Standards and dependencies
Security guidance, protocol standards, and established Go libraries used by Authlier.
Authlier does not invent password hashing, WebAuthn, OAuth, OIDC, SAML, or TOTP. It builds its server-side authentication flows on published standards and established Go libraries, then adds consistent configuration, storage, session handling, and HTTP routes.
Security guidance
Authlier uses the following OWASP material as engineering and verification input:
- Application Security Verification Standard 5.0
- Authentication Cheat Sheet
- Session Management Cheat Sheet
- Password Storage Cheat Sheet
- Forgot Password Cheat Sheet
- Multifactor Authentication Cheat Sheet
- OAuth 2.0 Protocol Cheat Sheet
These references guide the implementation and review of Authlier. They do not mean that OWASP has certified Authlier or that every application using the library automatically satisfies ASVS. The Security guide explains the controls that remain the application's responsibility.
Protocol standards
- Passwordless authentication follows Web Authentication: Level 3.
- Google authentication uses the OAuth 2.0 Authorization Code flow defined by RFC 6749.
- Bearer access tokens use the JSON Web Token format defined by RFC 7519 and Ed25519 signatures defined by RFC 8032.
- OIDC SSO follows OpenID Connect Core 1.0.
- SAML SSO uses the SAML 2.0 standard.
- Authenticator codes follow TOTP: Time-Based One-Time Password Algorithm.
Go libraries
Authlier uses focused libraries for protocol and cryptographic work:
golang.org/x/cryptoprovides password-hashing primitives.golang-jwt/jwtcreates and validates JWT access tokens.coreos/go-oidcverifies OpenID Connect identities.golang.org/x/oauth2implements OAuth 2.0 client flows.go-webauthn/webauthnimplements WebAuthn ceremonies and verification.crewjam/samlandgoxmldsigparse and verify SAML messages and XML signatures.pquerna/otpimplements TOTP generation and validation.
Official storage adapters use the established PostgreSQL, MySQL, MongoDB, and Redis Go drivers. The Storage guide explains when to choose each adapter.