DocumentazioneAccesso con Learnya
Gestisci
Accesso con Learnya
Permetti alle persone di accedere alla tua applicazione con il loro account Learnya. OAuth 2.1 e OpenID Connect, su auth.learnya.ai.
In questa pagina
Il documento di discovery
Tutto ciò di cui una libreria OpenID Connect ha bisogno è pubblicato a un indirizzo. La maggior parte si configura con quello soltanto.
curl https://auth.learnya.ai/.well-known/openid-configuration{
"issuer": "https://auth.learnya.ai",
"authorization_endpoint": "https://auth.learnya.ai/authorize",
"token_endpoint": "https://auth.learnya.ai/token",
"jwks_uri": "https://auth.learnya.ai/.well-known/jwks.json",
"grant_types_supported": [
"authorization_code",
"refresh_token",
"client_credentials",
"urn:ietf:params:oauth:grant-type:token-exchange"
],
"code_challenge_methods_supported": ["S256"]
}Quale flusso scegliere
| Il tuo caso | Flusso OAuth |
|---|---|
| Una persona accede alla tua applicazione | authorization_code |
| Il tuo server agisce a proprio nome | client_credentials |
| Mantenere aperta una sessione | refresh_token |
| Un servizio agisce per conto di un altro | token-exchange |
Codice di autorizzazione con PKCE
PKCE è obbligatorio per tutte le applicazioni, con il metodo S256. L’indirizzo di reindirizzamento deve corrispondere esattamente a quello registrato.
Mandare la persona ad accedere
GET https://auth.learnya.ai/authorize ?response_type=code &client_id=lyc_your_client &redirect_uri=https://app.example.ch/callback &scope=openid profile email offline_access &state=a value you check on return &code_challenge=BASE64URL(SHA256(verifier)) &code_challenge_method=S256Scambiare il codice con dei token
curl https://auth.learnya.ai/token \ -u "lyc_your_client:$CLIENT_SECRET" \ -d grant_type=authorization_code \ -d code=the_code_from_the_callback \ -d redirect_uri=https://app.example.ch/callback \ -d code_verifier=the_verifier_you_generatedRisposta{ "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6ImF0K2p3dCJ9…", "token_type": "Bearer", "expires_in": 900, "refresh_token": "…", "id_token": "eyJhbGciOiJSUzI1NiJ9…", "scope": "openid profile email offline_access" }
Verificare un token
I token di accesso sono JWT firmati in RS256. Verificali con le chiavi pubbliche pubblicate, senza segreto condiviso. Contano cinque controlli: l’algoritmo fissato a RS256, il tipo at+jwt, l’emittente, la tua audience e la scadenza.
import jwt from "jsonwebtoken"
const ISSUER = "https://auth.learnya.ai"
const AUDIENCE = "https://api.example.ch"
// keyFor maps a kid to a public key from the JWKS.
export function verifyAccessToken(token, keyFor) {
const decoded = jwt.decode(token, { complete: true })
if (!decoded?.header.kid) throw new Error("no kid in header")
if (decoded.header.typ !== "at+jwt")
throw new Error("not an access token")
return jwt.verify(token, keyFor(decoded.header.kid), {
algorithms: ["RS256"],
issuer: ISSUER,
audience: AUDIENCE,
})
}import type { KeyObject } from "node:crypto"
import jwt, { type JwtPayload } from "jsonwebtoken"
const ISSUER = "https://auth.learnya.ai"
const AUDIENCE = "https://api.example.ch"
// keyFor maps a kid to a public key from the JWKS.
export function verifyAccessToken(
token: string,
keyFor: (kid: string) => KeyObject,
): JwtPayload {
const decoded = jwt.decode(token, { complete: true })
if (!decoded?.header.kid) throw new Error("no kid in header")
if (decoded.header.typ !== "at+jwt")
throw new Error("not an access token")
const payload = jwt.verify(
token,
keyFor(decoded.header.kid),
{
algorithms: ["RS256"],
issuer: ISSUER,
audience: AUDIENCE,
},
)
if (typeof payload === "string")
throw new Error("not a JSON payload")
return payload
}Disponibile anche
| Funzione | Per |
|---|---|
| Richieste di autorizzazione push | Inviare la richiesta al server anziché nell’indirizzo |
| DPoP | Legare un token a una chiave detenuta dalla tua applicazione |
| Revoca e introspezione | Revocare un token, o chiedere se è ancora valido |
| Disconnessione | Chiudere la sessione Learnya dalla tua applicazione |
Registrare la tua applicazione
Ogni applicazione viene registrata da Learnya, con i suoi indirizzi di reindirizzamento esatti. Scrivici indicando il nome della tua applicazione, i suoi indirizzi di reindirizzamento e le informazioni sulla persona di cui hai bisogno.