Liking cljdoc? Tell your friends :D

dk.simongray.relmeauth

RelMeAuth: signing a user in as their website, with an account at GitHub or on a Mastodon server that the site names with rel=me.

A sign-in counts when the account that signed in is the one that the site names, and when it links back to the site. The code follows https://indieweb.org/RelMeAuth and the algorithm at https://microformats.org/wiki/relmeauth. The URLs that a user can sign in as, and their canonical form, are those of IndieAuth, from indieauth-clj.

RelMeAuth: signing a user in as their website, with an account at GitHub
or on a Mastodon server that the site names with rel=me.

A sign-in counts when the account that signed in is the one that the
site names, and when it links back to the site. The code follows
https://indieweb.org/RelMeAuth and the algorithm at
https://microformats.org/wiki/relmeauth. The URLs that a user can sign
in as, and their canonical form, are those of IndieAuth, from
indieauth-clj.
raw docstring

account-problemclj/s

(account-problem session info)
(account-problem {:keys [me urls account] :as session} info opts)

What's wrong with the info of the account that signed in, the JSON of the provider's API, for the session and by opts, as a map of the :type and the :reason, or nil.

The account must be the session's, by its username in any case, and it must link back to one of the session's :urls.

What's wrong with the `info` of the account that signed in, the JSON of
the provider's API, for the `session` and by `opts`, as a map of the
:type and the :reason, or nil.

The account must be the session's, by its username in any case, and it
must link back to one of the session's :urls.
sourceraw docstring

accountsclj/s

(accounts response opts)

The accounts that the rel=me links of the page in the response name, at the providers that opts set up: GitHub with :github and Mastodon servers with :mastodon. They come in the order of the page, once each.

The accounts that the rel=me links of the page in the `response` name,
at the providers that `opts` set up: GitHub with :github and Mastodon
servers with :mastodon. They come in the order of the page, once each.
sourceraw docstring

authorization-request!clj/s

(authorization-request! {:keys [me urls] :as discovery} account opts)

Give the URL at the provider of the account to send the user's browser to, and the session to keep until the browser comes back, as a map of :url and :session, for the discovery of discover!, by opts:

  • :redirect-uri, the URL that the browser comes back to
  • :github, the :client-id and :client-secret of your GitHub OAuth app, the secret as a hidden text of wary-fetch
  • :mastodon, the :registrations store, e.g. memory-store, and the :client-name and :website that a server shows of your app
  • :secret, a text of 32 bytes or more, to carry the session in a cookie, signed, for state-session
  • :data, any EDN of yours that the session carries

Keep the session for the browser's next request, or with a :secret, its :cookie in an HttpOnly cookie. A session too large for a cookie throws. A Mastodon server that refuses to register your app gives a map of the :error. In ClojureScript, it gives a promise.

Give the URL at the provider of the `account` to send the user's browser
to, and the session to keep until the browser comes back, as a map of
:url and :session, for the `discovery` of discover!, by `opts`:

- :redirect-uri, the URL that the browser comes back to
- :github, the :client-id and :client-secret of your GitHub OAuth app,
  the secret as a hidden text of wary-fetch
- :mastodon, the :registrations store, e.g. memory-store, and the
  :client-name and :website that a server shows of your app
- :secret, a text of 32 bytes or more, to carry the session in a
  cookie, signed, for state-session
- :data, any EDN of yours that the session carries

Keep the session for the browser's next request, or with a :secret, its
:cookie in an HttpOnly cookie. A session too large for a cookie throws.
A Mastodon server that refuses to register your app gives a map of the
:error. In ClojureScript, it gives a promise.
sourceraw docstring

callback-problemclj/s

(callback-problem {:keys [state] :as session} params)

What's wrong with the query params that the browser came back with, for the session, as a map of the :type and the :reason, or nil.

The state must be the session's. An error of the provider, e.g. access_denied when the user said no, is an ::authorization-error with the provider's :code.

What's wrong with the query `params` that the browser came back with,
for the `session`, as a map of the :type and the :reason, or nil.

The state must be the session's. An error of the provider, e.g.
access_denied when the user said no, is an ::authorization-error with
the provider's :code.
sourceraw docstring

default-optionsclj/s

The default of each option that has one:

  • :profile-url-pred, indieauth/profile-url?, the URLs that a user can sign in as, those that IndieAuth takes
  • :silo-urls?, false: refuse a URL that is an account at a provider, e.g. https://github.com/ann, since it isn't the user's own
  • :trim-slash?, true: let a link back differ from the user's URL by a slash at the end of its path
  • :session-seconds, 600: how long a user has to sign in at the provider, and how long a signed session lasts
  • :max-cookie-bytes, state/max-cookie-bytes: the largest cookie of a signed session, past which authorization-request! throws
  • :timeout-seconds, 10: the limit of each request
  • :max-redirects, 5: how many redirects the fetch of the user's page follows
  • :max-page-bytes, 2 MB: the largest page of a user
  • :max-json-bytes, 256 kB: the largest JSON document of a provider
  • :send, http/send-public!, which sends to the public internet alone
  • :now-fn, a function that gives the instant now
The default of each option that has one:

- :profile-url-pred, indieauth/profile-url?, the URLs that a user can
  sign in as, those that IndieAuth takes
- :silo-urls?, false: refuse a URL that is an account at a provider,
  e.g. https://github.com/ann, since it isn't the user's own
- :trim-slash?, true: let a link back differ from the user's URL by a
  slash at the end of its path
- :session-seconds, 600: how long a user has to sign in at the provider,
  and how long a signed session lasts
- :max-cookie-bytes, state/max-cookie-bytes: the largest cookie of a
  signed session, past which authorization-request! throws
- :timeout-seconds, 10: the limit of each request
- :max-redirects, 5: how many redirects the fetch of the user's page
  follows
- :max-page-bytes, 2 MB: the largest page of a user
- :max-json-bytes, 256 kB: the largest JSON document of a provider
- :send, http/send-public!, which sends to the public internet alone
- :now-fn, a function that gives the instant now
sourceraw docstring

discover!clj/s

(discover! url opts)

Fetch the page of the profile URL url with opts, and give its discovery, or a map of the :error. In ClojureScript, it gives a promise.

Fetch the page of the profile URL `url` with `opts`, and give its
discovery, or a map of the :error. In ClojureScript, it gives a promise.
sourceraw docstring

discoveryclj/s

(discovery url {:keys [redirects] :as response} opts)

The accounts that the user of the profile URL url can sign in with, from the response of its page that you fetched, by opts, as a map:

  • :me, the URL in canonical form
  • :urls, the URLs that the fetch went through: :me, those that redirected, and the last, in canonical form
  • :accounts, those of the accounts function

A URL that a user can't sign in as gives a map of the :error, with its :type and :reason. The opts are those of default-options and authorization-request!.

The accounts that the user of the profile URL `url` can sign in with,
from the `response` of its page that you fetched, by `opts`, as a map:

- :me, the URL in canonical form
- :urls, the URLs that the fetch went through: :me, those that
  redirected, and the last, in canonical form
- :accounts, those of the accounts function

A URL that a user can't sign in as gives a map of the :error, with its
:type and :reason. The `opts` are those of default-options and
authorization-request!.
sourceraw docstring

memory-storeclj/s

(memory-store)
(memory-store a)

A store of registrations in the atom a, or in a new one, as a map of the :instance of each Mastodon server to your app's registration there.

A store is a map of :get, a function of an instance that gives its registration or nil, and :put!, a function of an instance and a registration that keeps it. Either can give a promise in ClojureScript. A registration is a map of the :client-id, :client-secret, :scope, :redirect-uri and, if it expires, :expires. Its client secret is a hidden text of wary-fetch, so reveal it to write it as EDN.

A store of registrations in the atom `a`, or in a new one, as a map of
the :instance of each Mastodon server to your app's registration there.

A store is a map of :get, a function of an instance that gives its
registration or nil, and :put!, a function of an instance and a
registration that keeps it. Either can give a promise in ClojureScript.
A registration is a map of the :client-id, :client-secret, :scope,
:redirect-uri and, if it expires, :expires. Its client secret is a hidden
text of wary-fetch, so reveal it to write it as EDN.
sourceraw docstring

redeem!clj/s

(redeem! {:keys [me account] :as session} params opts)

Finish signing in when the user's browser comes back with the query params, for the session of authorization-request!, by opts, and give a map of the :me and the :account that signed in. In ClojureScript, it gives a promise.

The params must pass callback-problem, and the account account-problem. A failure gives a map of the :error. The :me keeps any slash at its end, and the access token isn't kept.

Finish signing in when the user's browser comes back with the query
`params`, for the `session` of authorization-request!, by `opts`, and
give a map of the :me and the :account that signed in. In
ClojureScript, it gives a promise.

The params must pass callback-problem, and the account account-problem.
A failure gives a map of the :error. The :me keeps any slash at its end,
and the access token isn't kept.
sourceraw docstring

state-sessionclj/s

(state-session secret state cookie)
(state-session secret state cookie opts)

The session that the signed cookie carries, which authorization-request! gave with the secret, if its state is the state that came back, or nil. It's nil too when the cookie is older than the :session-seconds of opts.

The cookie comes from the browser that came back, so that only the browser that started the sign-in can finish it.

The session that the signed `cookie` carries, which
authorization-request! gave with the `secret`, if its state is the
`state` that came back, or nil. It's nil too when the cookie is older
than the :session-seconds of `opts`.

The cookie comes from the browser that came back, so that only the
browser that started the sign-in can finish it.
sourceraw docstring

cljdoc builds & hosts documentation for Clojure/Script libraries

Keyboard shortcuts
Ctrl+kJump to recent docs
←Move to previous article
→Move to next article
Ctrl+/Jump to the search field
× close