package auth import "golang.org/x/oauth2" // AuthorizeURL builds the Authelia authorization redirect URL with PKCE and state. // challenge must be the pre-computed S256 value from ChallengeS256(verifier). // Extra options (e.g. the OIDC nonce) may be passed via opts. func AuthorizeURL(cfg *oauth2.Config, state, challenge string, opts ...oauth2.AuthCodeOption) string { args := append([]oauth2.AuthCodeOption{ oauth2.SetAuthURLParam("code_challenge", challenge), oauth2.SetAuthURLParam("code_challenge_method", "S256"), }, opts...) return cfg.AuthCodeURL(state, args...) }