Go app for capturing and archiving HSA-eligible receipts: OIDC/PKCE auth against Authelia, SQLite storage with dual-write (filesystem + DB blob), mobile-first upload, and DB export. Adds AI receipt classification: a config.json catalog of people and categories (seeded into the DB on startup), a prompt builder that derives name-order/initial variants from the data (with same-surname ambiguity handling), and an Anthropic tool-use client behind POST /classify. Tests run against a mock endpoint; a live integration test is env-gated to the cheapest model. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
23 lines
759 B
Go
23 lines
759 B
Go
package auth
|
|
|
|
// LoginState is the per-login data we stash in a short-lived encrypted cookie
|
|
// during /login, to validate the response at /callback.
|
|
type LoginState struct {
|
|
State string // CSRF token echoed back in the callback
|
|
Verifier string // PKCE code verifier
|
|
Nonce string // OIDC nonce echoed back in the ID token
|
|
}
|
|
|
|
// EncodeLoginState encrypts the login state into a cookie value.
|
|
func EncodeLoginState(ls LoginState, key [32]byte) (string, error) {
|
|
return seal(key, ls)
|
|
}
|
|
|
|
// DecodeLoginState decrypts a cookie value produced by EncodeLoginState.
|
|
func DecodeLoginState(encoded string, key [32]byte) (LoginState, error) {
|
|
var ls LoginState
|
|
if err := open(key, encoded, &ls); err != nil {
|
|
return LoginState{}, err
|
|
}
|
|
return ls, nil
|
|
}
|