Skip to main content

Module oauth

Module oauth 

Source
Expand description

“Sign in with GitHub / Google”: the OAuth 2.0 authorization code flow with PKCE.

ocre g auth --oauth github (or google) generates the routes that use this module (src/oauth.rs in the app): GET /auth/github redirects to the provider with a random state and a PKCE challenge kept in the session; GET /auth/github/callback checks the state, trades the code for an access token (exchange_code), reads the user’s Profile (profile) and signs the matching user in.

Each provider needs an OAuth app registered with it; its client id and secret are Worker secrets named after the provider (GITHUB_CLIENT_ID, GITHUB_CLIENT_SECRET, see Provider::client_id_secret), in .dev.vars for ocre dev and uploaded with ocre secrets push NAME --file .prod.vars.

§Free plan

A sign-in makes 2 subrequests (Google) or 3 (GitHub: user and emails) out of the 50 a free-plan request may make, and a few milliseconds of CPU; no D1, KV or queue operation here (the app then reads and writes its users).

use ocre::oauth::{GITHUB, Pkce, authorize_url};

let pkce = Pkce::new();
let state = ocre::token::generate();
let url = authorize_url(&GITHUB, "client-id", "https://app.example.com/auth/github/callback", &state, &pkce.challenge);
assert!(url.starts_with("https://github.com/login/oauth/authorize?response_type=code&client_id=client-id"));

Structs§

Pkce
A PKCE pair (RFC 7636, S256): keep the verifier in the session, send the challenge.
Profile
The user a provider signed in: its id there, and its email when verified.
Provider
An OAuth 2.0 provider: its endpoints and the scopes Ocre asks for.

Constants§

GITHUB
GitHub (OAuth app or GitHub App): scopes read:user user:email.
GOOGLE
Google (OpenID Connect): scopes openid email profile.
PROVIDERS
Every provider Ocre knows: ocre g auth --oauth accepts these names.

Functions§

authorize_url
The URL to send the browser to: the provider’s sign-in page for this app.
exchange_code
Trades the authorization code from the callback for an access token (one subrequest).
profile
Reads the signed-in user’s Profile with an access token (one subrequest; two for GitHub).
provider
The provider called name ("github", "google"), if Ocre knows it.