Skip to main content

Module external

Module external 

Source
Expand description

Ways in besides a password: external identities (OAuth/OIDC) and passkeys, and the rules that tie them to users.

Signing in with a provider (AuthStore::external_sign_in):

  1. a known identity (provider, subject) signs its user in;
  2. else a verified email that matches a user links the identity to that user and signs them in;
  3. else, with a verified email, an account is created only when the email has a pending invitation (the invitation token may ride the flow, and must then be for that email) or open sign-up is on. Every pending invitation for the email is accepted. Never before first-run setup.

An unverified email never links and never signs up. A user always keeps one way in: the last of password, identities and passkeys cannot be removed.

Structs§

ExternalIdentity
What a provider says about the person signing in.
Identity
A linked identity.
Passkey
A registered passkey (the public key stays in the store).
StoredPasskey
A passkey with what verifying an assertion needs.

Enums§

SignIn
How an external sign-in found its user.