NAME

WWW::Authentik::Role::HTTP - Sending requests to authentik and turning failures into exceptions

VERSION

version 0.001

DESCRIPTION

What WWW::Authentik::API and WWW::Authentik::OIDC share: one LWP::UserAgent, JSON in and out, and the mapping of authentik's four error shapes onto WWW::Authentik::Error::API.

Building the request and reading the response are separate from sending it, so that Net::Async::Authentik can reuse "build_request" and "read_response" and only replace the sending.

json_codec

The JSON codec every part uses: UTF-8, canonical, honouring TO_JSON.

api_error_class

network_error_class

validation_error_class

The classes the errors are thrown as. Net::Async::Authentik overrides them with its own subclasses.

build_request

my $request = $self->build_request( POST => $url, json => \%body, bearer => $token );
my $request = $self->build_request( POST => $url, form => \%fields );
my $request = $self->build_request( POST => $url, form => \%fields, basic => [ $id, $secret ] );

The HTTP::Request for one call: JSON accepted, a bearer token or a basic login when given, the body as JSON or as a form. Form values are sorted, so the same arguments always produce the same request.

read_response

my $result = $self->read_response( $response, $method, $url, %arg );

Turns an HTTP::Response into status, the decoded data, the location header and the decoded content, or throws "api_error_class" for any status of 400 and above. Anything below 400 is an answer, because authentik redirects where it wants a browser. %arg are the arguments the request was built with.

The body is read through "decoded_content" in HTTP::Response, so a user agent that asked for a compressed answer still gets its JSON.

When the body is neither of authentik's error shapes — a proxy's HTML, plain text, a JSON array — a squeezed snippet of it becomes the message, and the whole of it (up to 500 characters) is on the exception as "body" in WWW::Authentik::Error::API.

The thrown error names the method and the URL, never the token or the secret.

flatten_field_errors

my $fields = $self->flatten_field_errors( \%body );

authentik's field errors as a flat hash of field name to a list of messages. A nested shape such as {"grant_types": {"0": [...]}} or {"app": {"slug": [...]}} becomes grant_types.0 and app.slug.

send_request

my $result = $self->send_request( GET => $url, bearer => $token );
my $result = $self->send_request( POST => $url, json => \%body, bearer => $token );
my $result = $self->send_request( POST => $url, form => \%fields );

Sends one request and returns what "read_response" returns. Throws WWW::Authentik::Error::Network when no answer came back and WWW::Authentik::Error::API for any status of 400 and above.

SUPPORT

Issues

Please report bugs and feature requests on GitHub at https://github.com/Getty/p5-www-authentik/issues.

IRC

Join #kubernetes on irc.perl.org or message Getty directly.

CONTRIBUTING

Contributions are welcome! Please fork the repository and submit a pull request.

AUTHOR

Torsten Raudssus <getty@cpan.org>

COPYRIGHT AND LICENSE

This software is copyright (c) 2026 by Torsten Raudssus <torsten@raudssus.de> https://raudssus.de/.

This is free software; you can redistribute it and/or modify it under the same terms as the Perl 5 programming language system itself.