Repository navigation
v0.53.0
The three auth packages are now one tree under authkit, with one
principal type. Update imports, then the handful of renamed symbols below.
Every browser session logs in again once after the relying party deploys.
Changed
jwtauthis nowauthkit/jwtandoidcis nowauthkit/oidc. Replace
the import paths and thejwtauth.qualifier withjwt.; no symbol
changed its name in the move. A local variable namedjwtshadows the
package for the rest of its function, so rename it.authkit.Identityis the one principal.jwt.Claimsembeds it and adds
the token envelope (Iss,Aud,Exp);oidc.Userembeds it and adds
the profile (Name,Picture,DisplayName,Raw). Field reads such
asclaims.Subanduser.OrgIDare unchanged. A composite literal that
sets those fields compiles as before on Go 1.27.Identity.PrincipalTypeis the named typeauthkit.PrincipalType, with
PrincipalUser,PrincipalService,PrincipalAgent, andPrincipalDev.
jwt.PrincipalType,jwt.PrincipalUser, andjwt.PrincipalServiceare
aliases. Comparisons against string literals still compile.Identitycarries JSON tags (sub,org_id,roles, ...).TokenID
andAuthMethodare never serialised.oidc.User.OrgRolesis the embeddedRoles;oidc.User.AvatarURLis
gone, readPicture. Theavatar_urlaccess-token claim still feeds
Picturewhenpictureis absent.oidc.ClaimsMapper.MapandProvider.VerifyIDTokenreturnoidc.User;
oidc.Identityis deleted and itsSubjectisSub. A verified ID token
that maps to no subject is rejected.oidc.SessionCookieNameis__Host-latere-session-v2. A session written
under the previous shape stored roles under another key, so it is not
read; users sign in once more after deploy.jwt.Validator.Middlewarealso stores the principal through
authkit.WithIdentity, soauthkit.IdentityFromContextworks behind it.authkitimports no other auth package. The two authenticators that
needed one moved to where they are produced:authkit.NewJWTis
jwt.NewAuthenticator(typejwt.Authenticator), and
authkit.NewSessionAuthenticatorisoidc.NewSessionAuthenticator.
authkit.TokenInfo,TokenInfoClient,CachedTokenInfo,
TokenInfoLookup, andErrRevokedmoved tojwtunchanged.authkit.FileTokenStore,TokenStore,DefaultFileTokenStorePath,
DeviceCodeClient, andNewDeviceCodeClientmoved toauthkit/cli, the
only package in the tree that opens a browser or touches the home
directory.jwtauth.WriteUnauthorizedisauthkit.WriteUnauthorized;
oidc.SplitScopesisauthkit.SplitScopes.- Error strings from the JWT package start with
authkit/jwt:; sentinel
errors are unchanged.