Liking cljdoc? Tell your friends :D

synthigy.client.login

clj

OIDC authorization-code + PKCE — the protocol half of a browser login.

Owns the PKCE pair, the authorize URL, the code exchange and reading the user out of the id_token. Sessions, cookies and redirects stay the app's. The one piece of state the protocol needs — the in-flight login, from /login until the callback — lives in a login store, a map {:put-fn (fn [state login]) :take-fn (fn [state])} passed to connect! as :login-store. take-fn is one-shot.

JVM only: the exchange authenticates as a confidential client, and a browser can't hold a secret.

OIDC authorization-code + PKCE — the protocol half of a browser login.

Owns the PKCE pair, the authorize URL, the code exchange and reading the
user out of the id_token. Sessions, cookies and redirects stay the app's.
The one piece of state the protocol needs — the in-flight login, from
/login until the callback — lives in a login store, a map
`{:put-fn (fn [state login]) :take-fn (fn [state])}` passed to
`connect!` as `:login-store`. `take-fn` is one-shot.

JVM only: the exchange authenticates as a confidential client, and a
browser can't hold a secret.
cljs

Browser OIDC login as a public client: authorization code + PKCE, silent renew through a hidden iframe, tokens in memory only. Pass (provider) to connect!.

Browser OIDC login as a public client: authorization code + PKCE, silent renew
through a hidden iframe, tokens in memory only. Pass `(provider)` to `connect!`.
raw docstring

accept!cljs

(accept! tokens nonce)
source

authorization-errorcljs

(authorization-error {:keys [error error-description]})
source

authorize-urlcljs

(authorize-url {:keys [endpoint client-id scope audience]}
               {:keys [redirect-uri state nonce code-challenge prompt]})
source

b64urlcljs

(b64url bytes)
source

b64url-encodeclj

(b64url-encode raw)
source

callback-paramscljs

(callback-params href)

The authorization response carried by href, or nil when it carries none.

The authorization response carried by `href`, or nil when it carries none.
sourceraw docstring

callback?cljs

(callback?)
source

cancelclj

(cancel client state)
source

clear-timers!cljs

(clear-timers!)
source

completeclj

(complete client code state redirect-uri)
source

configcljs

(config)
source

configure!cljs

(configure! {:keys [endpoint client-id redirect-uri] :as opts})

Set :endpoint, :client-id, :redirect-uri and optional :silent-redirect-uri, :post-logout-redirect-uri, :scope, :audience, :load-user-info?.

Set :endpoint, :client-id, :redirect-uri and optional :silent-redirect-uri, :post-logout-redirect-uri, :scope, :audience, :load-user-info?.
sourceraw docstring

configured?cljs

(configured?)
source

decode-jwt-payloadclj/s≠

(decode-jwt-payload jwt)
clj

A JWT's payload, unverified — only for a token from our own authenticated token POST.

A JWT's payload, unverified — only for a token from our own authenticated token POST.
cljs

A JWT's payload, unverified — only for a token from our own token response.

A JWT's payload, unverified — only for a token from our own token response.
source (clj)source (cljs)raw docstring

defaultscljs

source

emit!cljs

(emit! event payload)
source

exchangecljs

(exchange {:keys [endpoint client-id]}
          code
          {:keys [redirect-uri code-verifier]})

Authorization code → token response, as a public client (no secret).

Authorization code → token response, as a public client (no secret).
sourceraw docstring

login-cancelcljs

(login-cancel)

Drop the login the current URL returns from; resolves {:return-to}.

Drop the login the current URL returns from; resolves {:return-to}.
sourceraw docstring

login-completecljs

(login-complete)

Finish the login the current URL returns from; resolves {:user :return-to}, or nil when the URL carries no response.

Finish the login the current URL returns from; resolves {:user :return-to}, or nil when the URL carries no response.
sourceraw docstring

login-startcljs

(login-start & {:keys [prompt return-to]})

Redirect the page to the authorize endpoint; :prompt "none" returns without a login form when a session is alive.

Redirect the page to the authorize endpoint; `:prompt "none"` returns without a login form when a session is alive.
sourceraw docstring

login-ttl-msclj

source

logout!cljs

(logout!)

End the server session and redirect to :post-logout-redirect-uri.

End the server session and redirect to :post-logout-redirect-uri.
sourceraw docstring

memory-login-storeclj

(memory-login-store)
(memory-login-store {:keys [ttl-ms] :or {ttl-ms login-ttl-ms}})

In-flight logins in an atom — SINGLE PROCESS ONLY; behind a load balancer use a shared store.

In-flight logins in an atom — SINGLE PROCESS ONLY; behind a load balancer use a shared store.
sourceraw docstring

message-sourcecljs

source

no-login-store-errorclj

(no-login-store-error)
source

oncljs

(on event f)

Subscribe to :user-loaded, :user-unloaded, :access-token-expiring, :access-token-expired or :silent-renew-error.

Subscribe to :user-loaded, :user-unloaded, :access-token-expiring, :access-token-expired or :silent-renew-error.
sourceraw docstring

pending-prefixcljs

source

pending-ttl-mscljs

source

pkceclj/s≠

(pkce)
clj

A fresh PKCE verifier and its S256 challenge (RFC 7636).

A fresh PKCE verifier and its S256 challenge (RFC 7636).
cljs

A fresh PKCE verifier and its S256 challenge (RFC 7636), as a promise.

A fresh PKCE verifier and its S256 challenge (RFC 7636), as a promise.
source (clj)source (cljs)raw docstring

providercljs

(provider)

{:token-fn :invalidate-fn} for connect!; a 401 retry waits for the renewal it triggers.

`{:token-fn :invalidate-fn}` for `connect!`; a 401 retry waits for the renewal it triggers.
sourceraw docstring

put-pending!cljs

(put-pending! {:keys [state] :as request} return-to)
source

query-stringclj

(query-string pairs)
source

randomclj

source

random-tokenclj/s

(random-token n)
source (clj)source (cljs)

rejecting-login-storeclj

(rejecting-login-store)

The default store: refuses rather than silently keeping logins in one process.

The default store: refuses rather than silently keeping logins in one process.
sourceraw docstring

remove-user!cljs

(remove-user!)

Forget the tokens locally without ending the server session.

Forget the tokens locally without ending the server session.
sourceraw docstring

renew!cljs

(renew!)

Silent renew through a hidden iframe with prompt=none; resolves the user, one renewal at a time.

Silent renew through a hidden iframe with prompt=none; resolves the user, one renewal at a time.
sourceraw docstring

require-confidentialclj

(require-confidential {:keys [client-id client-secret-fn]})
source

schedule!cljs

(schedule! expires-at)
source

silent-callback!cljs

(silent-callback!)

Call first thing on the silent redirect page; true when this window was a renewal iframe and has answered it.

Call first thing on the silent redirect page; true when this window was a renewal iframe and has answered it.
sourceraw docstring

silent-framecljs

(silent-frame cfg request)
source

startclj

(start client
       redirect-uri
       {:keys [return-to scope public-endpoint]
        :or {return-to "/" scope "openid"}})
source

start-requestcljs

(start-request redirect-uri prompt)

PKCE pair, state and nonce for one authorize round trip.

PKCE pair, state and nonce for one authorize round trip.
sourceraw docstring

statecljs

source

storeclj

(store client)
source

strip-callback!cljs

(strip-callback!)
source

take-pendingclj

(take-pending client state)

Take a pending login, refusing one older than login-ttl-ms even when the store kept it.

Take a pending login, refusing one older than login-ttl-ms even when the store kept it.
sourceraw docstring

take-pending!cljs

(take-pending! state)
source

tokencljs

(token)
source

usercljs

(user)
source

user-infocljs

(user-info {:keys [endpoint]} access-token)

GET /oauth/userinfo with the fresh access token.

GET /oauth/userinfo with the fresh access token.
sourceraw docstring

cljdoc builds & hosts documentation for Clojure/Script libraries

Keyboard shortcuts
Ctrl+kJump to recent docs
←Move to previous article
→Move to next article
Ctrl+/Jump to the search field
× close