hsa-app/internal/auth/loginstate.go
Jean-Michel Tremblay 8b7252dad4 Initial commit: HSA receipt tracker
Go app for capturing and archiving HSA-eligible receipts: OIDC/PKCE auth
against Authelia, SQLite storage with dual-write (filesystem + DB blob),
mobile-first upload, and DB export.

Adds AI receipt classification: a config.json catalog of people and
categories (seeded into the DB on startup), a prompt builder that derives
name-order/initial variants from the data (with same-surname ambiguity
handling), and an Anthropic tool-use client behind POST /classify. Tests
run against a mock endpoint; a live integration test is env-gated to the
cheapest model.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-17 21:40:12 -04:00

23 lines
759 B
Go

package auth
// LoginState is the per-login data we stash in a short-lived encrypted cookie
// during /login, to validate the response at /callback.
type LoginState struct {
State string // CSRF token echoed back in the callback
Verifier string // PKCE code verifier
Nonce string // OIDC nonce echoed back in the ID token
}
// EncodeLoginState encrypts the login state into a cookie value.
func EncodeLoginState(ls LoginState, key [32]byte) (string, error) {
return seal(key, ls)
}
// DecodeLoginState decrypts a cookie value produced by EncodeLoginState.
func DecodeLoginState(encoded string, key [32]byte) (LoginState, error) {
var ls LoginState
if err := open(key, encoded, &ls); err != nil {
return LoginState{}, err
}
return ls, nil
}