Enhance OAuth configuration types with optional defaults
- Updated the SigningConfig, TokenConfig, SecurityConfig, and ClientConfig structures to include optional default values for various fields, improving clarity and usability. - Added comments to specify default values and optionality for each configuration parameter, enhancing documentation within the code. - This change aims to streamline the configuration process for OAuth service implementations.
This commit is contained in:
parent
ef07622e7e
commit
72b732348d
3 changed files with 60 additions and 58 deletions
1
openapi/hello/hello.go
Normal file
1
openapi/hello/hello.go
Normal file
|
|
@ -0,0 +1 @@
|
||||||
|
package hello
|
||||||
|
|
@ -415,109 +415,109 @@ type JWK struct {
|
||||||
|
|
||||||
// SigningConfig represents signing configuration for OAuth service
|
// SigningConfig represents signing configuration for OAuth service
|
||||||
type SigningConfig struct {
|
type SigningConfig struct {
|
||||||
// Token signing certificate and key (for JWT tokens)
|
// Token signing certificate and key (for JWT and opaque tokens)
|
||||||
SigningCertPath string `json:"signing_cert_path"`
|
SigningCertPath string `json:"signing_cert_path"` // Required: Path to token signing certificate (public key)
|
||||||
SigningKeyPath string `json:"signing_key_path"`
|
SigningKeyPath string `json:"signing_key_path"` // Required: Path to token signing private key
|
||||||
SigningKeyPassword string `json:"signing_key_password,omitempty"`
|
SigningKeyPassword string `json:"signing_key_password,omitempty"` // Optional: Password for encrypted private key
|
||||||
SigningAlgorithm string `json:"signing_algorithm"` // RS256, RS384, RS512, ES256, ES384, ES512
|
SigningAlgorithm string `json:"signing_algorithm"` // Optional: Token signing algorithm (default: RS256)
|
||||||
|
|
||||||
// Token verification certificates (for token validation)
|
// Token verification certificates (for token validation)
|
||||||
VerificationCerts []string `json:"verification_certs,omitempty"`
|
VerificationCerts []string `json:"verification_certs,omitempty"` // Optional: Additional certificates for token verification
|
||||||
|
|
||||||
// mTLS client certificate validation
|
// mTLS client certificate validation
|
||||||
MTLSClientCACertPath string `json:"mtls_client_ca_cert_path,omitempty"`
|
MTLSClientCACertPath string `json:"mtls_client_ca_cert_path,omitempty"` // Optional: CA certificate path for mTLS client validation
|
||||||
MTLSEnabled bool `json:"mtls_enabled"`
|
MTLSEnabled bool `json:"mtls_enabled"` // Optional: Enable mutual TLS authentication (default: false)
|
||||||
|
|
||||||
// Certificate rotation settings
|
// Certificate rotation settings
|
||||||
CertRotationEnabled bool `json:"cert_rotation_enabled"`
|
CertRotationEnabled bool `json:"cert_rotation_enabled"` // Optional: Enable automatic certificate rotation (default: false)
|
||||||
CertRotationInterval time.Duration `json:"cert_rotation_interval"`
|
CertRotationInterval time.Duration `json:"cert_rotation_interval"` // Optional: Certificate rotation interval (default: 24h)
|
||||||
}
|
}
|
||||||
|
|
||||||
// TokenConfig represents token-related configuration
|
// TokenConfig represents token-related configuration
|
||||||
type TokenConfig struct {
|
type TokenConfig struct {
|
||||||
// Access token settings
|
// Access token settings
|
||||||
AccessTokenLifetime time.Duration `json:"access_token_lifetime"` // 1h
|
AccessTokenLifetime time.Duration `json:"access_token_lifetime"` // Optional: Access token validity period (default: 1h)
|
||||||
AccessTokenFormat string `json:"access_token_format"` // jwt, opaque
|
AccessTokenFormat string `json:"access_token_format"` // Optional: Access token format - jwt, opaque (default: jwt)
|
||||||
AccessTokenSigningAlg string `json:"access_token_signing_alg"` // RS256
|
AccessTokenSigningAlg string `json:"access_token_signing_alg"` // Optional: Access token signing algorithm (default: RS256)
|
||||||
|
|
||||||
// Refresh token settings
|
// Refresh token settings
|
||||||
RefreshTokenLifetime time.Duration `json:"refresh_token_lifetime"` // 24h
|
RefreshTokenLifetime time.Duration `json:"refresh_token_lifetime"` // Optional: Refresh token validity period (default: 24h)
|
||||||
RefreshTokenRotation bool `json:"refresh_token_rotation"` // true for OAuth 2.1
|
RefreshTokenRotation bool `json:"refresh_token_rotation"` // Optional: Enable refresh token rotation for OAuth 2.1 (default: true)
|
||||||
RefreshTokenFormat string `json:"refresh_token_format"` // opaque, jwt
|
RefreshTokenFormat string `json:"refresh_token_format"` // Optional: Refresh token format - opaque, jwt (default: opaque)
|
||||||
|
|
||||||
// Authorization code settings
|
// Authorization code settings
|
||||||
AuthorizationCodeLifetime time.Duration `json:"authorization_code_lifetime"` // 10m
|
AuthorizationCodeLifetime time.Duration `json:"authorization_code_lifetime"` // Optional: Authorization code validity period (default: 10m)
|
||||||
AuthorizationCodeLength int `json:"authorization_code_length"` // 32
|
AuthorizationCodeLength int `json:"authorization_code_length"` // Optional: Authorization code length in bytes (default: 32)
|
||||||
|
|
||||||
// Device code settings
|
// Device code settings
|
||||||
DeviceCodeLifetime time.Duration `json:"device_code_lifetime"` // 15m
|
DeviceCodeLifetime time.Duration `json:"device_code_lifetime"` // Optional: Device code validity period (default: 15m)
|
||||||
DeviceCodeLength int `json:"device_code_length"` // 8
|
DeviceCodeLength int `json:"device_code_length"` // Optional: Device code length in bytes (default: 8)
|
||||||
UserCodeLength int `json:"user_code_length"` // 8
|
UserCodeLength int `json:"user_code_length"` // Optional: User code length for device flow (default: 8)
|
||||||
DeviceCodeInterval time.Duration `json:"device_code_interval"` // 5s
|
DeviceCodeInterval time.Duration `json:"device_code_interval"` // Optional: Device code polling interval (default: 5s)
|
||||||
|
|
||||||
// Token binding settings
|
// Token binding settings
|
||||||
TokenBindingEnabled bool `json:"token_binding_enabled"`
|
TokenBindingEnabled bool `json:"token_binding_enabled"` // Optional: Enable token binding to client certificates (default: false)
|
||||||
SupportedBindingTypes []string `json:"supported_binding_types"` // dpop, mtls
|
SupportedBindingTypes []string `json:"supported_binding_types"` // Optional: Supported token binding types - dpop, mtls (default: [dpop, mtls])
|
||||||
|
|
||||||
// Token audience settings
|
// Token audience settings
|
||||||
DefaultAudience []string `json:"default_audience"`
|
DefaultAudience []string `json:"default_audience"` // Optional: Default token audience (default: [])
|
||||||
AudienceValidationMode string `json:"audience_validation_mode"` // strict, relaxed
|
AudienceValidationMode string `json:"audience_validation_mode"` // Optional: Audience validation mode - strict, relaxed (default: strict)
|
||||||
}
|
}
|
||||||
|
|
||||||
// SecurityConfig represents security-related configuration
|
// SecurityConfig represents security-related configuration
|
||||||
type SecurityConfig struct {
|
type SecurityConfig struct {
|
||||||
// PKCE settings (mandatory for OAuth 2.1)
|
// PKCE settings (mandatory for OAuth 2.1)
|
||||||
PKCERequired bool `json:"pkce_required"` // true for OAuth 2.1
|
PKCERequired bool `json:"pkce_required"` // Optional: Require PKCE for OAuth 2.1 compliance (default: true)
|
||||||
PKCECodeChallengeMethod []string `json:"pkce_code_challenge_method"` // S256
|
PKCECodeChallengeMethod []string `json:"pkce_code_challenge_method"` // Optional: Supported PKCE code challenge methods (default: [S256])
|
||||||
PKCECodeVerifierLength int `json:"pkce_code_verifier_length"` // 128
|
PKCECodeVerifierLength int `json:"pkce_code_verifier_length"` // Optional: PKCE code verifier length (default: 128)
|
||||||
|
|
||||||
// State parameter settings
|
// State parameter settings
|
||||||
StateParameterRequired bool `json:"state_parameter_required"`
|
StateParameterRequired bool `json:"state_parameter_required"` // Optional: Require state parameter for CSRF protection (default: false)
|
||||||
StateParameterLifetime time.Duration `json:"state_parameter_lifetime"` // 10m
|
StateParameterLifetime time.Duration `json:"state_parameter_lifetime"` // Optional: State parameter validity period (default: 10m)
|
||||||
StateParameterLength int `json:"state_parameter_length"` // 32
|
StateParameterLength int `json:"state_parameter_length"` // Optional: State parameter length in bytes (default: 32)
|
||||||
|
|
||||||
// Rate limiting
|
// Rate limiting
|
||||||
RateLimitEnabled bool `json:"rate_limit_enabled"`
|
RateLimitEnabled bool `json:"rate_limit_enabled"` // Optional: Enable rate limiting (default: false)
|
||||||
RateLimitRequests int `json:"rate_limit_requests"` // requests per window
|
RateLimitRequests int `json:"rate_limit_requests"` // Optional: Number of requests per window (default: 100)
|
||||||
RateLimitWindow time.Duration `json:"rate_limit_window"` // 1m
|
RateLimitWindow time.Duration `json:"rate_limit_window"` // Optional: Rate limit time window (default: 1m)
|
||||||
RateLimitByClientID bool `json:"rate_limit_by_client_id"`
|
RateLimitByClientID bool `json:"rate_limit_by_client_id"` // Optional: Enable per-client rate limiting (default: false)
|
||||||
|
|
||||||
// Brute force protection
|
// Brute force protection
|
||||||
BruteForceProtectionEnabled bool `json:"brute_force_protection_enabled"`
|
BruteForceProtectionEnabled bool `json:"brute_force_protection_enabled"` // Optional: Enable brute force attack protection (default: false)
|
||||||
MaxFailedAttempts int `json:"max_failed_attempts"` // 5
|
MaxFailedAttempts int `json:"max_failed_attempts"` // Optional: Maximum failed login attempts (default: 5)
|
||||||
LockoutDuration time.Duration `json:"lockout_duration"` // 15m
|
LockoutDuration time.Duration `json:"lockout_duration"` // Optional: Account lockout duration (default: 15m)
|
||||||
|
|
||||||
// Encryption settings
|
// Encryption settings
|
||||||
EncryptionKey string `json:"encryption_key"` // for encrypting sensitive data
|
EncryptionKey string `json:"encryption_key"` // Optional: Key for encrypting sensitive data (default: "")
|
||||||
EncryptionAlgorithm string `json:"encryption_algorithm"` // AES-256-GCM
|
EncryptionAlgorithm string `json:"encryption_algorithm"` // Optional: Encryption algorithm for sensitive data (default: AES-256-GCM)
|
||||||
|
|
||||||
// Additional security features
|
// Additional security features
|
||||||
IPWhitelist []string `json:"ip_whitelist,omitempty"`
|
IPWhitelist []string `json:"ip_whitelist,omitempty"` // Optional: IP addresses allowed to access (default: [])
|
||||||
IPBlacklist []string `json:"ip_blacklist,omitempty"`
|
IPBlacklist []string `json:"ip_blacklist,omitempty"` // Optional: IP addresses blocked from access (default: [])
|
||||||
RequireHTTPS bool `json:"require_https"`
|
RequireHTTPS bool `json:"require_https"` // Optional: Require HTTPS for all endpoints (default: true)
|
||||||
DisableUnsecureEndpoints bool `json:"disable_unsecure_endpoints"`
|
DisableUnsecureEndpoints bool `json:"disable_unsecure_endpoints"` // Optional: Disable non-HTTPS endpoints (default: false)
|
||||||
}
|
}
|
||||||
|
|
||||||
// ClientConfig represents default client configuration
|
// ClientConfig represents default client configuration
|
||||||
type ClientConfig struct {
|
type ClientConfig struct {
|
||||||
// Default client settings
|
// Default client settings
|
||||||
DefaultClientType string `json:"default_client_type"` // confidential, public
|
DefaultClientType string `json:"default_client_type"` // Optional: Default client type - confidential, public (default: confidential)
|
||||||
DefaultTokenEndpointAuthMethod string `json:"default_token_endpoint_auth_method"` // client_secret_basic, client_secret_post, private_key_jwt
|
DefaultTokenEndpointAuthMethod string `json:"default_token_endpoint_auth_method"` // Optional: Default client authentication method (default: client_secret_basic)
|
||||||
DefaultGrantTypes []string `json:"default_grant_types"` // authorization_code, refresh_token
|
DefaultGrantTypes []string `json:"default_grant_types"` // Optional: Default supported grant types (default: [authorization_code, refresh_token])
|
||||||
DefaultResponseTypes []string `json:"default_response_types"` // code
|
DefaultResponseTypes []string `json:"default_response_types"` // Optional: Default supported response types (default: [code])
|
||||||
DefaultScopes []string `json:"default_scopes"` // openid, profile, email
|
DefaultScopes []string `json:"default_scopes"` // Optional: Default OAuth scopes (default: [openid, profile, email])
|
||||||
|
|
||||||
// Client validation settings
|
// Client validation settings
|
||||||
ClientIDLength int `json:"client_id_length"` // 32
|
ClientIDLength int `json:"client_id_length"` // Optional: Client ID length in bytes (default: 32)
|
||||||
ClientSecretLength int `json:"client_secret_length"` // 64
|
ClientSecretLength int `json:"client_secret_length"` // Optional: Client secret length in bytes (default: 64)
|
||||||
ClientSecretLifetime time.Duration `json:"client_secret_lifetime"` // 0 (never expires)
|
ClientSecretLifetime time.Duration `json:"client_secret_lifetime"` // Optional: Client secret lifetime, 0 = never expires (default: 0s)
|
||||||
|
|
||||||
// Dynamic client registration
|
// Dynamic client registration
|
||||||
DynamicRegistrationEnabled bool `json:"dynamic_registration_enabled"`
|
DynamicRegistrationEnabled bool `json:"dynamic_registration_enabled"` // Optional: Enable dynamic client registration (default: true)
|
||||||
AllowedRedirectURISchemes []string `json:"allowed_redirect_uri_schemes"` // https, http (for dev)
|
AllowedRedirectURISchemes []string `json:"allowed_redirect_uri_schemes"` // Optional: Allowed redirect URI schemes (default: [https, http])
|
||||||
AllowedRedirectURIHosts []string `json:"allowed_redirect_uri_hosts"` // localhost (for dev)
|
AllowedRedirectURIHosts []string `json:"allowed_redirect_uri_hosts"` // Optional: Allowed redirect URI hosts (default: [localhost, 127.0.0.1])
|
||||||
|
|
||||||
// Client certificate settings
|
// Client certificate settings
|
||||||
ClientCertificateRequired bool `json:"client_certificate_required"`
|
ClientCertificateRequired bool `json:"client_certificate_required"` // Optional: Require client certificates (default: false)
|
||||||
ClientCertificateValidation string `json:"client_certificate_validation"` // none, optional, required
|
ClientCertificateValidation string `json:"client_certificate_validation"` // Optional: Client certificate validation mode - none, optional, required (default: none)
|
||||||
}
|
}
|
||||||
|
|
|
||||||
1
openapi/openapi.go
Normal file
1
openapi/openapi.go
Normal file
|
|
@ -0,0 +1 @@
|
||||||
|
package openapi
|
||||||
Loading…
Add table
Reference in a new issue