Expand description
“Sign in with GitHub / Google”: the OAuth 2.0 authorization code flow with PKCE.
ocre g auth --oauth github (or google) generates the routes that use
this module (src/oauth.rs in the app): GET /auth/github redirects to
the provider with a random state and a PKCE challenge kept in the
session; GET /auth/github/callback checks the state, trades the code
for an access token (exchange_code), reads the user’s Profile
(profile) and signs the matching user in.
Each provider needs an OAuth app registered with it; its client id and
secret are Worker secrets named after the provider (GITHUB_CLIENT_ID,
GITHUB_CLIENT_SECRET, see Provider::client_id_secret), in
.dev.vars for ocre dev and uploaded with ocre secrets push NAME --file .prod.vars.
§Free plan
A sign-in makes 2 subrequests (Google) or 3 (GitHub: user and emails) out of the 50 a free-plan request may make, and a few milliseconds of CPU; no D1, KV or queue operation here (the app then reads and writes its users).
use ocre::oauth::{GITHUB, Pkce, authorize_url};
let pkce = Pkce::new();
let state = ocre::token::generate();
let url = authorize_url(&GITHUB, "client-id", "https://app.example.com/auth/github/callback", &state, &pkce.challenge);
assert!(url.starts_with("https://github.com/login/oauth/authorize?response_type=code&client_id=client-id"));Structs§
- Pkce
- A PKCE pair (RFC 7636,
S256): keep the verifier in the session, send the challenge. - Profile
- The user a provider signed in: its id there, and its email when verified.
- Provider
- An OAuth 2.0 provider: its endpoints and the scopes Ocre asks for.
Constants§
- GITHUB
- GitHub (OAuth app or GitHub App): scopes
read:user user:email. - Google (OpenID Connect): scopes
openid email profile. - PROVIDERS
- Every provider Ocre knows:
ocre g auth --oauthaccepts these names.
Functions§
- authorize_
url - The URL to send the browser to: the provider’s sign-in page for this app.
- exchange_
code - Trades the authorization
codefrom the callback for an access token (one subrequest). - profile
- Reads the signed-in user’s
Profilewith an access token (one subrequest; two for GitHub). - provider
- The provider called
name("github","google"), if Ocre knows it.