Files
Olivier Meunier 88b7aa504f Oauth2 endpoints
- Dynamic Client Registration (RFC 7591)
- Dynamic Client Registration Management (RFC 7592)
- OAuth2 Authorization Code Grant (RFC 6749)
- OAuth 2.0 Token Revocation (RFC 7009)
- OAuth 2.0 Authorization Server Metadata (RFC 8414)

This introduces new routes as follow:

- GET /.well-known/oauth-authorization-server: authorization server metadata
- GET /authorize : authorization page
- POST /authorize : authorization redirect
- POST /api/oauth/client : client creation
- GET /api/oauth/client/{id} : client information
- PUT /api/oauth/client/{id} : client update
- DELETE /api/oauth/client/{id} : client removal
- POST /api/oauth/token : token retrieval
- POST /api/oauth/revoke: token revocation

Other considerations:

- The authorization flow MUST use PKCE with S256 (plain is not allowed).
- At least one scope is mandatory.
- There is no refresh token.
- There is no client_secret.

This commit also moves the API token signing to config.SigningKey
with corresponding methods. (This type, with another key) is also used
for client registration management tokens)
2025-10-24 18:23:04 +02:00
..
2025-05-10 13:22:01 +02:00
2025-10-24 18:23:04 +02:00