ProtoCore v1.0.16
Deterministic, zero-heap network stack for embedded targets
Loading...
Searching...
No Matches
oauth2.h File Reference

OAuth 2.0 client at the token endpoint (RFC 6749), PROTOCORE_ENABLE_OAUTH2. More...

#include "protocore_config.h"

Go to the source code of this file.

Detailed Description

OAuth 2.0 client at the token endpoint (RFC 6749), PROTOCORE_ENABLE_OAUTH2.

RFC 6749 sec 3.2 names the token endpoint; sec 4.1.3 is the Access Token Request that trades an authorization code for tokens, and sec 6 is the same exchange presenting a refresh token. Both requests are application/x-www-form-urlencoded bodies encoded per RFC 6749 Appendix B, whose percent-encoding is RFC 3986 sec 2.1 over the unreserved set of RFC 3986 sec 2.3. The reply is the JSON of RFC 6749 sec 5.1 on success, or the error object of sec 5.2, read here with the library's zero-heap JSON reader. token_type is "Bearer" for the tokens of RFC 6750 sec 6.1.1, which RFC 6750 sec 2.1 presents in the Authorization header.

Two layers, one handle:

  • Host-testable core: Oauth2Ns::build_code_request, Oauth2Ns::build_refresh_request and Oauth2Ns::parse_token_response work on caller-owned buffers.
  • Transport (needs PROTOCORE_ENABLE_HTTP_CLIENT): Oauth2Ns::exchange_code and Oauth2Ns::refresh post the built body to request.token_endpoint over the platform's HTTP(S) client and parse what comes back.

A confidential client sets client.client_secret; a public client sets code_grant.code_verifier, the PKCE verifier of RFC 7636 sec 4.1 that sec 4.5 sends to the token endpoint. The other stays NULL. No heap, no stdlib.

Author
Douglas Quigg (dstroy0)
Date
2026

Definition in file oauth2.h.