mirror of
https://codeberg.org/readeck/readeck.git
synced 2026-06-18 11:04:36 +00:00
- Dynamic Client Registration (RFC 7591)
- Dynamic Client Registration Management (RFC 7592)
- OAuth2 Authorization Code Grant (RFC 6749)
- OAuth 2.0 Token Revocation (RFC 7009)
- OAuth 2.0 Authorization Server Metadata (RFC 8414)
This introduces new routes as follow:
- GET /.well-known/oauth-authorization-server: authorization server metadata
- GET /authorize : authorization page
- POST /authorize : authorization redirect
- POST /api/oauth/client : client creation
- GET /api/oauth/client/{id} : client information
- PUT /api/oauth/client/{id} : client update
- DELETE /api/oauth/client/{id} : client removal
- POST /api/oauth/token : token retrieval
- POST /api/oauth/revoke: token revocation
Other considerations:
- The authorization flow MUST use PKCE with S256 (plain is not allowed).
- At least one scope is mandatory.
- There is no refresh token.
- There is no client_secret.
This commit also moves the API token signing to config.SigningKey
with corresponding methods. (This type, with another key) is also used
for client registration management tokens)