CarpaNet.OAuth is an OAuth library for CarpaNet.
This library is experimental and not stable. Expect issues and bugs!
This is an OAuth 2.0 flow orchestrator supporting PAR (Pushed Authorization Requests), PKCE, and DPoP. Use this to produce an ATProtoOAuthClient via CallbackAsync or RestoreSessionAsync.
var config = new OAuthClientConfig
{
ClientId = clientId,
RedirectUri = redirectUri,
Scope = "atproto transition:generic",
JsonOptions = myJsonOptions,
SessionStore = mySessionStore
};
using var oauthClient = new OAuthSession(config);
var authUrl = await oauthClient.AuthorizeAsync(handle);
// ... redirect user to authUrl, receive callback ...
var session = await oauthClient.CallbackAsync(callbackUrl);
// session implements IATProtoClientCallbackAsync validates the iss callback parameter (RFC 9207) and the token sub. The session's PDS URL is taken from the DID document of sub, also when authorization started from an entryway URL.
Use ScopeSet (namespace CarpaNet.OAuth.Scopes) to build the scope string with the atproto permission syntax:
config.SetScope(new ScopeSet()
.AddAtproto()
.AddRepo("app.bsky.feed.post", RepoActions.Create)
.AddBlob("image/*"));
// "atproto repo:app.bsky.feed.post?action=create blob:image/*"
