origin-auth 0.2.0

OAuth 2.0 authorization code flow with PKCE, token storage and refresh for Origin.
Documentation

origin-auth

OAuth 2.0 authorization code flow with PKCE, token storage and refresh for Origin.

Part of Origin, a Rust/Tauri platform for building desktop applications from a shared set of domain crates. See the workspace documentation for how the pieces fit together, and ARCHITECTURE.md for the rules this crate follows.

Example

use origin_auth::{AuthorizationFlow, OAuthConfig};

// `OAuthConfig::new` returns a `Result`: both endpoints must be `https://`.
let config = OAuthConfig::new(
    "client-id",
    "https://provider.example/authorize",
    "https://provider.example/token",
)?
.with_scopes(["profile", "offline_access"]);

// `http` is an `Arc<dyn HttpClient>` and `clock` an `Arc<dyn Clock>`, supplied by the
// composition root.
let flow = AuthorizationFlow::new(config, http, clock);

let pending = flow.begin(redirect_uri)?;
// Send the user to `pending.authorization_url`, then, once the redirect listener has
// the code:
let tokens = flow.exchange(&pending, &code).await?;

Stability

Pre-1.0 (0.2.0). Public types, enums and field sets may still change between minor versions; pin an exact version if that matters to you.