OIDC authorization-code + PKCE — the protocol half of a browser login.
Owns the PKCE pair, the authorize URL, the code exchange and reading the
user out of the id_token. Sessions, cookies and redirects stay the app's.
The one piece of state the protocol needs — the in-flight login, from
/login until the callback — lives in a login store, a map
{:put-fn (fn [state login]) :take-fn (fn [state])} passed to
connect! as :login-store. take-fn is one-shot.
JVM only: the exchange authenticates as a confidential client, and a browser can't hold a secret.
OIDC authorization-code + PKCE — the protocol half of a browser login.
Owns the PKCE pair, the authorize URL, the code exchange and reading the
user out of the id_token. Sessions, cookies and redirects stay the app's.
The one piece of state the protocol needs — the in-flight login, from
/login until the callback — lives in a login store, a map
`{:put-fn (fn [state login]) :take-fn (fn [state])}` passed to
`connect!` as `:login-store`. `take-fn` is one-shot.
JVM only: the exchange authenticates as a confidential client, and a
browser can't hold a secret.Browser OIDC login as a public client: authorization code + PKCE, silent renew
through a hidden iframe, tokens in memory only. Pass (provider) to connect!.
Browser OIDC login as a public client: authorization code + PKCE, silent renew through a hidden iframe, tokens in memory only. Pass `(provider)` to `connect!`.
(authorize-url {:keys [endpoint client-id scope audience]}
{:keys [redirect-uri state nonce code-challenge prompt]})(callback-params href)The authorization response carried by href, or nil when it carries none.
The authorization response carried by `href`, or nil when it carries none.
(configure! {:keys [endpoint client-id redirect-uri] :as opts})Set :endpoint, :client-id, :redirect-uri and optional :silent-redirect-uri, :post-logout-redirect-uri, :scope, :audience, :load-user-info?.
Set :endpoint, :client-id, :redirect-uri and optional :silent-redirect-uri, :post-logout-redirect-uri, :scope, :audience, :load-user-info?.
(decode-jwt-payload jwt)A JWT's payload, unverified — only for a token from our own authenticated token POST.
A JWT's payload, unverified — only for a token from our own authenticated token POST.
A JWT's payload, unverified — only for a token from our own token response.
A JWT's payload, unverified — only for a token from our own token response.
(exchange {:keys [endpoint client-id]}
code
{:keys [redirect-uri code-verifier]})Authorization code → token response, as a public client (no secret).
Authorization code → token response, as a public client (no secret).
(login-cancel)Drop the login the current URL returns from; resolves {:return-to}.
Drop the login the current URL returns from; resolves {:return-to}.
(login-complete)Finish the login the current URL returns from; resolves {:user :return-to}, or nil when the URL carries no response.
Finish the login the current URL returns from; resolves {:user :return-to}, or nil when the URL carries no response.
(login-start & {:keys [prompt return-to]})Redirect the page to the authorize endpoint; :prompt "none" returns without a login form when a session is alive.
Redirect the page to the authorize endpoint; `:prompt "none"` returns without a login form when a session is alive.
(logout!)End the server session and redirect to :post-logout-redirect-uri.
End the server session and redirect to :post-logout-redirect-uri.
(memory-login-store)(memory-login-store {:keys [ttl-ms] :or {ttl-ms login-ttl-ms}})In-flight logins in an atom — SINGLE PROCESS ONLY; behind a load balancer use a shared store.
In-flight logins in an atom — SINGLE PROCESS ONLY; behind a load balancer use a shared store.
(on event f)Subscribe to :user-loaded, :user-unloaded, :access-token-expiring, :access-token-expired or :silent-renew-error.
Subscribe to :user-loaded, :user-unloaded, :access-token-expiring, :access-token-expired or :silent-renew-error.
(pkce)A fresh PKCE verifier and its S256 challenge (RFC 7636).
A fresh PKCE verifier and its S256 challenge (RFC 7636).
A fresh PKCE verifier and its S256 challenge (RFC 7636), as a promise.
A fresh PKCE verifier and its S256 challenge (RFC 7636), as a promise.
(provider){:token-fn :invalidate-fn} for connect!; a 401 retry waits for the renewal it triggers.
`{:token-fn :invalidate-fn}` for `connect!`; a 401 retry waits for the renewal it triggers.
(rejecting-login-store)The default store: refuses rather than silently keeping logins in one process.
The default store: refuses rather than silently keeping logins in one process.
(remove-user!)Forget the tokens locally without ending the server session.
Forget the tokens locally without ending the server session.
(renew!)Silent renew through a hidden iframe with prompt=none; resolves the user, one renewal at a time.
Silent renew through a hidden iframe with prompt=none; resolves the user, one renewal at a time.
(silent-callback!)Call first thing on the silent redirect page; true when this window was a renewal iframe and has answered it.
Call first thing on the silent redirect page; true when this window was a renewal iframe and has answered it.
(start client
redirect-uri
{:keys [return-to scope public-endpoint]
:or {return-to "/" scope "openid"}})(start-request redirect-uri prompt)PKCE pair, state and nonce for one authorize round trip.
PKCE pair, state and nonce for one authorize round trip.
(take-pending client state)Take a pending login, refusing one older than login-ttl-ms even when the store kept it.
Take a pending login, refusing one older than login-ttl-ms even when the store kept it.
(user-info {:keys [endpoint]} access-token)GET /oauth/userinfo with the fresh access token.
GET /oauth/userinfo with the fresh access token.
cljdoc builds & hosts documentation for Clojure/Script libraries
| Ctrl+k | Jump to recent docs |
| ← | Move to previous article |
| → | Move to next article |
| Ctrl+/ | Jump to the search field |