Repository navigation
docs: cover v0.42.0's features and add an examples overview - #494
Merged
Merged
Conversation
Content fixes from a docs review against main: - GETTING_STARTED's login step passed time.Now() as the authentication time and didn't mention InteractionRequest.ACRValues/MaxAge. Copied as is, that silently defeats the max_age check v0.42.0 enforces. It now passes when the user actually authenticated, says when to re-authenticate, and shows GrantedAuthorization.GrantID. - Its resource-server step built VerifyRequest without PeerCertificate, so every mTLS-bound token would be refused. It now passes resource.PeerCertificateFromHTTP(r), and explains it. - It now covers RevokeGrant with Dependencies.Revocation, and serving your own grant at the token endpoint (TokenEndpointRequest.Parameters, AuthenticateAttestedClient, VerifyTokenRequestBinding, Config.AdditionalGrantTypes). - README's feature list gains refresh tokens and grant revocation, the OIDC claims parameter with acr_values and max_age, and embedder-served grants. - server/doc.go and client/doc.go list the new methods. A garbled sentence in client/doc.go is fixed. - ARCHITECTURE's package layout gains serverresource/, internal/grantrevocation/, cmd/ and examples/, and rules 3 and 7 gain the new flows. - UPGRADING's max_age section mentions the clock-skew leeway, the 100-year cap and passing the real authentication time. - The keys and keys/ephemeral package docs are corrected. examples/README.md is new. It has a table of the six demos with their stories and ports, a capability matrix mapping each FAPIgo feature to the demos that show it, and what every demo shares. The README links it. Each demo README's partial "runs alongside" port list now points at the overview's port table. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
These fixes come from a docs review of
main(a941962) against the last docs sweep (#468). The mechanical checks were already clean:var (...)blocks.GETTING_STARTEDGo blocks compile and vet (re-checked after these edits).The problems were in content.
Integrators copying these examples would get them wrong:
GETTING_STARTEDlogin step:time.Now()toNewAuthenticationContext, and never mentionedInteraction.ACRValues/MaxAge. An app that reuses an SSO session and copies this silently defeats v0.42.0'smax_agecheck.GrantedAuthorization.GrantID.GETTING_STARTEDresource-server step:VerifyRequestwithoutPeerCertificate, so every mTLS-bound access token would be refused.resource.PeerCertificateFromHTTP(r), with a paragraph on TLS-terminating proxies.Completeness:
GETTING_STARTED:RevokeGrantin the revocation guidance, on both the AS and the RS side;TokenEndpointRequest.Parameters,AuthenticateAttestedClient,VerifyTokenRequestBindingandConfig.AdditionalGrantTypes;claimswith per-claim consent,acr_valuesand enforcedmax_age; embedder-served grants.server/doc.go: the method list gainsRevokeGrantandBuildAuthorizationErrorRedirect, plus the embedder-grant pair and why it fits the "no generic primitives" rule. There are new bullets formax_age, and for CIBA inRevokeGrant.client/doc.go: a garbled sentence is fixed;RefreshTokensis noted as populating, and keeping, the ID token;ClientAttestationHeadersis added to the list of deliberate exceptions.serverresource/,internal/grantrevocation/,cmd/andexamples/, and rules 3 and 7 gain the new flows.max_agesection: the clock-skew leeway, the 100-year cap, and "pass the real authentication time".keys/keys/ephemeralpackage docs: corrected.Examples overview (new
examples/README.md):The root README links to it. Each demo README's partial "runs alongside the other demos" port list now points at that table.
No code changes beyond doc comments.
🤖 Generated with Claude Code