feat: serve RFC 8414 authorization server metadata (#1685)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Elias Schneider <login@eliasschneider.com>
This commit is contained in:
Jean-François Roy
2026-08-12 23:13:05 +02:00
committed by GitHub
co-authored by Claude Opus 5 Elias Schneider
parent 86cf73b86c
commit 46b8d54e15
4 changed files with 129 additions and 13 deletions
+2 -1
View File
@@ -46,7 +46,8 @@ func isCorsPath(path string) bool {
"/api/oidc/end-session",
"/api/oidc/introspect",
"/.well-known/jwks.json",
"/.well-known/openid-configuration":
"/.well-known/openid-configuration",
"/.well-known/oauth-authorization-server":
return true
default:
return false
+41
View File
@@ -0,0 +1,41 @@
package middleware
import (
"net/http"
"net/http/httptest"
"testing"
"github.com/gin-gonic/gin"
"github.com/stretchr/testify/require"
)
func TestCorsMiddlewareAllowsDiscoveryDocuments(t *testing.T) {
gin.SetMode(gin.TestMode)
router := gin.New()
router.Use(NewCorsMiddleware().Add())
paths := []string{"/.well-known/openid-configuration", "/.well-known/oauth-authorization-server"}
for _, path := range paths {
router.GET(path, func(c *gin.Context) {
c.Status(http.StatusOK)
})
}
for _, path := range paths {
t.Run(path, func(t *testing.T) {
req := httptest.NewRequestWithContext(t.Context(), http.MethodGet, path, http.NoBody)
w := httptest.NewRecorder()
router.ServeHTTP(w, req)
require.Equal(t, http.StatusOK, w.Code)
require.Equal(t, "*", w.Header().Get("Access-Control-Allow-Origin"))
req = httptest.NewRequestWithContext(t.Context(), http.MethodOptions, path, http.NoBody)
w = httptest.NewRecorder()
router.ServeHTTP(w, req)
require.Equal(t, http.StatusNoContent, w.Code)
require.Equal(t, "*", w.Header().Get("Access-Control-Allow-Origin"))
})
}
}