-
Notifications
You must be signed in to change notification settings - Fork 2
/
openid.go
74 lines (63 loc) · 2.2 KB
/
openid.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
// +build go1.12
package oidc
import (
"encoding/json"
"io/ioutil"
"net/http"
)
type OpenIDConfiguration struct {
Issuer string `json:"issuer"` // REQUIRED
AuthorizationEndpoint string `json:"authorization_endpoint"` // REQUIRED
TokenEndpoint string `json:"token_endpoint"` // REQUIRED
UserinfoEndpoint string `json:"userinfo_endpoint"` // REQUIRED
JwksURI string `json:"jwks_uri"` // REQUIRED
ResponseTypeSupported []string `json:"response_types_supported"` // REQUIRED
SubjectTypesSupported []string `json:"subject_types_supported"` // REQUIRED
IdTokenSigningAlgValuesSupported []string `json:"id_token_signing_alg_values_supported"` // REQUIRED
RegistrationEndpoint string `json:"registration_endpoint"` // RECOMMENDED ONLY
ScopeSupported []string `json:"scope_supported"` // RECOMMENDED ONLY
ClaimsSupported []string `json:"claims_supported"` // RECOMMENDED ONLY
}
// TODO:
func parseOpenIDConfiguration(url string) (authz, token, issuer, jwks string, err error) {
var o OpenIDConfiguration
resp, err := http.Get(url)
if err != nil {
return
}
defer resp.Body.Close()
buf, err := ioutil.ReadAll(resp.Body)
if err != nil {
return
}
/*
buf, err := ioutil.ReadFile(url)
if err != nil {
return
}
*/
//err = json.Unmarshal(buf, &oc)
err = json.Unmarshal(buf, &o)
if err != nil {
return
}
if len(o.Issuer) == 0 ||
len(o.AuthorizationEndpoint) == 0 ||
len(o.TokenEndpoint) == 0 ||
len(o.UserinfoEndpoint) == 0 ||
len(o.JwksURI) == 0 ||
len(o.ResponseTypeSupported) == 0 ||
len(o.SubjectTypesSupported) == 0 ||
len(o.IdTokenSigningAlgValuesSupported) == 0 {
err = ErrParse
return
}
// TODO CONFIGURATION SANITY CHECKS
// what encrypton are supported with this package etc..
// what flow, etc..
authz = o.AuthorizationEndpoint
token = o.TokenEndpoint
issuer = o.Issuer
jwks = o.JwksURI
return
}