IndieAuth for clients: the identifiers of users, clients and servers, the discovery of a user's server, and signing in with it.
The code follows the IndieAuth Living Standard of 11 July 2024 at https://indieauth.spec.indieweb.org/ and cites its sections. The server is in dk.simongray.indieauth.server, the checks of a resource server in dk.simongray.indieauth.resource, the signed maps that carry a value through a browser in dk.simongray.indieauth.signed, and the signed state of a sign-in, which other protocols can use too, in dk.simongray.indieauth.state. The other namespaces are internal and named for what they hold, e.g. identifier for the rules of identifiers and grant for the codes and tokens of a server.
IndieAuth for clients: the identifiers of users, clients and servers, the discovery of a user's server, and signing in with it. The code follows the IndieAuth Living Standard of 11 July 2024 at https://indieauth.spec.indieweb.org/ and cites its sections. The server is in dk.simongray.indieauth.server, the checks of a resource server in dk.simongray.indieauth.resource, the signed maps that carry a value through a browser in dk.simongray.indieauth.signed, and the signed state of a sign-in, which other protocols can use too, in dk.simongray.indieauth.state. The other namespaces are internal and named for what they hold, e.g. identifier for the rules of identifiers and grant for the codes and tokens of a server.
The checks of an access token that a resource server makes, e.g. a Micropub endpoint: in the store of tokens of a server in the same process, or at the introspection endpoint of one in another.
The code follows sections 6 and 8 of the IndieAuth Living Standard of 11 July 2024, https://indieauth.spec.indieweb.org/, and RFC 6750.
The checks of an access token that a resource server makes, e.g. a Micropub endpoint: in the store of tokens of a server in the same process, or at the introspection endpoint of one in another. The code follows sections 6 and 8 of the IndieAuth Living Standard of 11 July 2024, https://indieauth.spec.indieweb.org/, and RFC 6750.
An IndieAuth server: the authorization, token, revocation, introspection and userinfo endpoints and the metadata document.
Signing the user in and asking for consent are up to you: the :authorize function of handler gets the checked request, and approve! gives the client its code when the user says yes. Codes and tokens go in stores of yours, or in memory-store, as hashes. In ClojureScript, the handlers answer with promises, and take a body that has been read.
Its internals are in info, authorization, grant and endpoint.
An IndieAuth server: the authorization, token, revocation, introspection and userinfo endpoints and the metadata document. Signing the user in and asking for consent are up to you: the :authorize function of handler gets the checked request, and approve! gives the client its code when the user says yes. Codes and tokens go in stores of yours, or in memory-store, as hashes. In ClojureScript, the handlers answer with promises, and take a body that has been read. Its internals are in info, authorization, grant and endpoint.
Maps signed with a secret into URL-safe texts, so that a value can make a round trip through a browser, e.g. in a URL or a form, and come back unchanged, with nothing stored.
A signed map has a kind, a keyword such as :comment, so that one kind never passes for another, and the instant it was signed, so that unsign refuses it after the lifetime you give. The secret is a text of 32 bytes or more, e.g. a token of indieauth/token kept in your configuration, and can be a hidden text of wary-fetch. The map holds EDN values, e.g. texts, keywords, numbers and instants.
Maps signed with a secret into URL-safe texts, so that a value can make a round trip through a browser, e.g. in a URL or a form, and come back unchanged, with nothing stored. A signed map has a kind, a keyword such as :comment, so that one kind never passes for another, and the instant it was signed, so that unsign refuses it after the lifetime you give. The secret is a text of 32 bytes or more, e.g. a token of indieauth/token kept in your configuration, and can be a hidden text of wary-fetch. The map holds EDN values, e.g. texts, keywords, numbers and instants.
The state of an authorization request and the PKCE code verifier that goes with it: random, or with a secret, a state that carries the session, signed, and that a nonce ties to the browser.
The kind of a state is a keyword of its sign-in protocol, e.g. :dk.simongray.indieauth/session, so that under a shared secret the state of one protocol never passes for that of another.
The state of an authorization request and the PKCE code verifier that goes with it: random, or with a secret, a state that carries the session, signed, and that a nonce ties to the browser. The kind of a state is a keyword of its sign-in protocol, e.g. :dk.simongray.indieauth/session, so that under a shared secret the state of one protocol never passes for that of another.
cljdoc builds & hosts documentation for Clojure/Script libraries
| Ctrl+k | Jump to recent docs |
| ← | Move to previous article |
| → | Move to next article |
| Ctrl+/ | Jump to the search field |