The checks of an access token that a resource server makes, e.g. a Micropub endpoint: in the store of tokens of a server in the same process, or at the introspection endpoint of one in another.
The code follows sections 6 and 8 of the IndieAuth Living Standard of 11 July 2024, https://indieauth.spec.indieweb.org/, and RFC 6750.
The checks of an access token that a resource server makes, e.g. a Micropub endpoint: in the store of tokens of a server in the same process, or at the introspection endpoint of one in another. The code follows sections 6 and 8 of the IndieAuth Living Standard of 11 July 2024, https://indieauth.spec.indieweb.org/, and RFC 6750.
(access! request scopes {:keys [tokens] :as opts})What the server keeps of the access token of the Ring request, if it
grants one of the scopes, or any scope when they're empty, as
token-info! gives it. Else a map of the :error, as access-problem gives
it, and the Ring :response to answer with. In ClojureScript, it gives a
promise.
In the server's own process, give its :tokens store in opts, and else
the :introspection-endpoint and :resource-token of introspect!. Whether
the token's :me may use the resource is up to you.
What the server keeps of the access token of the Ring `request`, if it grants one of the `scopes`, or any scope when they're empty, as token-info! gives it. Else a map of the :error, as access-problem gives it, and the Ring :response to answer with. In ClojureScript, it gives a promise. In the server's own process, give its :tokens store in `opts`, and else the :introspection-endpoint and :resource-token of introspect!. Whether the token's :me may use the resource is up to you.
(access-problem info scopes)Why the access token of info, as token-info! gives it, can't be used
for a request that needs one of the scopes, or any scope when they're
empty, as a map of the :status, the :code and the :reason, or nil when
it can.
Why the access token of `info`, as token-info! gives it, can't be used for a request that needs one of the `scopes`, or any scope when they're empty, as a map of the :status, the :code and the :reason, or nil when it can.
(bearer-token request)The access token of the Ring request: that of its Authorization
header, or else the access_token of its :form-params, as a Micropub
client can send it. Nil when it has none.
The access token of the Ring `request`: that of its Authorization header, or else the access_token of its :form-params, as a Micropub client can send it. Nil when it has none.
The default of each option of a resource server that has one:
The default of each option of a resource server that has one: - :timeout-seconds, 10, and :max-json-bytes, 256 kB: the limits of a request to an introspection endpoint - :send, http/send-public!, which sends to the public internet alone - :now-fn, a function that gives the instant now
(header-token request)The bearer token of the Authorization header of the Ring request, or
nil.
The bearer token of the Authorization header of the Ring `request`, or nil.
(introspect! token {:keys [introspection-endpoint resource-token] :as opts})Ask the :introspection-endpoint of opts about the access token, with
the :resource-token of opts, and give what it says as token-info!
does, nil for a token that isn't active, or a map of the :error when it
can't be asked. In ClojureScript, it gives a promise.
A resource server checks the tokens of a server in another process this
way. The resource token can be a hidden text, and the opts are also
those of http/send!, and :send.
Ask the :introspection-endpoint of `opts` about the access `token`, with the :resource-token of `opts`, and give what it says as token-info! does, nil for a token that isn't active, or a map of the :error when it can't be asked. In ClojureScript, it gives a promise. A resource server checks the tokens of a server in another process this way. The resource token can be a hidden text, and the `opts` are also those of http/send!, and :send.
(problem-response {:keys [status code reason scope] :as problem})The Ring response of the problem of access-problem, with the
WWW-Authenticate header of a bearer token for a status of 401 or 403. A
problem without a :code is that of a request without a token, whose
answer says no more, as section 8.1 has it.
The Ring response of the `problem` of access-problem, with the WWW-Authenticate header of a bearer token for a status of 401 or 403. A problem without a :code is that of a request without a token, whose answer says no more, as section 8.1 has it.
(token-info! token opts)What the :tokens store of opts keeps of the access token: a map of
the :me, :client-id, :scope, :issued-at and :expires, and the id of its
:grant, or nil when the token is unknown, revoked or expired. A refresh
token is no access token. In ClojureScript, it gives a promise.
What the :tokens store of `opts` keeps of the access `token`: a map of the :me, :client-id, :scope, :issued-at and :expires, and the id of its :grant, or nil when the token is unknown, revoked or expired. A refresh token is no access token. In ClojureScript, it gives a promise.
cljdoc builds & hosts documentation for Clojure/Script libraries
| Ctrl+k | Jump to recent docs |
| ← | Move to previous article |
| → | Move to next article |
| Ctrl+/ | Jump to the search field |