Expand description
The browser-facing halves of the OAuth flow: starting a login and finishing one.
This is the part of the cutover that inverts rather than swapping. Under
the sidecar the app redirects to its /login, the sidecar owns the
callback, and the app receives a one-shot session_id to exchange for an
identity. Here the app owns both ends: it performs PAR itself, and the PDS
redirects the browser straight back to the app with a code.
The logic lives here rather than in web.rs so it can be tested without an
HTTP server, and so the handler stays a thin shell that does cookies and
redirects.
Structs§
- Completed
Login - Who logged in.
- Started
Login - A login that has been pushed to the authorization server and is waiting for the user.