses the global [slog] default; prefer [slog.SetDefault]. Deprecate
pkg/client/rp/relying_party.go:399
↓ 1 callers
Function
WithLogger
WithLogger is retained for source compatibility. Deprecated: use [slog.SetDefault]. This option has no effect.
pkg/op/op.go:674
↓ 1 callers
Method
WithReturnParentToClient
WithReturnParentToClient allows returning the set parent error to the HTTP client. Currently, it only supports setting the parent inside JSON response
pkg/oidc/error.go:198
↓ 1 callers
Function
WithSetRouter
WithSetRouter allows customization or the Server's router.
pkg/op/server_http.go:57
↓ 1 callers
Function
WithStaticEndpoints
WithStaticEndpoints provides the ability to set static token and introspect URL
pkg/client/rs/resource_server.go:112
↓ 1 callers
Function
WithSupportedAccessTokenSigningAlgorithms
(algs ...string)
pkg/op/verifier_access_token.go:13
↓ 1 callers
Function
WithSupportedIDTokenHintSigningAlgorithms
(algs ...string)
pkg/op/verifier_id_token_hint.go:14
↓ 1 callers
Function
WithUnsecure
()
pkg/http/cookie.go:51
↓ 1 callers
Function
absoluteEndpoint
(host, endpoint string)
pkg/op/endpoint.go:47
↓ 1 callers
Function
algToKeyType
(key any, alg string)
pkg/oidc/keyset.go:95
↓ 1 callers
Method
apply
(*deviceAuthorizationOptions)
pkg/client/client.go:265
↓ 1 callers
Function
authCallbackPath
(o OpenIDProvider)
pkg/op/op.go:158
↓ 1 callers
Function
authRequestToInternal
(authReq *oidc.AuthRequest, userID string)
example/server/storage/oidc.go:145
↓ 1 callers
Method
authenticateResourceClient
(ctx context.Context, cc *ClientCredentials)
pkg/op/server_legacy.go:360
↓ 1 callers
Function
authorizeHandler
(authorizer Authorizer)
pkg/op/auth_request.go:72
↓ 1 callers
Method
authorizeHandler
(w http.ResponseWriter, r *http.Request)
pkg/op/server_http.go:203
↓ 1 callers
Function
callExampleEndpoint
(client *http.Client, testURL string)
example/client/service/service.go:156
↓ 1 callers
Function
checkToken
(w http.ResponseWriter, r *http.Request)
example/client/api/api.go:96
↓ 1 callers
Function
createDiscoveryConfigV2
(ctx context.Context, config Configuration, storage DiscoverStorage, endpoints *Endpoints)
pkg/op/discovery.go:70
↓ 1 callers
Method
createRouter
(issuerInterceptor *op.IssuerInterceptor)
example/server/exampleop/login.go:27
↓ 1 callers
Method
createRouter
(issuerInterceptor *op.IssuerInterceptor)
example/server/dynamic/login.go:59
↓ 1 callers
Method
createRouter
()
pkg/op/server_http.go:98
↓ 1 callers
Function
createTokens
createTokens delegates token creation to the appropriate storage method based on the request type and requirements. It returns an access token ID and
pkg/op/token.go:79
↓ 1 callers
Function
devLocalAllowed
(url *url.URL, allowInsecure bool)
pkg/op/config.go:168
↓ 1 callers
Function
deviceAccessToken
(w http.ResponseWriter, r *http.Request, exchanger Exchanger)
pkg/op/device.go:210
↓ 1 callers
Function
discoveryHandler
(c Configuration, s DiscoverStorage)
pkg/op/discovery.go:26
↓ 1 callers
Method
done
done can only be called by a single goroutine. It records the result of the inflight request and signals other goroutines that the result is safe to i
pkg/client/rp/jwks.go:76
↓ 1 callers
Function
dynamicIssuer
(issuer, path string, allowInsecure bool)
pkg/op/config.go:175
↓ 1 callers
Function
endSessionHandler
(ender SessionEnder)
pkg/op/session.go:24
↓ 1 callers
Method
endpointRoute
(e *Endpoint, hf http.HandlerFunc)
pkg/op/server_http.go:113
↓ 1 callers
Method
exactMatch
(jwkID, jwsID string)
pkg/client/rp/jwks.go:135
↓ 1 callers
Method
exchangeRefreshToken
(ctx context.Context, request op.TokenExchangeRequest)
example/server/storage/storage.go:316
↓ 1 callers
Method
fetchRemoteKeys
(ctx context.Context)
pkg/client/rp/jwks.go:217
↓ 1 callers
Function
getInfoFromRequest
getInfoFromRequest returns the clientID, authTime and amr depending on the op.TokenRequest type / implementation
example/server/storage/storage.go:789
↓ 1 callers
Function
getTokenIDAndClaims
(ctx context.Context, userinfoProvider UserinfoProvider, accessToken string)
pkg/op/token_exchange.go:421
↓ 1 callers
Function
getUserStore
(cfg *config.Config)
example/server/main.go:14
↓ 1 callers
Function
handleFormPostResponse
handleFormPostResponse processes the authentication response using form post method
pkg/op/auth_request.go:519
↓ 1 callers
Function
handleRedirectResponse
handleRedirectResponse processes the authentication response using the redirect method
pkg/op/auth_request.go:528
↓ 1 callers
Function
hostFromForwarded
(r *http.Request, headers []string)
pkg/op/config.go:117
↓ 1 callers
Function
introspectionHandler
(introspector Introspector)
pkg/op/token_intospection.go:24
↓ 1 callers
Function
isAsymmetricKeyBindingAlgorithm
(alg jose.SignatureAlgorithm)
pkg/client/rp/key_binding.go:185
↓ 1 callers
Function
jwtProfile
()
pkg/op/server_http_routes_test.go:24
↓ 1 callers
Method
jwtProfileHandler
(w http.ResponseWriter, r *http.Request)
pkg/op/server_http.go:283
↓ 1 callers
Method
keysFromCache
()
pkg/client/rp/jwks.go:161
↓ 1 callers
Method
keysFromRemote
keysFromRemote syncs the key set from the remote set, records the values in the cache, and returns the key set.
pkg/client/rp/jwks.go:169
↓ 1 callers
Function
keysHandler
(k KeyProvider)
pkg/op/keys.go:16
↓ 1 callers
Function
needsRefreshToken
(tokenRequest TokenRequest, client AccessTokenClient)
pkg/op/token.go:90
↓ 1 callers
Function
newDeviceClientCredentialsRequest
(scopes []string, rp RelyingParty)
pkg/client/rp/device.go:15
↓ 1 callers
Function
newDynamicOP
newDynamicOP will create an OpenID Provider for localhost on a specified port with a given encryption key and a predefined default logout uri it will
example/server/dynamic/op.go:104
↓ 1 callers
Function
newInflight
()
pkg/client/rp/jwks.go:63
↓ 1 callers
Function
newOP
newOP will create an OpenID Provider for localhost on a specified port and a predefined default logout uri it will enable all options (see description
example/server/exampleop/op.go:115
↓ 1 callers
Method
path
()
pkg/op/server.go:167
↓ 1 callers
Method
proof
(method, tokenEndpoint, code string)
pkg/client/rp/key_binding.go:230
↓ 1 callers
Function
readyHandler
(probes []ProbesFn)
pkg/op/probes.go:17
↓ 1 callers
Function
registerDeviceAuth
(storage deviceAuthenticate, router chi.Router)
example/server/exampleop/device.go:39
↓ 1 callers
Function
renderConfirmPage
(w http.ResponseWriter, username, clientID string, scopes []string)
example/server/exampleop/device.go:75
↓ 1 callers
Function
renderDeviceLogin
(w http.ResponseWriter, userCode string, err error)
example/server/exampleop/device.go:62
↓ 1 callers
Function
renderUserCode
(w io.Writer, err error)
example/server/exampleop/device.go:50
↓ 1 callers
Method
renewRefreshToken
renewRefreshToken checks the provided refresh_token and creates a new one based on the current [Refresh Token Rotation] is implemented. [Refresh Tok
example/server/storage/storage.go:618
↓ 1 callers
Function
requestLoggingMiddleware
requestLoggingMiddleware demonstrates request IDs and structured incoming request logs using only the standard library.
example/client/app/app.go:188
↓ 1 callers
Method
result
result cannot be called until the wait() channel has returned a value.
pkg/client/rp/jwks.go:83
↓ 1 callers
Function
revocationHandler
(revoker Revoker)
pkg/op/token_revocation.go:28
↓ 1 callers
Function
rsaPublicKeyOfBits
rsaPublicKeyOfBits builds a public key of an exact size, avoiding slow keygen.
pkg/oidc/dpop_test.go:21
↓ 1 callers
Function
setFragment
(uri *url.URL, params url.Values)
pkg/op/auth_request.go:680
↓ 1 callers
Function
signKeyBoundIDToken
(t *testing.T, opKey crypto.Signer, typ string, cnfKey crypto.PublicKey)
pkg/client/rp/key_binding_test.go:195
↓ 1 callers
Function
testRelyingPartySession
(t *testing.T, wrapServer bool, cookieSpec cookieSpec)
pkg/client/integration_test.go:128
↓ 1 callers
Function
testResourceServerTokenExchange
(t *testing.T, wrapServer bool)
pkg/client/integration_test.go:273
↓ 1 callers
Function
toJoseSignatureAlgorithms
TODO(v4): Use the new jose.SignatureAlgorithm type directly, instead of string.
pkg/oidc/verifier.go:234
↓ 1 callers
Function
tokenHandler
(exchanger Exchanger)
pkg/op/token_request.go:30
↓ 1 callers
Function
tryReadStateCookie
(w http.ResponseWriter, r *http.Request, rp RelyingParty)
pkg/client/rp/relying_party.go:709
↓ 1 callers
Function
trySetStateCookie
(r *http.Request, w http.ResponseWriter, state string, rp RelyingParty)
pkg/client/rp/relying_party.go:693
↓ 1 callers
Method
updateKeys
(ctx context.Context)
pkg/client/rp/jwks.go:195
↓ 1 callers
Function
userinfoHandler
(userinfoProvider UserinfoProvider)
pkg/op/userinfo.go:20
↓ 1 callers
Function
validateAuthReqRedirectURINative
ValidateAuthReqRedirectURINative validates the passed redirect_uri and response_type to the registered uris and client type
pkg/op/auth_request.go:366
↓ 1 callers
Function
verifyDeviceKeyBinding
verifyDeviceKeyBinding checks that the ID Token returned by the device token endpoint is actually bound to the expected RP's key.
pkg/client/rp/device.go:124
↓ 1 callers
Method
verifySignatureCached
verifySignatureCached checks for a matching key in the cached key list if there is only one possible, it tries to verify the signature and will retur
pkg/client/rp/jwks.go:114
↓ 1 callers
Method
verifySignatureRemote
(ctx context.Context, jws *jose.JSONWebSignature, keyID, alg string)
pkg/client/rp/jwks.go:142
↓ 1 callers
Function
verifyTokenResponse
(ctx context.Context, token *oauth2.Token, rp RelyingParty)
pkg/client/rp/relying_party.go:517
↓ 1 callers
Method
wait
wait returns a channel that multiple goroutines can receive on. Once it returns a value, the inflight request is done and result() can be inspected.
pkg/client/rp/jwks.go:69
↓ 1 callers
Function
writeError
(w http.ResponseWriter, r *http.Request, err *oidc.Error, statusCode int)
pkg/op/error.go:200
Function
ACRVerify
ACRVerify is a oidc.ACRVerifier func.
internal/testutil/token.go:175
Method
AccessTokenLifetime
()
pkg/op/server_http_test.go:125
Method
AccessTokenLifetime
()
pkg/op/mock/storage.mock.impl.go:124
Method
AccessTokenType
AccessTokenType must return the type of access token the client uses (Bearer (opaque) or JWT)
example/server/storage/client.go:82
Method
AccessTokenType
()
pkg/op/server_http_test.go:133
Method
AccessTokenType
AccessTokenType mocks base method.
pkg/op/mock/client.mock.go:40
← previous
next →
701–800 of 1,804, ranked by callers