RelMeAuth: signing a user in as their website, with an account at GitHub or on a Mastodon server that the site names with rel=me.
A sign-in counts when the account that signed in is the one that the site names, and when it links back to the site. The code follows https://indieweb.org/RelMeAuth and the algorithm at https://microformats.org/wiki/relmeauth. The URLs that a user can sign in as, and their canonical form, are those of IndieAuth, from indieauth-clj.
RelMeAuth: signing a user in as their website, with an account at GitHub or on a Mastodon server that the site names with rel=me. A sign-in counts when the account that signed in is the one that the site names, and when it links back to the site. The code follows https://indieweb.org/RelMeAuth and the algorithm at https://microformats.org/wiki/relmeauth. The URLs that a user can sign in as, and their canonical form, are those of IndieAuth, from indieauth-clj.
(account-problem session info)(account-problem {:keys [me urls account] :as session} info opts)What's wrong with the info of the account that signed in, the JSON of
the provider's API, for the session and by opts, as a map of the
:type and the :reason, or nil.
The account must be the session's, by its username in any case, and it must link back to one of the session's :urls.
What's wrong with the `info` of the account that signed in, the JSON of the provider's API, for the `session` and by `opts`, as a map of the :type and the :reason, or nil. The account must be the session's, by its username in any case, and it must link back to one of the session's :urls.
(accounts response opts)The accounts that the rel=me links of the page in the response name,
at the providers that opts set up: GitHub with :github and Mastodon
servers with :mastodon. They come in the order of the page, once each.
The accounts that the rel=me links of the page in the `response` name, at the providers that `opts` set up: GitHub with :github and Mastodon servers with :mastodon. They come in the order of the page, once each.
(authorization-request! {:keys [me urls] :as discovery} account opts)Give the URL at the provider of the account to send the user's browser
to, and the session to keep until the browser comes back, as a map of
:url and :session, for the discovery of discover!, by opts:
Keep the session for the browser's next request, or with a :secret, its :cookie in an HttpOnly cookie. A session too large for a cookie throws. A Mastodon server that refuses to register your app gives a map of the :error. In ClojureScript, it gives a promise.
Give the URL at the provider of the `account` to send the user's browser to, and the session to keep until the browser comes back, as a map of :url and :session, for the `discovery` of discover!, by `opts`: - :redirect-uri, the URL that the browser comes back to - :github, the :client-id and :client-secret of your GitHub OAuth app, the secret as a hidden text of wary-fetch - :mastodon, the :registrations store, e.g. memory-store, and the :client-name and :website that a server shows of your app - :secret, a text of 32 bytes or more, to carry the session in a cookie, signed, for state-session - :data, any EDN of yours that the session carries Keep the session for the browser's next request, or with a :secret, its :cookie in an HttpOnly cookie. A session too large for a cookie throws. A Mastodon server that refuses to register your app gives a map of the :error. In ClojureScript, it gives a promise.
(callback-problem {:keys [state] :as session} params)What's wrong with the query params that the browser came back with,
for the session, as a map of the :type and the :reason, or nil.
The state must be the session's. An error of the provider, e.g. access_denied when the user said no, is an ::authorization-error with the provider's :code.
What's wrong with the query `params` that the browser came back with, for the `session`, as a map of the :type and the :reason, or nil. The state must be the session's. An error of the provider, e.g. access_denied when the user said no, is an ::authorization-error with the provider's :code.
The default of each option that has one:
The default of each option that has one: - :profile-url-pred, indieauth/profile-url?, the URLs that a user can sign in as, those that IndieAuth takes - :silo-urls?, false: refuse a URL that is an account at a provider, e.g. https://github.com/ann, since it isn't the user's own - :trim-slash?, true: let a link back differ from the user's URL by a slash at the end of its path - :session-seconds, 600: how long a user has to sign in at the provider, and how long a signed session lasts - :max-cookie-bytes, state/max-cookie-bytes: the largest cookie of a signed session, past which authorization-request! throws - :timeout-seconds, 10: the limit of each request - :max-redirects, 5: how many redirects the fetch of the user's page follows - :max-page-bytes, 2 MB: the largest page of a user - :max-json-bytes, 256 kB: the largest JSON document of a provider - :send, http/send-public!, which sends to the public internet alone - :now-fn, a function that gives the instant now
(discover! url opts)Fetch the page of the profile URL url with opts, and give its
discovery, or a map of the :error. In ClojureScript, it gives a promise.
Fetch the page of the profile URL `url` with `opts`, and give its discovery, or a map of the :error. In ClojureScript, it gives a promise.
(discovery url {:keys [redirects] :as response} opts)The accounts that the user of the profile URL url can sign in with,
from the response of its page that you fetched, by opts, as a map:
A URL that a user can't sign in as gives a map of the :error, with its
:type and :reason. The opts are those of default-options and
authorization-request!.
The accounts that the user of the profile URL `url` can sign in with, from the `response` of its page that you fetched, by `opts`, as a map: - :me, the URL in canonical form - :urls, the URLs that the fetch went through: :me, those that redirected, and the last, in canonical form - :accounts, those of the accounts function A URL that a user can't sign in as gives a map of the :error, with its :type and :reason. The `opts` are those of default-options and authorization-request!.
(memory-store)(memory-store a)A store of registrations in the atom a, or in a new one, as a map of
the :instance of each Mastodon server to your app's registration there.
A store is a map of :get, a function of an instance that gives its registration or nil, and :put!, a function of an instance and a registration that keeps it. Either can give a promise in ClojureScript. A registration is a map of the :client-id, :client-secret, :scope, :redirect-uri and, if it expires, :expires. Its client secret is a hidden text of wary-fetch, so reveal it to write it as EDN.
A store of registrations in the atom `a`, or in a new one, as a map of the :instance of each Mastodon server to your app's registration there. A store is a map of :get, a function of an instance that gives its registration or nil, and :put!, a function of an instance and a registration that keeps it. Either can give a promise in ClojureScript. A registration is a map of the :client-id, :client-secret, :scope, :redirect-uri and, if it expires, :expires. Its client secret is a hidden text of wary-fetch, so reveal it to write it as EDN.
(redeem! {:keys [me account] :as session} params opts)Finish signing in when the user's browser comes back with the query
params, for the session of authorization-request!, by opts, and
give a map of the :me and the :account that signed in. In
ClojureScript, it gives a promise.
The params must pass callback-problem, and the account account-problem. A failure gives a map of the :error. The :me keeps any slash at its end, and the access token isn't kept.
Finish signing in when the user's browser comes back with the query `params`, for the `session` of authorization-request!, by `opts`, and give a map of the :me and the :account that signed in. In ClojureScript, it gives a promise. The params must pass callback-problem, and the account account-problem. A failure gives a map of the :error. The :me keeps any slash at its end, and the access token isn't kept.
(state-session secret state cookie)(state-session secret state cookie opts)The session that the signed cookie carries, which
authorization-request! gave with the secret, if its state is the
state that came back, or nil. It's nil too when the cookie is older
than the :session-seconds of opts.
The cookie comes from the browser that came back, so that only the browser that started the sign-in can finish it.
The session that the signed `cookie` carries, which authorization-request! gave with the `secret`, if its state is the `state` that came back, or nil. It's nil too when the cookie is older than the :session-seconds of `opts`. The cookie comes from the browser that came back, so that only the browser that started the sign-in can finish it.
cljdoc builds & hosts documentation for Clojure/Script libraries
| Ctrl+k | Jump to recent docs |
| ← | Move to previous article |
| → | Move to next article |
| Ctrl+/ | Jump to the search field |