Layer: L7 Application ยท Build flags: PC_ENABLE_OAUTH2, PC_ENABLE_HTTP_CLIENT
What this example teaches
This is the redirect-callback half of an OAuth/OIDC login. After the user authorizes at the provider, the browser is redirected back to the device with ?code=...; this handler exchanges that code at the provider's token endpoint for tokens. Where OidcAuth verified a token someone else obtained, this one obtains the tokens.
Exchange the code for tokens in one call:
pc_o_auth2_tokens t;
int st = pc_oauth2_exchange_code(TOKEN_URL, code, REDIRECT_URI, CLIENT_ID, CLIENT_SECRET, nullptr, &t);
if (st != 200) { }
const char * http_get_query(const HttpReq *req, const char *key)
Look up a query parameter value by name (case-sensitive).
pc_oauth2_exchange_code() POSTs the code to the token endpoint through the outbound HTTP client (HttpClient) and fills a tokens struct. The nullptr argument is the PKCE code_verifier - pass it (and nullptr for the client secret) for a public client using PKCE instead of a client secret.
Next steps. Pair this with OidcAuth to verify the returned id_token, and call pc_oauth2_refresh() later with the refresh_token for fresh access tokens. In production use https:// token URLs and set a CA or pin on the HTTP client.
Build and run
pio ci --board=esp32dev --project-option="framework=arduino" \
--project-option="build_flags=-DPC_ENABLE_OAUTH2=1 -DPC_ENABLE_HTTP_CLIENT=1" \
--lib="." examples/L7-Application/OAuth2/OAuth2.ino
# the provider redirects the browser here after consent:
curl "http://<ip>/callback?code=<auth_code>" # {"token_type":"Bearer","expires_in":3600}
Annotated source
The complete sketch (OAuth2.ino), reproduced verbatim with added explanatory comments:
#define PC_ENABLE_OAUTH2 1
#define PC_ENABLE_HTTP_CLIENT 1
static const char *SSID = "YOUR_SSID";
static const char *PASSWORD = "YOUR_PASSWORD";
static const char *TOKEN_URL = "https://provider.example/oauth/token";
static const char *CLIENT_ID = "your-client-id";
static const char *CLIENT_SECRET = "your-client-secret";
static const char *REDIRECT_URI = "http://device.local/callback";
void setup()
{
delay(250);
Serial.print("IP: ");
Serial.printf("IP: %u.%u.%u.%u\n", (unsigned)(ip & 0xFF), (unsigned)((ip >> 8) & 0xFF),
(unsigned)((ip >> 16) & 0xFF), (unsigned)((ip >> 24) & 0xFF));
if (!code)
{
server.
send(
id, 400,
"application/json",
"{\"error\":\"missing code\"}");
return;
}
pc_o_auth2_tokens t;
int st = pc_oauth2_exchange_code(TOKEN_URL, code, REDIRECT_URI, CLIENT_ID, CLIENT_SECRET, nullptr, &t);
if (st != 200)
{
char b[48];
snprintf(b, sizeof(b), "{\"error\":\"exchange failed\",\"status\":%d}", st);
server.
send(
id, 502,
"application/json", b);
return;
}
char b[96];
snprintf(b, sizeof(b), "{\"token_type\":\"%s\",\"expires_in\":%ld}", t.token_type, t.expires_in);
server.
send(
id, 200,
"application/json", b);
});
}
void loop()
{
}
Single-port HTTP server with deterministic, zero-allocation execution.
void send(uint8_t slot_id, int code, const char *content_type, const char *payload)
Send an HTTP response with a body and close the connection.
int32_t begin(const WebServerConfig *cfg=nullptr)
Initialize all connection slots and open all registered listeners.
void on(const char *path, HttpMethod method, Handler callback)
Register a route handler.
void handle()
Drive the server - call every Arduino loop() iteration.
OAuth2 token-endpoint client - authorization-code + refresh (PC_ENABLE_OAUTH2).
bool init_wifi_physical(const char *, const char *)
Connect to a WiFi access point.
uint32_t pc_net_egress_ip(void)
IPv4 (network byte order) of the current egress interface, or 0 if none.
bool wifi_ready()
True if the WiFi station link is up (associated + an IP is assigned).
Layer 1 (Physical) - link bring-up and live egress-interface reporting.
Layer 7 (Application) - public HTTP routing API.
@ HTTP_GET
Safe, idempotent read.
Fully-parsed HTTP/1.1 request.