4 ms·
I can't recommend enough Zitadel and its OIDC library. Code is very well-writen and informative. Highly encourage everyone jump into source code and explore ho
by adeptima 3y ago
I can't recommend enough Zitadel and its OIDC library. Code is very well-writen and informative.
Highly encourage everyone jump into source code and explore how IntrospectionResponse struct work with all related code around
https://github.com/zitadel/oidc/blob/main/pkg/oidc/introspection.go https://github.com/zitadel/oidc/blob/main/pkg/oidc/introspec...
// IntrospectionResponse implements RFC 7662, section 2.2 and
// OpenID Connect Core 1.0, section 5.1 (UserInfo).
// https://www.rfc-editor.org/rfc/rfc7662.html#section-2.2 https://www.rfc-editor.org/rfc/rfc7662.html#section-2.2.
// https://openid.net/specs/openid-connect-core-1_0.html#StandardClaims https://openid.net/specs/openid-connect-core-1_0.html#Standa....
type IntrospectionResponse struct {
Active Scope ClientID TokenType ... exp iat nbf sub
Audience ... aud ...
JWTID ... Claims map[string]any
}
If you want to explore the difference between identity providers, click through
https://github.com/nextauthjs/next-auth/tree/main/packages/core/src/providers https://github.com/nextauthjs/next-auth/tree/main/packages/c...
Azure is the most insane ... and it's a lot of fun to compare them all against each other.
Next go though PKCE (Proof Key for Code Exchange) and look how code_challenge, code_verifier works or at least see interfaces .
Ory Fosite is a great alternative too
https://github.com/ory/fosite https://github.com/ory/fosite
Support PKCE #59835 in x/oauth2
https://github.com/golang/go/issues/59835 https://github.com/golang/go/issues/59835
Scott Brady's content is great for undetstanding the topic
SPA Identity and Access Control with OpenID Connect https://www.youtube.com/watch?v=rP3St0GU_Bk https://www.youtube.com/watch?v=rP3St0GU_Bk
OAuth is Not Authentication https://www.scottbrady91.com/oauth/oauth-is-not-authentication https://www.scottbrady91.com/oauth/oauth-is-not-authenticati...
SPA is a landmine ..
OAuth 2 0 and OpenID Connect for Single Page Applications Philippe De Ryck https://www.youtube.com/watch?v=XoBtUn4XczU https://www.youtube.com/watch?v=XoBtUn4XczU
The deeper you go into the topic the more you will discover. It's an ultimate "rabbit hole" - web, native, SPA flows, PKCE, JWT, session storage, custome middleware for your favorite flavor of backend framework, etc