> ## Documentation Index
> Fetch the complete documentation index at: https://docs-dev-docs-event-stream-action-templates.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Ajouter une fonctionnalité de connexion à votre application Go

> Ce guide explique comment intégrer Auth0 à n’importe quelle application Web Go, nouvelle ou existante.

export const AuthCodeGroup = ({children, dropdown}) => {
  const [processedChildren, setProcessedChildren] = useState(children);
  useEffect(() => {
    let unsubscribe = null;
    function init() {
      unsubscribe = window.autorun(() => {
        const processChildren = node => {
          if (typeof node === "string") {
            let processedNode = node;
            for (const [key, value] of window.rootStore.variableStore.values.entries()) {
              const escapedKey = key.replaceAll(/[.*+?^${}()|[\]\\]/g, (String.raw)`\$&`);
              processedNode = processedNode.replaceAll(new RegExp(escapedKey, "g"), value);
            }
            return processedNode;
          } else if (Array.isArray(node)) {
            return node.map(processChildren);
          } else if (node && node.props && node.props.children) {
            return {
              ...node,
              props: {
                ...node.props,
                children: processChildren(node.props.children)
              }
            };
          }
          return node;
        };
        setProcessedChildren(processChildren(children));
      });
    }
    if (window.rootStore) {
      init();
    } else {
      window.addEventListener("adu:storeReady", init);
    }
    return () => {
      window.removeEventListener("adu:storeReady", init);
      unsubscribe?.();
    };
  }, [children]);
  return <CodeGroup dropdown={dropdown}>{processedChildren}</CodeGroup>;
};

export const QuickstartButtons = ({githubLink, lang = "en"}) => {
  const translations = {
    en: {
      viewOnGithub: "View On GitHub",
      loginAndDownload: "Download Sample"
    },
    "fr-ca": {
      viewOnGithub: "Afficher sur GitHub",
      loginAndDownload: "Télécharger un exemple"
    },
    "ja-jp": {
      viewOnGithub: "Githubで表示",
      loginAndDownload: "サンプルをダウンロード"
    }
  };
  const text = translations[lang] || translations.en;
  const parseGithubUrl = url => {
    try {
      const urlObj = new URL(url);
      const pathParts = urlObj.pathname.split("/").filter(Boolean);
      if (pathParts.length >= 4 && pathParts[2] === "tree") {
        const repoName = pathParts[1];
        const branch = pathParts[3];
        const path = pathParts.slice(4).join("/") || undefined;
        return {
          repo: repoName,
          branch,
          path
        };
      }
      console.warn("Could not parse GitHub URL:", url);
      return null;
    } catch (error) {
      console.error("Error parsing GitHub URL:", error);
      return null;
    }
  };
  const handleDownload = async () => {
    const params = parseGithubUrl(githubLink);
    if (!params) {
      console.error("Invalid GitHub URL format");
      return;
    }
    try {
      await window.Auth0DocsUI?.getSample(params);
    } catch (error) {
      console.error("Failed to download sample:", error);
    }
  };
  return <div className="quickstart_buttons flex flex-wrap gap-3 mb-4">
      <a href={githubLink} target="_blank" rel="noopener noreferrer" className="no_external_icon quickstart_button inline-flex items-center justify-center px-6 py-3 text-sm font-medium rounded-[18px] bg-black dark:bg-white !text-white dark:!text-black hover:bg-gray-800 dark:hover:bg-gray-100 transition-colors">
        {text.viewOnGithub}
      </a>
      <button onClick={handleDownload} type="button" className="no_external_icon quickstart_button inline-flex items-center justify-center px-6 py-3 text-sm font-medium rounded-[18px] border border-gray-300 dark:border-[#454545] bg-white dark:bg-[#272728] !text-black dark:!text-white hover:bg-gray-50 dark:hover:bg-neutral-800 transition-colors">
        {text.loginAndDownload}
      </button>
    </div>;
};

export const LoggedInForm = ({sampleApp}) => {
  const LS_APPS_KEY = "auth_demo_apps";
  const LS_APP_CFG_KEY = "auth_demo_app_cfg";
  const CHANNEL = "auth_flows_sync_v1";
  const mkChannel = () => new BroadcastChannel(CHANNEL);
  function uid() {
    return Math.random().toString(36).slice(2) + Date.now().toString(36);
  }
  function loadApps() {
    const raw = localStorage.getItem(LS_APPS_KEY);
    if (raw) return JSON.parse(raw);
    const seeded = [{
      id: "{yourClientId}",
      name: "Default App"
    }];
    localStorage.setItem(LS_APPS_KEY, JSON.stringify(seeded));
    return seeded;
  }
  function saveApps(apps) {
    localStorage.setItem(LS_APPS_KEY, JSON.stringify(apps));
  }
  function loadCfg() {
    const raw = localStorage.getItem(LS_APP_CFG_KEY);
    return raw ? JSON.parse(raw) : {};
  }
  function saveCfg(cfg) {
    localStorage.setItem(LS_APP_CFG_KEY, JSON.stringify(cfg));
  }
  const RightChevron = ({className = "w-5 h-5", ...props}) => <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" stroke="currentColor" fill="none" strokeWidth="2" strokeLinecap="round" strokeLinejoin="round" className={className} {...props}>
      <polyline points="9 18 15 12 9 6" />
    </svg>;
  const LightningIcon = () => <svg width="24" height="24" viewBox="0 0 48 48" fill="none" xmlns="http://www.w3.org/2000/svg">
      <path fillRule="evenodd" clipRule="evenodd" className="fill-[#3F59E4] dark:fill-[#99A7F1]" d="M24.971 30.152H7.088c-1.786 0-2.745-2.103-1.574-3.453l19.07-21.988c1.33-1.532 3.835-.4 3.569 1.607L24.97 30.152z" />
      <path fillRule="evenodd" clipRule="evenodd" className="fill-[#3F59E4] dark:fill-[#99A7F1]" d="M23.201 17.885h17.885c1.787 0 2.746 2.102 1.575 3.453l-19.073 21.99c-1.33 1.532-3.835.4-3.568-1.607L23.2 17.885z" />
    </svg>;
  const LayersIcon = () => <svg width="24" height="24" viewBox="0 0 48 48" fill="none" xmlns="http://www.w3.org/2000/svg">
      <path className="fill-[#3F59E4] dark:fill-[#99A7F1]" d="M34.54 29.135l6.373 3.183c1.566.782 1.566 3.017 0 3.8l-14.815 7.396a4.623 4.623 0 01-4.125 0L7.174 36.12c-1.565-.782-1.565-3.017 0-3.798l6.532-3.214" />
      <path className="fill-[#AAB6F3] dark:fill-[#3449BA]" d="M34.54 18.86l6.373 3.183c1.566.782 1.566 3.016 0 3.8L26.098 33.24a4.623 4.623 0 01-4.125 0L7.174 25.843c-1.565-.781-1.565-3.016 0-3.798l6.33-3.164" />
      <path className="fill-[#CFD6F8] dark:fill-[#22307C]" d="M21.94 23.058L7.306 15.745c-1.62-.81-1.62-3.123 0-3.932l14.631-7.319a4.693 4.693 0 014.194 0l14.648 7.319c1.622.81 1.62 3.124 0 3.932L26.13 23.058c-1.321.66-2.873.66-4.191 0z" />
    </svg>;
  const GithubIcon = () => <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" strokeWidth="2" strokeLinecap="round" strokeLinejoin="round" className="w-5 h-5">
      <path d="M9 19c-5 1.5-5-2.5-7-3m14 6v-3.87a3.37 3.37 0 0 0-.94-2.61c3.14-.35 6.44-1.54 6.44-7A5.44 5.44 0 0 0 20 4.77 5.07 5.07 0 0 0 19.91 1S18.73.65 16 2.48a13.38 13.38 0 0 0-7 0C6.27.65 5.09 1 5.09 1A5.07 5.07 0 0 0 5 4.77a5.44 5.44 0 0 0-1.5 3.78c0 5.42 3.3 6.61 6.44 7A3.37 3.37 0 0 0 9 18.13V22"></path>
    </svg>;
  function IconTile({children}) {
    return <div className="
          shrink-0 grid place-items-center w-10 h-10 rounded-lg
          bg-indigo-50 ring-1 ring-indigo-200/60
          dark:bg-indigo-950/40 dark:ring-white/10
        ">
        {children}
      </div>;
  }
  function Card({className = "", children}) {
    return <div className={`rounded-2xl shadow-sm ring-1 ring-zinc-200 dark:ring-zinc-800 ${className}`}>{children}</div>;
  }
  function Button({variant = "primary", type = "button", onClick, children}) {
    const base = "inline-flex items-center justify-center gap-2 h-10 px-4 rounded-xl font-medium transition";
    let styles = "";
    if (variant === "primary") {
      styles = "mint-bg-indigo-600 text-white hover:mint-bg-indigo-700";
    } else if (variant === "outline") {
      styles = "border border-zinc-300 dark:border-zinc-700 mint-bg-transparent hover:mint-bg-zinc-50 dark:hover:mint-bg-zinc-800";
    } else if (variant === "ghost") {
      styles = "hover:mint-bg-zinc-100 dark:hover:mint-bg-zinc-800";
    }
    return <button type={type} onClick={onClick} className={`${base} ${styles}`}>
        {children}
      </button>;
  }
  function Input({id, label, value, onChange, placeholder, name}) {
    return <label className="block space-y-1">
        <span className="text-sm text-zinc-700 dark:text-zinc-300">{label}</span>
        <input id={id} name={name} className="w-full h-11 px-3 rounded-xl border border-zinc-300 dark:border-zinc-700 bg-white dark:bg-zinc-900 text-zinc-900 dark:text-zinc-100 focus:outline-none focus:ring-2 focus:ring-indigo-500" placeholder={placeholder} value={value} onChange={e => onChange(e.target.value)} />
      </label>;
  }
  function Select({label, value, onChange, options}) {
    return <label className="block space-y-1 max-w-[300px]">
        <span className="text-sm text-zinc-700 dark:text-zinc-300">{label}</span>
        <div className="relative">
          <select className="w-full h-11 appearance-none px-3 pr-9 rounded-xl border border-zinc-300 dark:border-zinc-700 bg-white dark:bg-zinc-900 text-zinc-900 dark:text-zinc-100 focus:outline-none focus:ring-2 focus:ring-indigo-500" value={value} onChange={e => onChange(e.target.value)}>
            <optgroup label="Generic Applications">
              {options.map(o => <option key={o.id} value={o.id}>
                  {o.name}
                </option>)}
            </optgroup>
          </select>
          <svg className="pointer-events-none absolute right-3 top-1/2 -translate-y-1/2 w-5 h-5 text-zinc-500" viewBox="0 0 24 24">
            <path d="M7 10l5 5 5-5z" fill="currentColor" />
          </svg>
        </div>
      </label>;
  }
  function Toast({open, onClose, children}) {
    useEffect(() => {
      if (!open) return;
      const t = setTimeout(onClose, 2200);
      return () => clearTimeout(t);
    }, [open, onClose]);
    return <div className={`fixed right-4 top-4 z-50 transition ${open ? "opacity-100 translate-y-0" : "opacity-0 -translate-y-2 pointer-events-none"}`}>
        <div className="flex items-center gap-2 rounded-xl shadow ring-1 ring-emerald-200 bg-white dark:bg-zinc-900 px-4 py-2">
          <span className="w-1.5 h-8 rounded-l bg-emerald-500" />
          <svg className="w-5 h-5 text-emerald-600" viewBox="0 0 24 24" fill="none" stroke="currentColor" strokeWidth="2">
            <path d="M20 6L9 17l-5-5" />
          </svg>
          <span className="text-sm text-zinc-900 dark:text-zinc-100">{children}</span>
        </div>
      </div>;
  }
  function Flows() {
    const [route, setRoute] = useState("menu");
    const [apps, setApps] = useState(loadApps());
    const [cfg, setCfg] = useState(loadCfg());
    const [selected, setSelected] = useState(apps[0]?.id || "");
    const [toast, setToast] = useState(false);
    const [bc] = useState(() => mkChannel());
    useEffect(() => {
      if (!apps.find(a => a.id === selected)) {
        setSelected(apps[0]?.id || "");
      }
    }, [apps, selected]);
    useEffect(() => {
      const onMsg = e => {
        const {type, payload} = e.data || ({});
        switch (type) {
          case "NAV":
            setRoute(payload.route);
            break;
          case "SELECT":
            setSelected(payload.appId);
            break;
          case "APPS_UPDATED":
            setApps(loadApps());
            break;
          case "CFG_UPDATED":
            setCfg(loadCfg());
            setToast(true);
            break;
          default:
            break;
        }
      };
      bc.addEventListener("message", onMsg);
      return () => bc.removeEventListener("message", onMsg);
    }, [bc]);
    const nav = nextRoute => {
      setRoute(nextRoute);
      bc.postMessage({
        type: "NAV",
        payload: {
          route: nextRoute
        }
      });
    };
    const selectApp = appId => {
      setSelected(appId);
      bc.postMessage({
        type: "SELECT",
        payload: {
          appId
        }
      });
    };
    const onCreate = name => {
      const id = uid();
      const next = [...apps, {
        id,
        name: name || "Untitled"
      }];
      setApps(next);
      saveApps(next);
      bc.postMessage({
        type: "APPS_UPDATED"
      });
      selectApp(id);
      nav("integrate");
    };
    const onSaveCfg = (appId, data) => {
      const next = {
        ...cfg,
        [appId]: data
      };
      setCfg(next);
      saveCfg(next);
      setToast(true);
      bc.postMessage({
        type: "CFG_UPDATED"
      });
    };
    return <div>
        {route === "menu" && <Menu onCreate={() => nav("create")} onIntegrate={() => nav("integrate")} />}

        {route === "create" && <CreateForm onCancel={() => nav("menu")} onSave={onCreate} />}

        {route === "integrate" && <IntegrateForm apps={apps} selected={selected} onSelect={selectApp} saved={cfg[selected]} onSave={data => onSaveCfg(selected, data)} onCancel={() => nav("menu")} />}

        <Toast open={toast} onClose={() => setToast(false)}>
          Successfully saved your changes.
        </Toast>
      </div>;
  }
  function Menu({onCreate, onIntegrate}) {
    return <ul className="space-y-4 list-none login_list">
        <li className="list-none !px-0">
          <button onClick={onCreate} className="w-full text-left">
            <Card className="p-5 hover:shadow-md transition">
              <div className="flex items-center justify-between">
                <div className="flex items-center gap-4">
                  <IconTile>
                    <LightningIcon />
                  </IconTile>
                  <h2 className="text-lg">Create a new application</h2>
                </div>
                <RightChevron className="w-4 h-4 text-zinc-500" />
              </div>
            </Card>
          </button>
        </li>
        <li className="list-none !px-0">
          <button onClick={onIntegrate} className="w-full text-left">
            <Card className="p-5 hover:shadow-md transition">
              <div className="flex items-center justify-between">
                <div className="flex items-center gap-4">
                  <IconTile>
                    <LayersIcon />
                  </IconTile>
                  <h2 className="text-lg">Integrate with an existing application</h2>
                </div>
                <RightChevron className="w-4 h-4 text-zinc-500" />
              </div>
            </Card>
          </button>
        </li>
        <li className="list-none !px-0">
          <a className="no_external_icon block" href={sampleApp ? sampleApp : "/"} target="_blank" rel="noreferrer">
            <Card className="p-5 hover:shadow-md transition">
              <div className="flex items-center justify-between">
                <div className="flex items-center gap-4">
                  <IconTile>
                    <GithubIcon />
                  </IconTile>
                  <h2 className="text-lg">View a sample application</h2>
                </div>
                <RightChevron className="w-4 h-4 text-zinc-500" />
              </div>
            </Card>
          </a>
        </li>
      </ul>;
  }
  function CreateForm({onSave, onCancel}) {
    const [name, setName] = useState("");
    return <div className="space-y-6">
        <Input id="app-name" label="Application Name" placeholder="My App" value={name} onChange={setName} />
        <p className="text-sm text-zinc-500">You can change this later in the application settings.</p>
        <div className="flex gap-3">
          <Button onClick={() => onSave(name)}>Save</Button>
          <Button variant="outline" onClick={onCancel}>
            Cancel
          </Button>
        </div>
      </div>;
  }
  function IntegrateForm({apps, selected, onSelect, saved, onSave, onCancel}) {
    const [callbacks, setCallbacks] = useState(saved?.callbacks ?? "");
    const [logouts, setLogouts] = useState(saved?.logouts ?? "");
    const [origins, setOrigins] = useState(saved?.origins ?? "");
    useEffect(() => {
      setCallbacks(loadCfg()[selected]?.callbacks ?? "");
      setLogouts(loadCfg()[selected]?.logouts ?? "");
      setOrigins(loadCfg()[selected]?.origins ?? "");
    }, [selected]);
    return <div className="space-y-6">
        <div>
          <span className="block text-sm text-zinc-600 dark:text-zinc-300 mb-1">Select your Application</span>
          <Select label="" value={selected} onChange={onSelect} options={apps} />
        </div>

        <form className="space-y-4" onSubmit={e => {
      e.preventDefault();
      onSave({
        callbacks,
        logouts,
        origins
      });
    }}>
          <Input id="callbacks" name="callbacks" label="Callback URLs" placeholder="http://localhost:3000" value={callbacks} onChange={setCallbacks} />
          <Input id="logout" name="allowed_logout_urls" label="Logout URLs" placeholder="http://localhost:3000" value={logouts} onChange={setLogouts} />
          <Input id="origins" name="web_origins" label="Allowed Web Origins" placeholder="http://localhost:3000" value={origins} onChange={setOrigins} />

          <div className="flex gap-3 pt-2">
            <Button type="submit">Save</Button>
            <Button variant="outline" type="button" onClick={onCancel}>
              Cancel
            </Button>
          </div>
        </form>
      </div>;
  }
  return <div className="w-full mx-auto py-8">
      <Flows />
    </div>;
};

export const SignUpForm = () => {
  const [isAuthenticated, setIsAuthenticated] = useState(false);
  const [storeReady, setStoreReady] = useState(false);
  useEffect(() => {
    let unsubscribe = null;
    function init() {
      setStoreReady(true);
      unsubscribe = window.autorun(() => {
        const authenticated = window.rootStore?.sessionStore?.isAuthenticated || false;
        setIsAuthenticated(authenticated);
      });
    }
    if (window.rootStore) {
      init();
    } else {
      window.addEventListener("adu:storeReady", init);
    }
    return () => {
      window.removeEventListener("adu:storeReady", init);
      unsubscribe?.();
    };
  }, []);
  function LoggedInForm({sampleApp}) {
    const LS_APPS_KEY = "auth_demo_apps";
    const LS_APP_CFG_KEY = "auth_demo_app_cfg";
    const CHANNEL = "auth_flows_sync_v1";
    const mkChannel = () => new BroadcastChannel(CHANNEL);
    function uid() {
      return Math.random().toString(36).slice(2) + Date.now().toString(36);
    }
    function loadApps() {
      const raw = localStorage.getItem(LS_APPS_KEY);
      if (raw) return JSON.parse(raw);
      const seeded = [{
        id: "{yourClientId}",
        name: "Default App"
      }];
      localStorage.setItem(LS_APPS_KEY, JSON.stringify(seeded));
      return seeded;
    }
    function saveApps(apps) {
      localStorage.setItem(LS_APPS_KEY, JSON.stringify(apps));
    }
    function loadCfg() {
      const raw = localStorage.getItem(LS_APP_CFG_KEY);
      return raw ? JSON.parse(raw) : {};
    }
    function saveCfg(cfg) {
      localStorage.setItem(LS_APP_CFG_KEY, JSON.stringify(cfg));
    }
    const RightChevron = ({className = "w-5 h-5", ...props}) => <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" stroke="currentColor" fill="none" strokeWidth="2" strokeLinecap="round" strokeLinejoin="round" className={className} {...props}>
        <polyline points="9 18 15 12 9 6" />
      </svg>;
    const LightningIcon = () => <svg width="24" height="24" viewBox="0 0 48 48" fill="none" xmlns="http://www.w3.org/2000/svg">
        <path fillRule="evenodd" clipRule="evenodd" className="fill-[#3F59E4] dark:fill-[#99A7F1]" d="M24.971 30.152H7.088c-1.786 0-2.745-2.103-1.574-3.453l19.07-21.988c1.33-1.532 3.835-.4 3.569 1.607L24.97 30.152z" />
        <path fillRule="evenodd" clipRule="evenodd" className="fill-[#3F59E4] dark:fill-[#99A7F1]" d="M23.201 17.885h17.885c1.787 0 2.746 2.102 1.575 3.453l-19.073 21.99c-1.33 1.532-3.835.4-3.568-1.607L23.2 17.885z" />
      </svg>;
    const LayersIcon = () => <svg width="24" height="24" viewBox="0 0 48 48" fill="none" xmlns="http://www.w3.org/2000/svg">
        <path className="fill-[#3F59E4] dark:fill-[#99A7F1]" d="M34.54 29.135l6.373 3.183c1.566.782 1.566 3.017 0 3.8l-14.815 7.396a4.623 4.623 0 01-4.125 0L7.174 36.12c-1.565-.782-1.565-3.017 0-3.798l6.532-3.214" />
        <path className="fill-[#AAB6F3] dark:fill-[#3449BA]" d="M34.54 18.86l6.373 3.183c1.566.782 1.566 3.016 0 3.8L26.098 33.24a4.623 4.623 0 01-4.125 0L7.174 25.843c-1.565-.781-1.565-3.016 0-3.798l6.33-3.164" />
        <path className="fill-[#CFD6F8] dark:fill-[#22307C]" d="M21.94 23.058L7.306 15.745c-1.62-.81-1.62-3.123 0-3.932l14.631-7.319a4.693 4.693 0 014.194 0l14.648 7.319c1.622.81 1.62 3.124 0 3.932L26.13 23.058c-1.321.66-2.873.66-4.191 0z" />
      </svg>;
    const GithubIcon = () => <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none" stroke="currentColor" strokeWidth="2" strokeLinecap="round" strokeLinejoin="round" className="w-5 h-5">
        <path d="M9 19c-5 1.5-5-2.5-7-3m14 6v-3.87a3.37 3.37 0 0 0-.94-2.61c3.14-.35 6.44-1.54 6.44-7A5.44 5.44 0 0 0 20 4.77 5.07 5.07 0 0 0 19.91 1S18.73.65 16 2.48a13.38 13.38 0 0 0-7 0C6.27.65 5.09 1 5.09 1A5.07 5.07 0 0 0 5 4.77a5.44 5.44 0 0 0-1.5 3.78c0 5.42 3.3 6.61 6.44 7A3.37 3.37 0 0 0 9 18.13V22"></path>
      </svg>;
    function IconTile({children}) {
      return <div className="
            shrink-0 grid place-items-center w-10 h-10 rounded-lg
            bg-indigo-50 ring-1 ring-indigo-200/60
            dark:bg-indigo-950/40 dark:ring-white/10
          ">
          {children}
        </div>;
    }
    function Card({className = "", children}) {
      return <div className={`rounded-2xl shadow-sm ring-1 ring-zinc-200 dark:ring-zinc-800 ${className}`}>{children}</div>;
    }
    function Button({variant = "primary", type = "button", onClick, children}) {
      const base = "inline-flex items-center justify-center gap-2 h-10 px-4 rounded-xl font-medium transition";
      let styles = "";
      if (variant === "primary") {
        styles = "mint-bg-indigo-600 text-white hover:mint-bg-indigo-700";
      } else if (variant === "outline") {
        styles = "border border-zinc-300 dark:border-zinc-700 mint-bg-transparent hover:mint-bg-zinc-50 dark:hover:mint-bg-zinc-800";
      } else if (variant === "ghost") {
        styles = "hover:mint-bg-zinc-100 dark:hover:mint-bg-zinc-800";
      }
      return <button type={type} onClick={onClick} className={`${base} ${styles}`}>
          {children}
        </button>;
    }
    function Input({id, label, value, onChange, placeholder, name}) {
      return <label className="block space-y-1">
          <span className="text-sm text-zinc-700 dark:text-zinc-300">{label}</span>
          <input id={id} name={name} className="w-full h-11 px-3 rounded-xl border border-zinc-300 dark:border-zinc-700 bg-white dark:bg-zinc-900 text-zinc-900 dark:text-zinc-100 focus:outline-none focus:ring-2 focus:ring-indigo-500" placeholder={placeholder} value={value} onChange={e => onChange(e.target.value)} />
        </label>;
    }
    function Select({label, value, onChange, options}) {
      return <label className="block space-y-1 max-w-[300px]">
          <span className="text-sm text-zinc-700 dark:text-zinc-300">{label}</span>
          <div className="relative">
            <select className="w-full h-11 appearance-none px-3 pr-9 rounded-xl border border-zinc-300 dark:border-zinc-700 bg-white dark:bg-zinc-900 text-zinc-900 dark:text-zinc-100 focus:outline-none focus:ring-2 focus:ring-indigo-500" value={value} onChange={e => onChange(e.target.value)}>
              <optgroup label="Generic Applications">
                {options.map(o => <option key={o.id} value={o.id}>
                    {o.name}
                  </option>)}
              </optgroup>
            </select>
            <svg className="pointer-events-none absolute right-3 top-1/2 -translate-y-1/2 w-5 h-5 text-zinc-500" viewBox="0 0 24 24">
              <path d="M7 10l5 5 5-5z" fill="currentColor" />
            </svg>
          </div>
        </label>;
    }
    function Toast({open, onClose, children}) {
      useEffect(() => {
        if (!open) return;
        const t = setTimeout(onClose, 2200);
        return () => clearTimeout(t);
      }, [open, onClose]);
      return <div className={`fixed right-4 top-4 z-50 transition ${open ? "opacity-100 translate-y-0" : "opacity-0 -translate-y-2 pointer-events-none"}`}>
          <div className="flex items-center gap-2 rounded-xl shadow ring-1 ring-emerald-200 bg-white dark:bg-zinc-900 px-4 py-2">
            <span className="w-1.5 h-8 rounded-l bg-emerald-500" />
            <svg className="w-5 h-5 text-emerald-600" viewBox="0 0 24 24" fill="none" stroke="currentColor" strokeWidth="2">
              <path d="M20 6L9 17l-5-5" />
            </svg>
            <span className="text-sm text-zinc-900 dark:text-zinc-100">{children}</span>
          </div>
        </div>;
    }
    function Flows() {
      const [route, setRoute] = useState("menu");
      const [apps, setApps] = useState(loadApps());
      const [cfg, setCfg] = useState(loadCfg());
      const [selected, setSelected] = useState(apps[0]?.id || "");
      const [toast, setToast] = useState(false);
      const [bc] = useState(() => mkChannel());
      useEffect(() => {
        if (!apps.find(a => a.id === selected)) {
          setSelected(apps[0]?.id || "");
        }
      }, [apps, selected]);
      useEffect(() => {
        const onMsg = e => {
          const {type, payload} = e.data || ({});
          switch (type) {
            case "NAV":
              setRoute(payload.route);
              break;
            case "SELECT":
              setSelected(payload.appId);
              break;
            case "APPS_UPDATED":
              setApps(loadApps());
              break;
            case "CFG_UPDATED":
              setCfg(loadCfg());
              setToast(true);
              break;
            default:
              break;
          }
        };
        bc.addEventListener("message", onMsg);
        return () => bc.removeEventListener("message", onMsg);
      }, [bc]);
      const nav = nextRoute => {
        setRoute(nextRoute);
        bc.postMessage({
          type: "NAV",
          payload: {
            route: nextRoute
          }
        });
      };
      const selectApp = appId => {
        setSelected(appId);
        bc.postMessage({
          type: "SELECT",
          payload: {
            appId
          }
        });
      };
      const onCreate = name => {
        const id = uid();
        const next = [...apps, {
          id,
          name: name || "Untitled"
        }];
        setApps(next);
        saveApps(next);
        bc.postMessage({
          type: "APPS_UPDATED"
        });
        selectApp(id);
        nav("integrate");
      };
      const onSaveCfg = (appId, data) => {
        const next = {
          ...cfg,
          [appId]: data
        };
        setCfg(next);
        saveCfg(next);
        setToast(true);
        bc.postMessage({
          type: "CFG_UPDATED"
        });
      };
      return <div>
          {route === "menu" && <Menu onCreate={() => nav("create")} onIntegrate={() => nav("integrate")} />}

          {route === "create" && <CreateForm onCancel={() => nav("menu")} onSave={onCreate} />}

          {route === "integrate" && <IntegrateForm apps={apps} selected={selected} onSelect={selectApp} saved={cfg[selected]} onSave={data => onSaveCfg(selected, data)} onCancel={() => nav("menu")} />}

          <Toast open={toast} onClose={() => setToast(false)}>
            Successfully saved your changes.
          </Toast>
        </div>;
    }
    function Menu({onCreate, onIntegrate}) {
      return <ul className="space-y-4 list-none login_list">
          <li className="list-none !px-0">
            <button onClick={onCreate} className="w-full text-left">
              <Card className="p-5 hover:shadow-md transition">
                <div className="flex items-center justify-between">
                  <div className="flex items-center gap-4">
                    <IconTile>
                      <LightningIcon />
                    </IconTile>
                    <h2 className="text-lg">Create a new application</h2>
                  </div>
                  <RightChevron className="w-4 h-4 text-zinc-500" />
                </div>
              </Card>
            </button>
          </li>
          <li className="list-none !px-0">
            <button onClick={onIntegrate} className="w-full text-left">
              <Card className="p-5 hover:shadow-md transition">
                <div className="flex items-center justify-between">
                  <div className="flex items-center gap-4">
                    <IconTile>
                      <LayersIcon />
                    </IconTile>
                    <h2 className="text-lg">Integrate with an existing application</h2>
                  </div>
                  <RightChevron className="w-4 h-4 text-zinc-500" />
                </div>
              </Card>
            </button>
          </li>
          <li className="list-none !px-0">
            <a className="no_external_icon block" href={sampleApp ? sampleApp : "/"} target="_blank" rel="noreferrer">
              <Card className="p-5 hover:shadow-md transition">
                <div className="flex items-center justify-between">
                  <div className="flex items-center gap-4">
                    <IconTile>
                      <GithubIcon />
                    </IconTile>
                    <h2 className="text-lg">View a sample application</h2>
                  </div>
                  <RightChevron className="w-4 h-4 text-zinc-500" />
                </div>
              </Card>
            </a>
          </li>
        </ul>;
    }
    function CreateForm({onSave, onCancel}) {
      const [name, setName] = useState("");
      return <div className="space-y-6">
          <Input id="app-name" label="Application Name" placeholder="My App" value={name} onChange={setName} />
          <p className="text-sm text-zinc-500">You can change this later in the application settings.</p>
          <div className="flex gap-3">
            <Button onClick={() => onSave(name)}>Save</Button>
            <Button variant="outline" onClick={onCancel}>
              Cancel
            </Button>
          </div>
        </div>;
    }
    function IntegrateForm({apps, selected, onSelect, saved, onSave, onCancel}) {
      const [callbacks, setCallbacks] = useState(saved?.callbacks ?? "");
      const [logouts, setLogouts] = useState(saved?.logouts ?? "");
      const [origins, setOrigins] = useState(saved?.origins ?? "");
      useEffect(() => {
        setCallbacks(loadCfg()[selected]?.callbacks ?? "");
        setLogouts(loadCfg()[selected]?.logouts ?? "");
        setOrigins(loadCfg()[selected]?.origins ?? "");
      }, [selected]);
      return <div className="space-y-6">
          <div>
            <span className="block text-sm text-zinc-600 dark:text-zinc-300 mb-1">Select your Application</span>
            <Select label="" value={selected} onChange={onSelect} options={apps} />
          </div>

          <form className="space-y-4" onSubmit={e => {
        e.preventDefault();
        onSave({
          callbacks,
          logouts,
          origins
        });
      }}>
            <Input id="callbacks" name="callbacks" label="Callback URLs" placeholder="http://localhost:3000" value={callbacks} onChange={setCallbacks} />
            <Input id="logout" name="allowed_logout_urls" label="Logout URLs" placeholder="http://localhost:3000" value={logouts} onChange={setLogouts} />
            <Input id="origins" name="web_origins" label="Allowed Web Origins" placeholder="http://localhost:3000" value={origins} onChange={setOrigins} />

            <div className="flex gap-3 pt-2">
              <Button type="submit">Save</Button>
              <Button variant="outline" type="button" onClick={onCancel}>
                Cancel
              </Button>
            </div>
          </form>
        </div>;
    }
    return <div className="w-full mx-auto py-8">
        <Flows />
      </div>;
  }
  ;
  function SignUpFormInternal() {
    return <div className="flex flex-col gap-2 items-center h-full">
        <img noZoom src="/docs/img/quickstarts/action_hero_dashboard.svg" alt="Sign up for an Auth0 account" style={{
      width: "250px",
      height: "250px"
    }} />
        <span className="text-center" style={{
      width: "400px"
    }}>
          Sign up for an{" "}
          <a href="https://auth0.com/signup" target="_blank" rel="noopener noreferrer">
            Auth0 account
          </a>{" "}
          or{" "}
          <span className="font-semibold text-primary dark:text-white cursor-pointer" onClick={() => console.log("log in")}>
            log in
          </span>{" "}
          to your existing account to integrate directly with your own tenant.
        </span>
        <button onClick={() => console.log("sign up")} className="bg-primary dark:bg-primary-light text-white dark:text-black px-4 py-2 rounded-md mt-4 font-medium" style={{
      width: "140px"
    }}>
          Sign up
        </button>
      </div>;
  }
  ;
  return <></>;
};

export const SideMenuSectionItem = ({id, children}) => {
  return <div id={`side-menu-item-${id}`} className="recipe-side-menu-item flex flex-col w-full h-full">
      {children}
    </div>;
};

export const SideMenu = ({sections, children}) => {
  const [visibleSection, setVisibleSection] = useState(sections[0]?.id ?? null);
  const checkVisibility = () => {
    let currentVisible = null;
    const viewportHeight = window.innerHeight;
    const scrollY = window.scrollY;
    sections.forEach(({id}) => {
      const section = document.getElementById(id);
      if (section) {
        const rect = section.getBoundingClientRect();
        const sectionTop = rect.top + scrollY;
        const sectionBottom = sectionTop + rect.height;
        const multiplier = viewportHeight > 1600 ? 0.34 : 0.22;
        if (scrollY + viewportHeight * multiplier >= sectionTop && scrollY <= sectionBottom) {
          currentVisible = id;
        }
      }
    });
    if (currentVisible && currentVisible !== visibleSection) {
      setVisibleSection(currentVisible);
    }
  };
  useEffect(() => {
    const throttledCheck = () => {
      setTimeout(checkVisibility, 100);
    };
    checkVisibility();
    window.addEventListener("scroll", throttledCheck);
    return () => {
      window.removeEventListener("scroll", throttledCheck);
    };
  }, [sections, visibleSection]);
  useEffect(() => {
    sections.forEach(({id}) => {
      const section = document.getElementById(id);
      const sideMenuItem = document.getElementById(`side-menu-item-${id}`);
      if (section) {
        if (id === visibleSection) {
          section.classList.add("active-section");
        } else {
          section.classList.remove("active-section");
        }
      }
      if (sideMenuItem) {
        if (id === visibleSection) {
          sideMenuItem.classList.add("active-side-menu-item");
        } else {
          sideMenuItem.classList.remove("active-side-menu-item");
        }
      }
    });
  }, [visibleSection, sections]);
  return <div className="recipe-side-menu sticky px-2 py-1" style={{
    height: "calc(100vh - 7rem)",
    top: "7rem",
    scrollMarginTop: "var(--scroll-mt)"
  }}>
      {children.map(child => {
    if (child.props.id === visibleSection) {
      return child;
    }
    return null;
  })}
    </div>;
};

export const Section = ({id, title, stepNumber, children, isSingleColumn = false}) => {
  return <div id={id} className={`recipe-section flex flex-col transition-opacity duration-200`}>
      {}
      <Step title={title} stepNumber={stepNumber} titleSize="h3">
        {children}
      </Step>
    </div>;
};

export const Content = ({title, children}) => {
  return <div className="recipe-content flex flex-col">
      {title && <h1 className="text-3xl">{title}</h1>}
      {children}
    </div>;
};

export const Recipe = ({children, isSingleColumn = false}) => {
  return <div className={`pl-4 recipe-container mx-auto grid grid-cols-1 gap-10 relative ${isSingleColumn ? "md:grid-cols-1" : "md:grid-cols-2"}`}>
      {children}
    </div>;
};

<QuickstartButtons githubLink="https://github.com/auth0-samples/auth0-golang-web-app/tree/master/01-Login" lang="fr-ca" />

export const sections = [{
  id: "configuration-d-auth0",
  title: "Configuration d’Auth0"
}, {
  id: "installer-les-dépendances",
  title: "Installer les dépendances"
}, {
  id: "configurer-les-variables-d-environnement",
  title: "Configurer les variables d’environnement"
}, {
  id: "configurez-les-packages-oauth2-et-openid-connect",
  title: "Configurez les packages OAuth2 et OpenID Connect"
}, {
  id: "configurer-vos-routes-d-application",
  title: "Configurer vos routes d’application"
}, {
  id: "ajouter-une-fonctionnalité-de-connexion-à-votre-application",
  title: "Ajouter une fonctionnalité de connexion à votre application"
}, {
  id: "gérer-le-rappel-d-authentification",
  title: "Gérer le rappel d’authentification"
}, {
  id: "afficher-les-informations-du-profil-utilisateur",
  title: "Afficher les informations du profil utilisateur"
}, {
  id: "ajouter-une-fonctionnalité-de-déconnexion-à-votre-application",
  title: "Ajouter une fonctionnalité de déconnexion à votre application"
}, {
  id: "protéger-les-routes",
  title: "Protéger les routes"
}, {
  id: "lancer-votre-application",
  title: "Lancer votre application"
}];

<Recipe>
  <Content>
    Auth0 vous permet d’ajouter l’authentification et de pouvoir accéder aux informations relatives au profil de l’utilisateur dans votre application. Ce guide explique comment intégrer Auth0 à n’importe quelle application Web Go, nouvelle ou existante.

    <Section id={sections[0].id} title={sections[0].title} stepNumber="1">
      Pour utiliser les services Auth0, vous devez avoir une application installée dans Auth0 Dashboard. L’application Auth0 est l’endroit où vous allez configurer le fonctionnement de l’authentification pour le projet que vous développez.

      ### Configurer une application

      Utilisez le sélecteur interactif pour créer une nouvelle application Auth0 ou sélectionner une application existante qui représente le projet avec lequel vous souhaitez effectuer l’intégration. Dans Auth0, chaque application se voit attribuer un identifiant client unique alphanumérique que votre code d’application utilisera pour appeler les API Auth0 via la trousse SDK.

      Tous les paramètres que vous configurez à l’aide de ce guide de démarrage rapide seront automatiquement mis à jour pour votre application dans le [Tableau de bord](https://manage.auth0.com/dashboard/us/auth0-dsepaid/), qui est l’endroit où vous pourrez gérer vos applications à l’avenir.

      Si vous préférez explorer une configuration complète, consultez plutôt un exemple d’application.

      ### Configuration des URL de rappel

      Une URL de rappel est une URL intégrée dans votre application vers laquelle vous souhaitez qu’Auth0 redirige les utilisateurs après leur authentification. Si elle n’est pas définie, les utilisateurs ne seront pas redirigés vers votre application après s’être connectés.

      <Info>
        Si vous suivez notre exemple de projet, définissez cette URL comme suit : `http://localhost:3000``/callback`.
      </Info>

      ### Configuration des URL de déconnexion

      Une URL de déconnexion est une URL intégrée dans votre application vers laquelle vous souhaitez qu’Auth0 redirige les utilisateurs après leur déconnexion. Si elle n’est pas définie, les utilisateurs ne pourront pas se déconnecter de votre application et recevront un message d’erreur.

      <Info>
        Si vous suivez notre exemple de projet, définissez cette URL comme suit : `http://localhost:3000`.
      </Info>
    </Section>

    <Section id={sections[1].id} title={sections[1].title} stepNumber="2">
      Créez un fichier `go.mod` pour lister toutes les dépendances de votre application.

      Pour intégrer Auth0 dans une application Go, ajoutez les packages `coreos/go-oidc/v3` et `x/oauth2`.

      En plus des packages OIDC et OAuth2, ajoutez `joho/godotenv`, `gin-gonic/gin`, et `gin-contrib/sessions`.

      <Info>
        Cet exemple utilise `gin` pour le routage, mais vous pouvez utiliser le routeur de votre choix.
      </Info>

      Enregistrez le fichier `go.mod` avec les dépendances nécessaires et installez-les en utilisant la commande suivante dans votre terminal :

      `go mod download`
    </Section>

    <Section id={sections[2].id} title={sections[2].title} stepNumber="3">
      Vous devez définir les variables d’environnement suivantes dans `.env` à la racine de votre répertoire de projet :

      * **AUTH0\_DOMAIN** : Le domaine de votre locataire Auth0. Trouvez votre domaine Auth0 dans Auth0 Dashboard sous les paramètres de votre application dans le champ Domain (Domaine). Pour les domaines personnalisés, définissez-le plutôt sur la valeur de votre domaine personnalisé.
      * **AUTH0\_CLIENT\_ID** : L’identificateur de l’application Auth0 que vous avez configurée précédemment dans ce guide rapide. Vous le trouverez dans Auth0 Dashboard sous les paramètres de votre application dans le champ Client ID (Identificateur client).
      * **AUTH0\_CLIENT\_SECRET** : Le secret de l’application Auth0 que vous avez configurée précédemment dans ce guide rapide. Vous le trouverez dans Auth0 Dashboard, sous les paramètres de votre application dans le champ Client Secret (Secret client).
      * **AUTH0\_CALLBACK\_URL** : L’URL utilisée par Auth0 pour rediriger l’utilisateur après une authentification réussie.
    </Section>

    <Section id={sections[3].id} title={sections[3].title} stepNumber="4">
      Ensuite, configurez les packages OAuth2 et OpenID Connect

      Créez un fichier nommé `auth.go` dans le dossier `platform/authenticator`. Dans ce package, créez une méthode pour configurer et renvoyer les clients [OAuth2](https://godoc.org/golang.org/x/oauth2) et [OIDC](https://godoc.org/github.com/coreos/go-oidc), et une autre pour vérifier un jeton d’ID.
    </Section>

    <Section id={sections[4].id} title={sections[4].title} stepNumber="5">
      Créez un fichier nommé `router.go` dans le dossier `platform/router`. Dans ce package, créez une méthode pour configurer et renvoyer nos routes en utilisant [github.com/gin-gonic/gin](https://github.com/gin-gonic/gin). Vous passerez une instance de `Authenticator` à la méthode pour l’utiliser avec les gestionnaires `login (connexion)` et `callback (rappel)`.
    </Section>

    <Section id={sections[5].id} title={sections[5].title} stepNumber="6">
      Pour que l’utilisateur s’authentifie, nous devons créer une fonction gestionnaire pour traiter la route`/login`.

      Créez un fichier nommé `login.go` dans le dossier `web/app/login` et ajoutez une fonction `Handler`. Lors de l’exécution du gestionnaire, l’utilisateur sera redirigé vers Auth0 où il pourra saisir ses identifiants.

      Pour appeler la route `/login` ajoutez un lien vers `/login` dans le modèle `home.html` situé dans le directory `web/template`.
    </Section>

    <Section id={sections[6].id} title={sections[6].title} stepNumber="7">
      Une fois que les utilisateurs se sont authentifiés en utilisant la page de connexion universelle d’Auth0, ils reviendront à l’application à la route `/callback`.

      Créez un fichier nommé `callback.go` dans le dossier `web/app/callback` et ajoutez une fonction `Handler`.

      Ce gestionnaire prendra la chaîne de requête `code` fournie par Auth0 et l’échangera contre un jeton d’ID et un jeton d’accès.

      Si le jeton d’ID est valide, il stockera les informations de profil et le jeton d’accès dans la session. Les informations de profil sont basées sur les demandes contenues dans le jeton d’ID. Le stockage de session permet à l’application d’accéder à ces informations selon les besoins.
    </Section>

    <Section id={sections[7].id} title={sections[7].title} stepNumber="8">
      Maintenant que vos utilisateurs peuvent se connecter, vous voulez probablement pouvoir récupérer et utiliser les informations de profil associées aux utilisateurs authentifiés.

      Vous pouvez accéder à ces informations de profil, telles que leur pseudonyme ou leur photo de profil, à partir du `profile` qui a été sauvegardé dans la session précédemment.

      Créez un gestionnaire pour le point de terminaison `/user` dans `web/app/user/user.go` et renvoyez le fichier HTML correspondant. Comme le `profile` passe à `ctx.HTML()`, vous pouvez accéder aux informations de profil, telles que `picture` et `nickname` à l’intérieur de ce même fichier HTML.

      Un exemple de fichier HTML de ce type pourrait ressembler à l’exemple ci-dessous, mais vous pouvez récupérer n’importe quelle information de profil, y compris des demandes personnalisées.
    </Section>

    <Section id={sections[8].id} title={sections[8].title} stepNumber="9">
      Pour déconnecter l’utilisateur, effacez les données de la session et redirigez l’utilisateur vers le point de terminaison de déconnexion Auth0. Vous trouverez plus d’informations à ce sujet dans la [documentation sur la déconnexion](https://auth0.com/docs/logout).

      Créez un fichier nommé `logout.go` dans le dossier `web/app/logout`, et ajoutez la fonction `Handler` pour rediriger l’utilisateur vers le point de terminaison de déconnexion Auth0.

      L’URL `returnTo` doit figurer dans la liste des URL de déconnexion autorisées de la section des paramètres de l’application. Pour plus d’informations, consultez [Rediriger les utilisateurs après la déconnexion](https://auth0.com/docs/logout/guides/redirect-users-after-logout).

      Créez un fichier nommé `user.js` dans le dossier `web/static/js`, et ajoutez le code pour supprimer le témoin d’un utilisateur connecté.
    </Section>

    <Section id={sections[9].id} title={sections[9].title} stepNumber="10">
      La pratique recommandée veut que certaines routes ne soient accessibles qu’aux utilisateurs authentifiés. Lorsque des utilisateurs non authentifiés essaient d’accéder à des routes protégées, votre application devrait les rediriger.

      Dans ce cas, vous devez mettre en œuvre un intergiciel pour accéder à la requête HTTP. La fonction d’intergiciel détermine si la requête doit être dirigée vers le gestionnaire de point de terminaison ou si elle doit être bloquée.

      Créez un fichier nommé `isAuthenticated.go` dans `platform/middleware` et ajoutez une fonction qui vérifie si l’utilisateur est authentifié ou non, en fonction de la clé de session de `profile`. Si l’utilisateur n’est pas authentifié, l’intergiciel le redirigera vers la racine de l’application.

      L’intergiciel créé, nous pouvons le configurer pour toute route nécessitant une authentification en l’ajoutant au routeur.
    </Section>

    <Section id={sections[10].id} title={sections[10].title} stepNumber="11">
      L’authentificateur et le routeur configurés, nous pouvons connecter les éléments à l’aide du point d’entrée de notre application. Dans `main.go`, créez une instance de l’authentificateur et du routeur, qui reçoit l’instance de l’authentificateur.

      Si vous utilisez un fichier `.env` , vous devez appeler `godotenv.Load()` au tout début de la fonction `main()`.

      Lancez votre application en utilisant la commande suivante dans votre terminal :

      `go run main.go`
    </Section>

    ## Étapes suivantes

    Beau travail! Si vous en êtes arrivé là, vous devriez avoir la connexion, la déconnexion et les informations de profil utilisateur actives dans votre application.

    Cela conclut notre tutoriel de démarrage rapide, mais il y a tellement plus à explorer. Pour en savoir plus sur ce que vous pouvez faire avec Auth0, consultez :

    * [Auth0 Dashboard](https://manage.auth0.com/#) : apprenez à configurer et gérer votre locataire et vos applications Auth0
    * [Auth0 Marketplace](https://marketplace.auth0.com/) : découvrez des intégrations que vous pouvez activer pour étendre les fonctionnalités d’Auth0
  </Content>

  <SideMenu sections={sections}>
    <SideMenuSectionItem id={sections[0].id}>
      <SignUpForm lang="fr" />
    </SideMenuSectionItem>

    <SideMenuSectionItem id={sections[1].id}>
      <AuthCodeGroup>
        ```golang user.go lines theme={null}
        // Save this file in ./web/app/user/user.go

        package user

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // Handler for our logged-in user page.
        func Handler(ctx *gin.Context) {
        	session := sessions.Default(ctx)
        	profile := session.Get("profile")

        	ctx.HTML(http.StatusOK, "user.html", profile)
        }
        ```

        ```golang auth.go lines  theme={null}
        // Save this file in ./platform/authenticator/auth.go

        package authenticator

        import (
        	"context"
        	"errors"
        	"os"

        	"github.com/coreos/go-oidc/v3/oidc"
        	"golang.org/x/oauth2"
        )

        // Authenticator is used to authenticate our users.
        type Authenticator struct {
        	*oidc.Provider
        	oauth2.Config
        }

        // New instantiates the *Authenticator.
        func New() (*Authenticator, error) {
        	provider, err := oidc.NewProvider(
        		context.Background(),
        		"https://"+os.Getenv("AUTH0_DOMAIN")+"/",
        	)
        	if err != nil {
        		return nil, err
        	}

        	conf := oauth2.Config{
        		ClientID:     os.Getenv("AUTH0_CLIENT_ID"),
        		ClientSecret: os.Getenv("AUTH0_CLIENT_SECRET"),
        		RedirectURL:  os.Getenv("AUTH0_CALLBACK_URL"),
        		Endpoint:     provider.Endpoint(),
        		Scopes:       []string{oidc.ScopeOpenID, "profile"},
        	}

        	return &Authenticator{
        		Provider: provider,
        		Config:   conf,
        	}, nil
        }

        // VerifyIDToken verifies that an *oauth2.Token is a valid *oidc.IDToken.
        func (a *Authenticator) VerifyIDToken(ctx context.Context, token *oauth2.Token) (*oidc.IDToken, error) {
        	rawIDToken, ok := token.Extra("id_token").(string)
        	if !ok {
        		return nil, errors.New("no id_token field in oauth2 token")
        	}

        	oidcConfig := &oidc.Config{
        		ClientID: a.ClientID,
        	}

        	return a.Verifier(oidcConfig).Verify(ctx, rawIDToken)
        }
        ```

        ```golang callback.go lines  theme={null}
        / Save this file in ./web/app/callback/callback.go

        package callback

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our callback.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		session := sessions.Default(ctx)
        		if ctx.Query("state") != session.Get("state") {
        			ctx.String(http.StatusBadRequest, "Invalid state parameter.")
        			return
        		}

        		// Exchange an authorization code for a token.
        		token, err := auth.Exchange(ctx.Request.Context(), ctx.Query("code"))
        		if err != nil {
        			ctx.String(http.StatusUnauthorized, "Failed to exchange an authorization code for a token.")
        			return
        		}

        		idToken, err := auth.VerifyIDToken(ctx.Request.Context(), token)
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, "Failed to verify ID Token.")
        			return
        		}

        		var profile map[string]interface{}
        		if err := idToken.Claims(&profile); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		session.Set("access_token", token.AccessToken)
        		session.Set("profile", profile)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Redirect to logged in page.
        		ctx.Redirect(http.StatusTemporaryRedirect, "/user")
        	}
        }
        ```

        ```env .env lines theme={null}
        # Save this file in ./.env

        # The URL of our Auth0 Tenant Domain.
        # If you're using a Custom Domain, be sure to set this to that value instead.
        AUTH0_DOMAIN='{yourDomain}'

        # Our Auth0 application's Client ID.
        AUTH0_CLIENT_ID='{yourClientId}'

        # Our Auth0 application's Client Secret.
        AUTH0_CLIENT_SECRET='{yourClientSecret}'

        # The Callback URL of our application.
        AUTH0_CALLBACK_URL='http://localhost:3000/callback'
        ```

        ```mod go.mod lines theme={null}
        // Save this file in ./go.mod

        module 01-Login

        go 1.21

        require (
        	github.com/coreos/go-oidc/v3 v3.8.0
        	github.com/gin-contrib/sessions v0.0.5
        	github.com/gin-gonic/gin v1.9.1
        	github.com/joho/godotenv v1.5.1
        	golang.org/x/oauth2 v0.15.0
        )
        ```

        ```golang isAuthenticated.go lines theme={null}
        // Save this file in ./platform/middleware/isAuthenticated.go

        package middleware

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // IsAuthenticated is a middleware that checks if
        // the user has already been authenticated previously.
        func IsAuthenticated(ctx *gin.Context) {
        	if sessions.Default(ctx).Get("profile") == nil {
        		ctx.Redirect(http.StatusSeeOther, "/")
        	} else {
        		ctx.Next()
        	}
        }
        ```

        ```golang login.go lines  theme={null}
        // Save this file in ./web/app/login/login.go

        package login

        import (
        	"crypto/rand"
        	"encoding/base64"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our login.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		state, err := generateRandomState()
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Save the state inside the session.
        		session := sessions.Default(ctx)
        		session.Set("state", state)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		ctx.Redirect(http.StatusTemporaryRedirect, auth.AuthCodeURL(state))
        	}
        }

        func generateRandomState() (string, error) {
        	b := make([]byte, 32)
        	_, err := rand.Read(b)
        	if err != nil {
        		return "", err
        	}

        	state := base64.StdEncoding.EncodeToString(b)

        	return state, nil
        }
        ```

        ```golang logout.go lines  theme={null}
        // Save this file in ./web/app/logout/logout.go

        package logout

        import (
        	"net/http"
        	"net/url"
        	"os"

        	"github.com/gin-gonic/gin"
        )

        // Handler for our logout.
        func Handler(ctx *gin.Context) {
        	logoutUrl, err := url.Parse("https://" + os.Getenv("AUTH0_DOMAIN") + "/v2/logout")
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	scheme := "http"
        	if ctx.Request.TLS != nil {
        		scheme = "https"
        	}

        	returnTo, err := url.Parse(scheme + "://" + ctx.Request.Host)
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	parameters := url.Values{}
        	parameters.Add("returnTo", returnTo.String())
        	parameters.Add("client_id", os.Getenv("AUTH0_CLIENT_ID"))
        	logoutUrl.RawQuery = parameters.Encode()

        	ctx.Redirect(http.StatusTemporaryRedirect, logoutUrl.String())
        }
        ```

        ```golang main.go lines  theme={null}
        // Save this file in ./main.go

        package main

        import (
        	"log"
        	"net/http"

        	"github.com/joho/godotenv"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/router"
        )

        func main() {
        	if err := godotenv.Load(); err != nil {
        		log.Fatalf("Failed to load the env vars: %v", err)
        	}

        	auth, err := authenticator.New()
        	if err != nil {
        		log.Fatalf("Failed to initialize the authenticator: %v", err)
        	}

        	rtr := router.New(auth)

        	log.Print("Server listening on http://localhost:3000/")
        	if err := http.ListenAndServe("0.0.0.0:3000", rtr); err != nil {
        		log.Fatalf("There was an error with the http server: %v", err)
        	}
        }
        ```

        ```golang router.go lines  theme={null}
        // Save this file in ./platform/router/router.go

        package router

        import (
        	"encoding/gob"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-contrib/sessions/cookie"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/middleware"
        	"01-Login/web/app/callback"
        	"01-Login/web/app/login"
        	"01-Login/web/app/logout"
        	"01-Login/web/app/user"
        )

        // New registers the routes and returns the router.
        func New(auth *authenticator.Authenticator) *gin.Engine {
        	router := gin.Default()

        	// To store custom types in our cookies,
        	// we must first register them using gob.Register
        	gob.Register(map[string]interface{}{})

        	store := cookie.NewStore([]byte("secret"))
        	router.Use(sessions.Sessions("auth-session", store))

        	router.Static("/public", "web/static")
        	router.LoadHTMLGlob("web/template/*")

        	router.GET("/", func(ctx *gin.Context) {
        		ctx.HTML(http.StatusOK, "home.html", nil)
        	})
        	router.GET("/login", login.Handler(auth))
        	router.GET("/callback", callback.Handler(auth))
        	router.GET("/user", user.Handler)
        	router.GET("/logout", logout.Handler)

        	return router
        }
        ```
      </AuthCodeGroup>
    </SideMenuSectionItem>

    <SideMenuSectionItem id={sections[2].id}>
      <AuthCodeGroup>
        ```env .env lines theme={null}
        # Save this file in ./.env

        # The URL of our Auth0 Tenant Domain.
        # If you're using a Custom Domain, be sure to set this to that value instead.
        AUTH0_DOMAIN='{yourDomain}'

        # Our Auth0 application's Client ID.
        AUTH0_CLIENT_ID='{yourClientId}'

        # Our Auth0 application's Client Secret.
        AUTH0_CLIENT_SECRET='{yourClientSecret}'

        # The Callback URL of our application.
        AUTH0_CALLBACK_URL='http://localhost:3000/callback'
        ```

        ```golang auth.go lines  theme={null}
        // Save this file in ./platform/authenticator/auth.go

        package authenticator

        import (
        	"context"
        	"errors"
        	"os"

        	"github.com/coreos/go-oidc/v3/oidc"
        	"golang.org/x/oauth2"
        )

        // Authenticator is used to authenticate our users.
        type Authenticator struct {
        	*oidc.Provider
        	oauth2.Config
        }

        // New instantiates the *Authenticator.
        func New() (*Authenticator, error) {
        	provider, err := oidc.NewProvider(
        		context.Background(),
        		"https://"+os.Getenv("AUTH0_DOMAIN")+"/",
        	)
        	if err != nil {
        		return nil, err
        	}

        	conf := oauth2.Config{
        		ClientID:     os.Getenv("AUTH0_CLIENT_ID"),
        		ClientSecret: os.Getenv("AUTH0_CLIENT_SECRET"),
        		RedirectURL:  os.Getenv("AUTH0_CALLBACK_URL"),
        		Endpoint:     provider.Endpoint(),
        		Scopes:       []string{oidc.ScopeOpenID, "profile"},
        	}

        	return &Authenticator{
        		Provider: provider,
        		Config:   conf,
        	}, nil
        }

        // VerifyIDToken verifies that an *oauth2.Token is a valid *oidc.IDToken.
        func (a *Authenticator) VerifyIDToken(ctx context.Context, token *oauth2.Token) (*oidc.IDToken, error) {
        	rawIDToken, ok := token.Extra("id_token").(string)
        	if !ok {
        		return nil, errors.New("no id_token field in oauth2 token")
        	}

        	oidcConfig := &oidc.Config{
        		ClientID: a.ClientID,
        	}

        	return a.Verifier(oidcConfig).Verify(ctx, rawIDToken)
        }
        ```

        ```golang callback.go lines  theme={null}
        / Save this file in ./web/app/callback/callback.go

        package callback

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our callback.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		session := sessions.Default(ctx)
        		if ctx.Query("state") != session.Get("state") {
        			ctx.String(http.StatusBadRequest, "Invalid state parameter.")
        			return
        		}

        		// Exchange an authorization code for a token.
        		token, err := auth.Exchange(ctx.Request.Context(), ctx.Query("code"))
        		if err != nil {
        			ctx.String(http.StatusUnauthorized, "Failed to exchange an authorization code for a token.")
        			return
        		}

        		idToken, err := auth.VerifyIDToken(ctx.Request.Context(), token)
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, "Failed to verify ID Token.")
        			return
        		}

        		var profile map[string]interface{}
        		if err := idToken.Claims(&profile); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		session.Set("access_token", token.AccessToken)
        		session.Set("profile", profile)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Redirect to logged in page.
        		ctx.Redirect(http.StatusTemporaryRedirect, "/user")
        	}
        }
        ```

        ```mod go.mod lines theme={null}
        // Save this file in ./go.mod

        module 01-Login

        go 1.21

        require (
        	github.com/coreos/go-oidc/v3 v3.8.0
        	github.com/gin-contrib/sessions v0.0.5
        	github.com/gin-gonic/gin v1.9.1
        	github.com/joho/godotenv v1.5.1
        	golang.org/x/oauth2 v0.15.0
        )
        ```

        ```golang isAuthenticated.go lines theme={null}
        // Save this file in ./platform/middleware/isAuthenticated.go

        package middleware

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // IsAuthenticated is a middleware that checks if
        // the user has already been authenticated previously.
        func IsAuthenticated(ctx *gin.Context) {
        	if sessions.Default(ctx).Get("profile") == nil {
        		ctx.Redirect(http.StatusSeeOther, "/")
        	} else {
        		ctx.Next()
        	}
        }
        ```

        ```golang login.go lines  theme={null}
        // Save this file in ./web/app/login/login.go

        package login

        import (
        	"crypto/rand"
        	"encoding/base64"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our login.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		state, err := generateRandomState()
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Save the state inside the session.
        		session := sessions.Default(ctx)
        		session.Set("state", state)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		ctx.Redirect(http.StatusTemporaryRedirect, auth.AuthCodeURL(state))
        	}
        }

        func generateRandomState() (string, error) {
        	b := make([]byte, 32)
        	_, err := rand.Read(b)
        	if err != nil {
        		return "", err
        	}

        	state := base64.StdEncoding.EncodeToString(b)

        	return state, nil
        }
        ```

        ```golang logout.go lines  theme={null}
        // Save this file in ./web/app/logout/logout.go

        package logout

        import (
        	"net/http"
        	"net/url"
        	"os"

        	"github.com/gin-gonic/gin"
        )

        // Handler for our logout.
        func Handler(ctx *gin.Context) {
        	logoutUrl, err := url.Parse("https://" + os.Getenv("AUTH0_DOMAIN") + "/v2/logout")
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	scheme := "http"
        	if ctx.Request.TLS != nil {
        		scheme = "https"
        	}

        	returnTo, err := url.Parse(scheme + "://" + ctx.Request.Host)
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	parameters := url.Values{}
        	parameters.Add("returnTo", returnTo.String())
        	parameters.Add("client_id", os.Getenv("AUTH0_CLIENT_ID"))
        	logoutUrl.RawQuery = parameters.Encode()

        	ctx.Redirect(http.StatusTemporaryRedirect, logoutUrl.String())
        }
        ```

        ```golang main.go lines  theme={null}
        // Save this file in ./main.go

        package main

        import (
        	"log"
        	"net/http"

        	"github.com/joho/godotenv"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/router"
        )

        func main() {
        	if err := godotenv.Load(); err != nil {
        		log.Fatalf("Failed to load the env vars: %v", err)
        	}

        	auth, err := authenticator.New()
        	if err != nil {
        		log.Fatalf("Failed to initialize the authenticator: %v", err)
        	}

        	rtr := router.New(auth)

        	log.Print("Server listening on http://localhost:3000/")
        	if err := http.ListenAndServe("0.0.0.0:3000", rtr); err != nil {
        		log.Fatalf("There was an error with the http server: %v", err)
        	}
        }
        ```

        ```golang router.go lines  theme={null}
        // Save this file in ./platform/router/router.go

        package router

        import (
        	"encoding/gob"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-contrib/sessions/cookie"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/middleware"
        	"01-Login/web/app/callback"
        	"01-Login/web/app/login"
        	"01-Login/web/app/logout"
        	"01-Login/web/app/user"
        )

        // New registers the routes and returns the router.
        func New(auth *authenticator.Authenticator) *gin.Engine {
        	router := gin.Default()

        	// To store custom types in our cookies,
        	// we must first register them using gob.Register
        	gob.Register(map[string]interface{}{})

        	store := cookie.NewStore([]byte("secret"))
        	router.Use(sessions.Sessions("auth-session", store))

        	router.Static("/public", "web/static")
        	router.LoadHTMLGlob("web/template/*")

        	router.GET("/", func(ctx *gin.Context) {
        		ctx.HTML(http.StatusOK, "home.html", nil)
        	})
        	router.GET("/login", login.Handler(auth))
        	router.GET("/callback", callback.Handler(auth))
        	router.GET("/user", user.Handler)
        	router.GET("/logout", logout.Handler)

        	return router
        }
        ```

        ```golang user.go lines theme={null}
        // Save this file in ./web/app/user/user.go

        package user

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // Handler for our logged-in user page.
        func Handler(ctx *gin.Context) {
        	session := sessions.Default(ctx)
        	profile := session.Get("profile")

        	ctx.HTML(http.StatusOK, "user.html", profile)
        }
        ```
      </AuthCodeGroup>
    </SideMenuSectionItem>

    <SideMenuSectionItem id={sections[3].id}>
      <AuthCodeGroup>
        ```golang auth.go lines  theme={null}
        // Save this file in ./platform/authenticator/auth.go

        package authenticator

        import (
        	"context"
        	"errors"
        	"os"

        	"github.com/coreos/go-oidc/v3/oidc"
        	"golang.org/x/oauth2"
        )

        // Authenticator is used to authenticate our users.
        type Authenticator struct {
        	*oidc.Provider
        	oauth2.Config
        }

        // New instantiates the *Authenticator.
        func New() (*Authenticator, error) {
        	provider, err := oidc.NewProvider(
        		context.Background(),
        		"https://"+os.Getenv("AUTH0_DOMAIN")+"/",
        	)
        	if err != nil {
        		return nil, err
        	}

        	conf := oauth2.Config{
        		ClientID:     os.Getenv("AUTH0_CLIENT_ID"),
        		ClientSecret: os.Getenv("AUTH0_CLIENT_SECRET"),
        		RedirectURL:  os.Getenv("AUTH0_CALLBACK_URL"),
        		Endpoint:     provider.Endpoint(),
        		Scopes:       []string{oidc.ScopeOpenID, "profile"},
        	}

        	return &Authenticator{
        		Provider: provider,
        		Config:   conf,
        	}, nil
        }

        // VerifyIDToken verifies that an *oauth2.Token is a valid *oidc.IDToken.
        func (a *Authenticator) VerifyIDToken(ctx context.Context, token *oauth2.Token) (*oidc.IDToken, error) {
        	rawIDToken, ok := token.Extra("id_token").(string)
        	if !ok {
        		return nil, errors.New("no id_token field in oauth2 token")
        	}

        	oidcConfig := &oidc.Config{
        		ClientID: a.ClientID,
        	}

        	return a.Verifier(oidcConfig).Verify(ctx, rawIDToken)
        }
        ```

        ```golang callback.go lines  theme={null}
        / Save this file in ./web/app/callback/callback.go

        package callback

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our callback.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		session := sessions.Default(ctx)
        		if ctx.Query("state") != session.Get("state") {
        			ctx.String(http.StatusBadRequest, "Invalid state parameter.")
        			return
        		}

        		// Exchange an authorization code for a token.
        		token, err := auth.Exchange(ctx.Request.Context(), ctx.Query("code"))
        		if err != nil {
        			ctx.String(http.StatusUnauthorized, "Failed to exchange an authorization code for a token.")
        			return
        		}

        		idToken, err := auth.VerifyIDToken(ctx.Request.Context(), token)
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, "Failed to verify ID Token.")
        			return
        		}

        		var profile map[string]interface{}
        		if err := idToken.Claims(&profile); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		session.Set("access_token", token.AccessToken)
        		session.Set("profile", profile)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Redirect to logged in page.
        		ctx.Redirect(http.StatusTemporaryRedirect, "/user")
        	}
        }
        ```

        ```env .env lines theme={null}
        # Save this file in ./.env

        # The URL of our Auth0 Tenant Domain.
        # If you're using a Custom Domain, be sure to set this to that value instead.
        AUTH0_DOMAIN='{yourDomain}'

        # Our Auth0 application's Client ID.
        AUTH0_CLIENT_ID='{yourClientId}'

        # Our Auth0 application's Client Secret.
        AUTH0_CLIENT_SECRET='{yourClientSecret}'

        # The Callback URL of our application.
        AUTH0_CALLBACK_URL='http://localhost:3000/callback'
        ```

        ```mod go.mod lines theme={null}
        // Save this file in ./go.mod

        module 01-Login

        go 1.21

        require (
        	github.com/coreos/go-oidc/v3 v3.8.0
        	github.com/gin-contrib/sessions v0.0.5
        	github.com/gin-gonic/gin v1.9.1
        	github.com/joho/godotenv v1.5.1
        	golang.org/x/oauth2 v0.15.0
        )
        ```

        ```golang isAuthenticated.go lines theme={null}
        // Save this file in ./platform/middleware/isAuthenticated.go

        package middleware

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // IsAuthenticated is a middleware that checks if
        // the user has already been authenticated previously.
        func IsAuthenticated(ctx *gin.Context) {
        	if sessions.Default(ctx).Get("profile") == nil {
        		ctx.Redirect(http.StatusSeeOther, "/")
        	} else {
        		ctx.Next()
        	}
        }
        ```

        ```golang login.go lines  theme={null}
        // Save this file in ./web/app/login/login.go

        package login

        import (
        	"crypto/rand"
        	"encoding/base64"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our login.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		state, err := generateRandomState()
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Save the state inside the session.
        		session := sessions.Default(ctx)
        		session.Set("state", state)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		ctx.Redirect(http.StatusTemporaryRedirect, auth.AuthCodeURL(state))
        	}
        }

        func generateRandomState() (string, error) {
        	b := make([]byte, 32)
        	_, err := rand.Read(b)
        	if err != nil {
        		return "", err
        	}

        	state := base64.StdEncoding.EncodeToString(b)

        	return state, nil
        }
        ```

        ```golang logout.go lines  theme={null}
        // Save this file in ./web/app/logout/logout.go

        package logout

        import (
        	"net/http"
        	"net/url"
        	"os"

        	"github.com/gin-gonic/gin"
        )

        // Handler for our logout.
        func Handler(ctx *gin.Context) {
        	logoutUrl, err := url.Parse("https://" + os.Getenv("AUTH0_DOMAIN") + "/v2/logout")
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	scheme := "http"
        	if ctx.Request.TLS != nil {
        		scheme = "https"
        	}

        	returnTo, err := url.Parse(scheme + "://" + ctx.Request.Host)
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	parameters := url.Values{}
        	parameters.Add("returnTo", returnTo.String())
        	parameters.Add("client_id", os.Getenv("AUTH0_CLIENT_ID"))
        	logoutUrl.RawQuery = parameters.Encode()

        	ctx.Redirect(http.StatusTemporaryRedirect, logoutUrl.String())
        }
        ```

        ```golang main.go lines  theme={null}
        // Save this file in ./main.go

        package main

        import (
        	"log"
        	"net/http"

        	"github.com/joho/godotenv"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/router"
        )

        func main() {
        	if err := godotenv.Load(); err != nil {
        		log.Fatalf("Failed to load the env vars: %v", err)
        	}

        	auth, err := authenticator.New()
        	if err != nil {
        		log.Fatalf("Failed to initialize the authenticator: %v", err)
        	}

        	rtr := router.New(auth)

        	log.Print("Server listening on http://localhost:3000/")
        	if err := http.ListenAndServe("0.0.0.0:3000", rtr); err != nil {
        		log.Fatalf("There was an error with the http server: %v", err)
        	}
        }
        ```

        ```golang router.go lines  theme={null}
        // Save this file in ./platform/router/router.go

        package router

        import (
        	"encoding/gob"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-contrib/sessions/cookie"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/middleware"
        	"01-Login/web/app/callback"
        	"01-Login/web/app/login"
        	"01-Login/web/app/logout"
        	"01-Login/web/app/user"
        )

        // New registers the routes and returns the router.
        func New(auth *authenticator.Authenticator) *gin.Engine {
        	router := gin.Default()

        	// To store custom types in our cookies,
        	// we must first register them using gob.Register
        	gob.Register(map[string]interface{}{})

        	store := cookie.NewStore([]byte("secret"))
        	router.Use(sessions.Sessions("auth-session", store))

        	router.Static("/public", "web/static")
        	router.LoadHTMLGlob("web/template/*")

        	router.GET("/", func(ctx *gin.Context) {
        		ctx.HTML(http.StatusOK, "home.html", nil)
        	})
        	router.GET("/login", login.Handler(auth))
        	router.GET("/callback", callback.Handler(auth))
        	router.GET("/user", user.Handler)
        	router.GET("/logout", logout.Handler)

        	return router
        }
        ```

        ```golang user.go lines theme={null}
        // Save this file in ./web/app/user/user.go

        package user

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // Handler for our logged-in user page.
        func Handler(ctx *gin.Context) {
        	session := sessions.Default(ctx)
        	profile := session.Get("profile")

        	ctx.HTML(http.StatusOK, "user.html", profile)
        }
        ```
      </AuthCodeGroup>
    </SideMenuSectionItem>

    <SideMenuSectionItem id={sections[4].id}>
      <AuthCodeGroup>
        ```golang router.go lines  theme={null}
        // Save this file in ./platform/router/router.go

        package router

        import (
        	"encoding/gob"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-contrib/sessions/cookie"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/middleware"
        	"01-Login/web/app/callback"
        	"01-Login/web/app/login"
        	"01-Login/web/app/logout"
        	"01-Login/web/app/user"
        )

        // New registers the routes and returns the router.
        func New(auth *authenticator.Authenticator) *gin.Engine {
        	router := gin.Default()

        	// To store custom types in our cookies,
        	// we must first register them using gob.Register
        	gob.Register(map[string]interface{}{})

        	store := cookie.NewStore([]byte("secret"))
        	router.Use(sessions.Sessions("auth-session", store))

        	router.Static("/public", "web/static")
        	router.LoadHTMLGlob("web/template/*")

        	router.GET("/", func(ctx *gin.Context) {
        		ctx.HTML(http.StatusOK, "home.html", nil)
        	})
        	router.GET("/login", login.Handler(auth))
        	router.GET("/callback", callback.Handler(auth))
        	router.GET("/user", user.Handler)
        	router.GET("/logout", logout.Handler)

        	return router
        }
        ```

        ```golang auth.go lines  theme={null}
        // Save this file in ./platform/authenticator/auth.go

        package authenticator

        import (
        	"context"
        	"errors"
        	"os"

        	"github.com/coreos/go-oidc/v3/oidc"
        	"golang.org/x/oauth2"
        )

        // Authenticator is used to authenticate our users.
        type Authenticator struct {
        	*oidc.Provider
        	oauth2.Config
        }

        // New instantiates the *Authenticator.
        func New() (*Authenticator, error) {
        	provider, err := oidc.NewProvider(
        		context.Background(),
        		"https://"+os.Getenv("AUTH0_DOMAIN")+"/",
        	)
        	if err != nil {
        		return nil, err
        	}

        	conf := oauth2.Config{
        		ClientID:     os.Getenv("AUTH0_CLIENT_ID"),
        		ClientSecret: os.Getenv("AUTH0_CLIENT_SECRET"),
        		RedirectURL:  os.Getenv("AUTH0_CALLBACK_URL"),
        		Endpoint:     provider.Endpoint(),
        		Scopes:       []string{oidc.ScopeOpenID, "profile"},
        	}

        	return &Authenticator{
        		Provider: provider,
        		Config:   conf,
        	}, nil
        }

        // VerifyIDToken verifies that an *oauth2.Token is a valid *oidc.IDToken.
        func (a *Authenticator) VerifyIDToken(ctx context.Context, token *oauth2.Token) (*oidc.IDToken, error) {
        	rawIDToken, ok := token.Extra("id_token").(string)
        	if !ok {
        		return nil, errors.New("no id_token field in oauth2 token")
        	}

        	oidcConfig := &oidc.Config{
        		ClientID: a.ClientID,
        	}

        	return a.Verifier(oidcConfig).Verify(ctx, rawIDToken)
        }
        ```

        ```golang callback.go lines  theme={null}
        / Save this file in ./web/app/callback/callback.go

        package callback

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our callback.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		session := sessions.Default(ctx)
        		if ctx.Query("state") != session.Get("state") {
        			ctx.String(http.StatusBadRequest, "Invalid state parameter.")
        			return
        		}

        		// Exchange an authorization code for a token.
        		token, err := auth.Exchange(ctx.Request.Context(), ctx.Query("code"))
        		if err != nil {
        			ctx.String(http.StatusUnauthorized, "Failed to exchange an authorization code for a token.")
        			return
        		}

        		idToken, err := auth.VerifyIDToken(ctx.Request.Context(), token)
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, "Failed to verify ID Token.")
        			return
        		}

        		var profile map[string]interface{}
        		if err := idToken.Claims(&profile); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		session.Set("access_token", token.AccessToken)
        		session.Set("profile", profile)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Redirect to logged in page.
        		ctx.Redirect(http.StatusTemporaryRedirect, "/user")
        	}
        }
        ```

        ```env .env lines theme={null}
        # Save this file in ./.env

        # The URL of our Auth0 Tenant Domain.
        # If you're using a Custom Domain, be sure to set this to that value instead.
        AUTH0_DOMAIN='{yourDomain}'

        # Our Auth0 application's Client ID.
        AUTH0_CLIENT_ID='{yourClientId}'

        # Our Auth0 application's Client Secret.
        AUTH0_CLIENT_SECRET='{yourClientSecret}'

        # The Callback URL of our application.
        AUTH0_CALLBACK_URL='http://localhost:3000/callback'
        ```

        ```mod go.mod lines theme={null}
        // Save this file in ./go.mod

        module 01-Login

        go 1.21

        require (
        	github.com/coreos/go-oidc/v3 v3.8.0
        	github.com/gin-contrib/sessions v0.0.5
        	github.com/gin-gonic/gin v1.9.1
        	github.com/joho/godotenv v1.5.1
        	golang.org/x/oauth2 v0.15.0
        )
        ```

        ```golang isAuthenticated.go lines theme={null}
        // Save this file in ./platform/middleware/isAuthenticated.go

        package middleware

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // IsAuthenticated is a middleware that checks if
        // the user has already been authenticated previously.
        func IsAuthenticated(ctx *gin.Context) {
        	if sessions.Default(ctx).Get("profile") == nil {
        		ctx.Redirect(http.StatusSeeOther, "/")
        	} else {
        		ctx.Next()
        	}
        }
        ```

        ```golang login.go lines  theme={null}
        // Save this file in ./web/app/login/login.go

        package login

        import (
        	"crypto/rand"
        	"encoding/base64"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our login.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		state, err := generateRandomState()
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Save the state inside the session.
        		session := sessions.Default(ctx)
        		session.Set("state", state)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		ctx.Redirect(http.StatusTemporaryRedirect, auth.AuthCodeURL(state))
        	}
        }

        func generateRandomState() (string, error) {
        	b := make([]byte, 32)
        	_, err := rand.Read(b)
        	if err != nil {
        		return "", err
        	}

        	state := base64.StdEncoding.EncodeToString(b)

        	return state, nil
        }
        ```

        ```golang logout.go lines  theme={null}
        // Save this file in ./web/app/logout/logout.go

        package logout

        import (
        	"net/http"
        	"net/url"
        	"os"

        	"github.com/gin-gonic/gin"
        )

        // Handler for our logout.
        func Handler(ctx *gin.Context) {
        	logoutUrl, err := url.Parse("https://" + os.Getenv("AUTH0_DOMAIN") + "/v2/logout")
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	scheme := "http"
        	if ctx.Request.TLS != nil {
        		scheme = "https"
        	}

        	returnTo, err := url.Parse(scheme + "://" + ctx.Request.Host)
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	parameters := url.Values{}
        	parameters.Add("returnTo", returnTo.String())
        	parameters.Add("client_id", os.Getenv("AUTH0_CLIENT_ID"))
        	logoutUrl.RawQuery = parameters.Encode()

        	ctx.Redirect(http.StatusTemporaryRedirect, logoutUrl.String())
        }
        ```

        ```golang main.go lines  theme={null}
        // Save this file in ./main.go

        package main

        import (
        	"log"
        	"net/http"

        	"github.com/joho/godotenv"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/router"
        )

        func main() {
        	if err := godotenv.Load(); err != nil {
        		log.Fatalf("Failed to load the env vars: %v", err)
        	}

        	auth, err := authenticator.New()
        	if err != nil {
        		log.Fatalf("Failed to initialize the authenticator: %v", err)
        	}

        	rtr := router.New(auth)

        	log.Print("Server listening on http://localhost:3000/")
        	if err := http.ListenAndServe("0.0.0.0:3000", rtr); err != nil {
        		log.Fatalf("There was an error with the http server: %v", err)
        	}
        }
        ```

        ```golang user.go lines theme={null}
        // Save this file in ./web/app/user/user.go

        package user

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // Handler for our logged-in user page.
        func Handler(ctx *gin.Context) {
        	session := sessions.Default(ctx)
        	profile := session.Get("profile")

        	ctx.HTML(http.StatusOK, "user.html", profile)
        }
        ```
      </AuthCodeGroup>
    </SideMenuSectionItem>

    <SideMenuSectionItem id={sections[5].id}>
      <AuthCodeGroup>
        ```golang login.go lines  theme={null}
        // Save this file in ./web/app/login/login.go

        package login

        import (
        	"crypto/rand"
        	"encoding/base64"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our login.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		state, err := generateRandomState()
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Save the state inside the session.
        		session := sessions.Default(ctx)
        		session.Set("state", state)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		ctx.Redirect(http.StatusTemporaryRedirect, auth.AuthCodeURL(state))
        	}
        }

        func generateRandomState() (string, error) {
        	b := make([]byte, 32)
        	_, err := rand.Read(b)
        	if err != nil {
        		return "", err
        	}

        	state := base64.StdEncoding.EncodeToString(b)

        	return state, nil
        }
        ```

        ```golang auth.go lines  theme={null}
        // Save this file in ./platform/authenticator/auth.go

        package authenticator

        import (
        	"context"
        	"errors"
        	"os"

        	"github.com/coreos/go-oidc/v3/oidc"
        	"golang.org/x/oauth2"
        )

        // Authenticator is used to authenticate our users.
        type Authenticator struct {
        	*oidc.Provider
        	oauth2.Config
        }

        // New instantiates the *Authenticator.
        func New() (*Authenticator, error) {
        	provider, err := oidc.NewProvider(
        		context.Background(),
        		"https://"+os.Getenv("AUTH0_DOMAIN")+"/",
        	)
        	if err != nil {
        		return nil, err
        	}

        	conf := oauth2.Config{
        		ClientID:     os.Getenv("AUTH0_CLIENT_ID"),
        		ClientSecret: os.Getenv("AUTH0_CLIENT_SECRET"),
        		RedirectURL:  os.Getenv("AUTH0_CALLBACK_URL"),
        		Endpoint:     provider.Endpoint(),
        		Scopes:       []string{oidc.ScopeOpenID, "profile"},
        	}

        	return &Authenticator{
        		Provider: provider,
        		Config:   conf,
        	}, nil
        }

        // VerifyIDToken verifies that an *oauth2.Token is a valid *oidc.IDToken.
        func (a *Authenticator) VerifyIDToken(ctx context.Context, token *oauth2.Token) (*oidc.IDToken, error) {
        	rawIDToken, ok := token.Extra("id_token").(string)
        	if !ok {
        		return nil, errors.New("no id_token field in oauth2 token")
        	}

        	oidcConfig := &oidc.Config{
        		ClientID: a.ClientID,
        	}

        	return a.Verifier(oidcConfig).Verify(ctx, rawIDToken)
        }
        ```

        ```golang callback.go lines  theme={null}
        / Save this file in ./web/app/callback/callback.go

        package callback

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our callback.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		session := sessions.Default(ctx)
        		if ctx.Query("state") != session.Get("state") {
        			ctx.String(http.StatusBadRequest, "Invalid state parameter.")
        			return
        		}

        		// Exchange an authorization code for a token.
        		token, err := auth.Exchange(ctx.Request.Context(), ctx.Query("code"))
        		if err != nil {
        			ctx.String(http.StatusUnauthorized, "Failed to exchange an authorization code for a token.")
        			return
        		}

        		idToken, err := auth.VerifyIDToken(ctx.Request.Context(), token)
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, "Failed to verify ID Token.")
        			return
        		}

        		var profile map[string]interface{}
        		if err := idToken.Claims(&profile); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		session.Set("access_token", token.AccessToken)
        		session.Set("profile", profile)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Redirect to logged in page.
        		ctx.Redirect(http.StatusTemporaryRedirect, "/user")
        	}
        }
        ```

        ```env .env lines theme={null}
        # Save this file in ./.env

        # The URL of our Auth0 Tenant Domain.
        # If you're using a Custom Domain, be sure to set this to that value instead.
        AUTH0_DOMAIN='{yourDomain}'

        # Our Auth0 application's Client ID.
        AUTH0_CLIENT_ID='{yourClientId}'

        # Our Auth0 application's Client Secret.
        AUTH0_CLIENT_SECRET='{yourClientSecret}'

        # The Callback URL of our application.
        AUTH0_CALLBACK_URL='http://localhost:3000/callback'
        ```

        ```mod go.mod lines theme={null}
        // Save this file in ./go.mod

        module 01-Login

        go 1.21

        require (
        	github.com/coreos/go-oidc/v3 v3.8.0
        	github.com/gin-contrib/sessions v0.0.5
        	github.com/gin-gonic/gin v1.9.1
        	github.com/joho/godotenv v1.5.1
        	golang.org/x/oauth2 v0.15.0
        )
        ```

        ```golang isAuthenticated.go lines theme={null}
        // Save this file in ./platform/middleware/isAuthenticated.go

        package middleware

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // IsAuthenticated is a middleware that checks if
        // the user has already been authenticated previously.
        func IsAuthenticated(ctx *gin.Context) {
        	if sessions.Default(ctx).Get("profile") == nil {
        		ctx.Redirect(http.StatusSeeOther, "/")
        	} else {
        		ctx.Next()
        	}
        }
        ```

        ```golang logout.go lines  theme={null}
        // Save this file in ./web/app/logout/logout.go

        package logout

        import (
        	"net/http"
        	"net/url"
        	"os"

        	"github.com/gin-gonic/gin"
        )

        // Handler for our logout.
        func Handler(ctx *gin.Context) {
        	logoutUrl, err := url.Parse("https://" + os.Getenv("AUTH0_DOMAIN") + "/v2/logout")
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	scheme := "http"
        	if ctx.Request.TLS != nil {
        		scheme = "https"
        	}

        	returnTo, err := url.Parse(scheme + "://" + ctx.Request.Host)
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	parameters := url.Values{}
        	parameters.Add("returnTo", returnTo.String())
        	parameters.Add("client_id", os.Getenv("AUTH0_CLIENT_ID"))
        	logoutUrl.RawQuery = parameters.Encode()

        	ctx.Redirect(http.StatusTemporaryRedirect, logoutUrl.String())
        }
        ```

        ```golang main.go lines  theme={null}
        // Save this file in ./main.go

        package main

        import (
        	"log"
        	"net/http"

        	"github.com/joho/godotenv"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/router"
        )

        func main() {
        	if err := godotenv.Load(); err != nil {
        		log.Fatalf("Failed to load the env vars: %v", err)
        	}

        	auth, err := authenticator.New()
        	if err != nil {
        		log.Fatalf("Failed to initialize the authenticator: %v", err)
        	}

        	rtr := router.New(auth)

        	log.Print("Server listening on http://localhost:3000/")
        	if err := http.ListenAndServe("0.0.0.0:3000", rtr); err != nil {
        		log.Fatalf("There was an error with the http server: %v", err)
        	}
        }
        ```

        ```golang router.go lines  theme={null}
        // Save this file in ./platform/router/router.go

        package router

        import (
        	"encoding/gob"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-contrib/sessions/cookie"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/middleware"
        	"01-Login/web/app/callback"
        	"01-Login/web/app/login"
        	"01-Login/web/app/logout"
        	"01-Login/web/app/user"
        )

        // New registers the routes and returns the router.
        func New(auth *authenticator.Authenticator) *gin.Engine {
        	router := gin.Default()

        	// To store custom types in our cookies,
        	// we must first register them using gob.Register
        	gob.Register(map[string]interface{}{})

        	store := cookie.NewStore([]byte("secret"))
        	router.Use(sessions.Sessions("auth-session", store))

        	router.Static("/public", "web/static")
        	router.LoadHTMLGlob("web/template/*")

        	router.GET("/", func(ctx *gin.Context) {
        		ctx.HTML(http.StatusOK, "home.html", nil)
        	})
        	router.GET("/login", login.Handler(auth))
        	router.GET("/callback", callback.Handler(auth))
        	router.GET("/user", user.Handler)
        	router.GET("/logout", logout.Handler)

        	return router
        }
        ```

        ```golang user.go lines theme={null}
        // Save this file in ./web/app/user/user.go

        package user

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // Handler for our logged-in user page.
        func Handler(ctx *gin.Context) {
        	session := sessions.Default(ctx)
        	profile := session.Get("profile")

        	ctx.HTML(http.StatusOK, "user.html", profile)
        }
        ```
      </AuthCodeGroup>
    </SideMenuSectionItem>

    <SideMenuSectionItem id={sections[6].id}>
      <AuthCodeGroup>
        ```golang callback.go lines  theme={null}
        / Save this file in ./web/app/callback/callback.go

        package callback

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our callback.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		session := sessions.Default(ctx)
        		if ctx.Query("state") != session.Get("state") {
        			ctx.String(http.StatusBadRequest, "Invalid state parameter.")
        			return
        		}

        		// Exchange an authorization code for a token.
        		token, err := auth.Exchange(ctx.Request.Context(), ctx.Query("code"))
        		if err != nil {
        			ctx.String(http.StatusUnauthorized, "Failed to exchange an authorization code for a token.")
        			return
        		}

        		idToken, err := auth.VerifyIDToken(ctx.Request.Context(), token)
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, "Failed to verify ID Token.")
        			return
        		}

        		var profile map[string]interface{}
        		if err := idToken.Claims(&profile); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		session.Set("access_token", token.AccessToken)
        		session.Set("profile", profile)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Redirect to logged in page.
        		ctx.Redirect(http.StatusTemporaryRedirect, "/user")
        	}
        }
        ```

        ```golang auth.go lines  theme={null}
        // Save this file in ./platform/authenticator/auth.go

        package authenticator

        import (
        	"context"
        	"errors"
        	"os"

        	"github.com/coreos/go-oidc/v3/oidc"
        	"golang.org/x/oauth2"
        )

        // Authenticator is used to authenticate our users.
        type Authenticator struct {
        	*oidc.Provider
        	oauth2.Config
        }

        // New instantiates the *Authenticator.
        func New() (*Authenticator, error) {
        	provider, err := oidc.NewProvider(
        		context.Background(),
        		"https://"+os.Getenv("AUTH0_DOMAIN")+"/",
        	)
        	if err != nil {
        		return nil, err
        	}

        	conf := oauth2.Config{
        		ClientID:     os.Getenv("AUTH0_CLIENT_ID"),
        		ClientSecret: os.Getenv("AUTH0_CLIENT_SECRET"),
        		RedirectURL:  os.Getenv("AUTH0_CALLBACK_URL"),
        		Endpoint:     provider.Endpoint(),
        		Scopes:       []string{oidc.ScopeOpenID, "profile"},
        	}

        	return &Authenticator{
        		Provider: provider,
        		Config:   conf,
        	}, nil
        }

        // VerifyIDToken verifies that an *oauth2.Token is a valid *oidc.IDToken.
        func (a *Authenticator) VerifyIDToken(ctx context.Context, token *oauth2.Token) (*oidc.IDToken, error) {
        	rawIDToken, ok := token.Extra("id_token").(string)
        	if !ok {
        		return nil, errors.New("no id_token field in oauth2 token")
        	}

        	oidcConfig := &oidc.Config{
        		ClientID: a.ClientID,
        	}

        	return a.Verifier(oidcConfig).Verify(ctx, rawIDToken)
        }
        ```

        ```env .env lines theme={null}
        # Save this file in ./.env

        # The URL of our Auth0 Tenant Domain.
        # If you're using a Custom Domain, be sure to set this to that value instead.
        AUTH0_DOMAIN='{yourDomain}'

        # Our Auth0 application's Client ID.
        AUTH0_CLIENT_ID='{yourClientId}'

        # Our Auth0 application's Client Secret.
        AUTH0_CLIENT_SECRET='{yourClientSecret}'

        # The Callback URL of our application.
        AUTH0_CALLBACK_URL='http://localhost:3000/callback'
        ```

        ```mod go.mod lines theme={null}
        // Save this file in ./go.mod

        module 01-Login

        go 1.21

        require (
        	github.com/coreos/go-oidc/v3 v3.8.0
        	github.com/gin-contrib/sessions v0.0.5
        	github.com/gin-gonic/gin v1.9.1
        	github.com/joho/godotenv v1.5.1
        	golang.org/x/oauth2 v0.15.0
        )
        ```

        ```golang isAuthenticated.go lines theme={null}
        // Save this file in ./platform/middleware/isAuthenticated.go

        package middleware

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // IsAuthenticated is a middleware that checks if
        // the user has already been authenticated previously.
        func IsAuthenticated(ctx *gin.Context) {
        	if sessions.Default(ctx).Get("profile") == nil {
        		ctx.Redirect(http.StatusSeeOther, "/")
        	} else {
        		ctx.Next()
        	}
        }
        ```

        ```golang login.go lines  theme={null}
        // Save this file in ./web/app/login/login.go

        package login

        import (
        	"crypto/rand"
        	"encoding/base64"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our login.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		state, err := generateRandomState()
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Save the state inside the session.
        		session := sessions.Default(ctx)
        		session.Set("state", state)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		ctx.Redirect(http.StatusTemporaryRedirect, auth.AuthCodeURL(state))
        	}
        }

        func generateRandomState() (string, error) {
        	b := make([]byte, 32)
        	_, err := rand.Read(b)
        	if err != nil {
        		return "", err
        	}

        	state := base64.StdEncoding.EncodeToString(b)

        	return state, nil
        }
        ```

        ```golang logout.go lines  theme={null}
        // Save this file in ./web/app/logout/logout.go

        package logout

        import (
        	"net/http"
        	"net/url"
        	"os"

        	"github.com/gin-gonic/gin"
        )

        // Handler for our logout.
        func Handler(ctx *gin.Context) {
        	logoutUrl, err := url.Parse("https://" + os.Getenv("AUTH0_DOMAIN") + "/v2/logout")
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	scheme := "http"
        	if ctx.Request.TLS != nil {
        		scheme = "https"
        	}

        	returnTo, err := url.Parse(scheme + "://" + ctx.Request.Host)
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	parameters := url.Values{}
        	parameters.Add("returnTo", returnTo.String())
        	parameters.Add("client_id", os.Getenv("AUTH0_CLIENT_ID"))
        	logoutUrl.RawQuery = parameters.Encode()

        	ctx.Redirect(http.StatusTemporaryRedirect, logoutUrl.String())
        }
        ```

        ```golang main.go lines  theme={null}
        // Save this file in ./main.go

        package main

        import (
        	"log"
        	"net/http"

        	"github.com/joho/godotenv"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/router"
        )

        func main() {
        	if err := godotenv.Load(); err != nil {
        		log.Fatalf("Failed to load the env vars: %v", err)
        	}

        	auth, err := authenticator.New()
        	if err != nil {
        		log.Fatalf("Failed to initialize the authenticator: %v", err)
        	}

        	rtr := router.New(auth)

        	log.Print("Server listening on http://localhost:3000/")
        	if err := http.ListenAndServe("0.0.0.0:3000", rtr); err != nil {
        		log.Fatalf("There was an error with the http server: %v", err)
        	}
        }
        ```

        ```golang router.go lines  theme={null}
        // Save this file in ./platform/router/router.go

        package router

        import (
        	"encoding/gob"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-contrib/sessions/cookie"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/middleware"
        	"01-Login/web/app/callback"
        	"01-Login/web/app/login"
        	"01-Login/web/app/logout"
        	"01-Login/web/app/user"
        )

        // New registers the routes and returns the router.
        func New(auth *authenticator.Authenticator) *gin.Engine {
        	router := gin.Default()

        	// To store custom types in our cookies,
        	// we must first register them using gob.Register
        	gob.Register(map[string]interface{}{})

        	store := cookie.NewStore([]byte("secret"))
        	router.Use(sessions.Sessions("auth-session", store))

        	router.Static("/public", "web/static")
        	router.LoadHTMLGlob("web/template/*")

        	router.GET("/", func(ctx *gin.Context) {
        		ctx.HTML(http.StatusOK, "home.html", nil)
        	})
        	router.GET("/login", login.Handler(auth))
        	router.GET("/callback", callback.Handler(auth))
        	router.GET("/user", user.Handler)
        	router.GET("/logout", logout.Handler)

        	return router
        }
        ```

        ```golang user.go lines theme={null}
        // Save this file in ./web/app/user/user.go

        package user

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // Handler for our logged-in user page.
        func Handler(ctx *gin.Context) {
        	session := sessions.Default(ctx)
        	profile := session.Get("profile")

        	ctx.HTML(http.StatusOK, "user.html", profile)
        }
        ```
      </AuthCodeGroup>
    </SideMenuSectionItem>

    <SideMenuSectionItem id={sections[7].id}>
      <AuthCodeGroup>
        ```golang user.go lines theme={null}
        // Save this file in ./web/app/user/user.go

        package user

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // Handler for our logged-in user page.
        func Handler(ctx *gin.Context) {
        	session := sessions.Default(ctx)
        	profile := session.Get("profile")

        	ctx.HTML(http.StatusOK, "user.html", profile)
        }
        ```

        ```golang auth.go lines  theme={null}
        // Save this file in ./platform/authenticator/auth.go

        package authenticator

        import (
        	"context"
        	"errors"
        	"os"

        	"github.com/coreos/go-oidc/v3/oidc"
        	"golang.org/x/oauth2"
        )

        // Authenticator is used to authenticate our users.
        type Authenticator struct {
        	*oidc.Provider
        	oauth2.Config
        }

        // New instantiates the *Authenticator.
        func New() (*Authenticator, error) {
        	provider, err := oidc.NewProvider(
        		context.Background(),
        		"https://"+os.Getenv("AUTH0_DOMAIN")+"/",
        	)
        	if err != nil {
        		return nil, err
        	}

        	conf := oauth2.Config{
        		ClientID:     os.Getenv("AUTH0_CLIENT_ID"),
        		ClientSecret: os.Getenv("AUTH0_CLIENT_SECRET"),
        		RedirectURL:  os.Getenv("AUTH0_CALLBACK_URL"),
        		Endpoint:     provider.Endpoint(),
        		Scopes:       []string{oidc.ScopeOpenID, "profile"},
        	}

        	return &Authenticator{
        		Provider: provider,
        		Config:   conf,
        	}, nil
        }

        // VerifyIDToken verifies that an *oauth2.Token is a valid *oidc.IDToken.
        func (a *Authenticator) VerifyIDToken(ctx context.Context, token *oauth2.Token) (*oidc.IDToken, error) {
        	rawIDToken, ok := token.Extra("id_token").(string)
        	if !ok {
        		return nil, errors.New("no id_token field in oauth2 token")
        	}

        	oidcConfig := &oidc.Config{
        		ClientID: a.ClientID,
        	}

        	return a.Verifier(oidcConfig).Verify(ctx, rawIDToken)
        }
        ```

        ```golang callback.go lines  theme={null}
        / Save this file in ./web/app/callback/callback.go

        package callback

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our callback.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		session := sessions.Default(ctx)
        		if ctx.Query("state") != session.Get("state") {
        			ctx.String(http.StatusBadRequest, "Invalid state parameter.")
        			return
        		}

        		// Exchange an authorization code for a token.
        		token, err := auth.Exchange(ctx.Request.Context(), ctx.Query("code"))
        		if err != nil {
        			ctx.String(http.StatusUnauthorized, "Failed to exchange an authorization code for a token.")
        			return
        		}

        		idToken, err := auth.VerifyIDToken(ctx.Request.Context(), token)
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, "Failed to verify ID Token.")
        			return
        		}

        		var profile map[string]interface{}
        		if err := idToken.Claims(&profile); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		session.Set("access_token", token.AccessToken)
        		session.Set("profile", profile)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Redirect to logged in page.
        		ctx.Redirect(http.StatusTemporaryRedirect, "/user")
        	}
        }
        ```

        ```env .env lines theme={null}
        # Save this file in ./.env

        # The URL of our Auth0 Tenant Domain.
        # If you're using a Custom Domain, be sure to set this to that value instead.
        AUTH0_DOMAIN='{yourDomain}'

        # Our Auth0 application's Client ID.
        AUTH0_CLIENT_ID='{yourClientId}'

        # Our Auth0 application's Client Secret.
        AUTH0_CLIENT_SECRET='{yourClientSecret}'

        # The Callback URL of our application.
        AUTH0_CALLBACK_URL='http://localhost:3000/callback'
        ```

        ```mod go.mod lines theme={null}
        // Save this file in ./go.mod

        module 01-Login

        go 1.21

        require (
        	github.com/coreos/go-oidc/v3 v3.8.0
        	github.com/gin-contrib/sessions v0.0.5
        	github.com/gin-gonic/gin v1.9.1
        	github.com/joho/godotenv v1.5.1
        	golang.org/x/oauth2 v0.15.0
        )
        ```

        ```golang isAuthenticated.go lines theme={null}
        // Save this file in ./platform/middleware/isAuthenticated.go

        package middleware

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // IsAuthenticated is a middleware that checks if
        // the user has already been authenticated previously.
        func IsAuthenticated(ctx *gin.Context) {
        	if sessions.Default(ctx).Get("profile") == nil {
        		ctx.Redirect(http.StatusSeeOther, "/")
        	} else {
        		ctx.Next()
        	}
        }
        ```

        ```golang login.go lines  theme={null}
        // Save this file in ./web/app/login/login.go

        package login

        import (
        	"crypto/rand"
        	"encoding/base64"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our login.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		state, err := generateRandomState()
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Save the state inside the session.
        		session := sessions.Default(ctx)
        		session.Set("state", state)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		ctx.Redirect(http.StatusTemporaryRedirect, auth.AuthCodeURL(state))
        	}
        }

        func generateRandomState() (string, error) {
        	b := make([]byte, 32)
        	_, err := rand.Read(b)
        	if err != nil {
        		return "", err
        	}

        	state := base64.StdEncoding.EncodeToString(b)

        	return state, nil
        }
        ```

        ```golang logout.go lines  theme={null}
        // Save this file in ./web/app/logout/logout.go

        package logout

        import (
        	"net/http"
        	"net/url"
        	"os"

        	"github.com/gin-gonic/gin"
        )

        // Handler for our logout.
        func Handler(ctx *gin.Context) {
        	logoutUrl, err := url.Parse("https://" + os.Getenv("AUTH0_DOMAIN") + "/v2/logout")
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	scheme := "http"
        	if ctx.Request.TLS != nil {
        		scheme = "https"
        	}

        	returnTo, err := url.Parse(scheme + "://" + ctx.Request.Host)
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	parameters := url.Values{}
        	parameters.Add("returnTo", returnTo.String())
        	parameters.Add("client_id", os.Getenv("AUTH0_CLIENT_ID"))
        	logoutUrl.RawQuery = parameters.Encode()

        	ctx.Redirect(http.StatusTemporaryRedirect, logoutUrl.String())
        }
        ```

        ```golang main.go lines  theme={null}
        // Save this file in ./main.go

        package main

        import (
        	"log"
        	"net/http"

        	"github.com/joho/godotenv"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/router"
        )

        func main() {
        	if err := godotenv.Load(); err != nil {
        		log.Fatalf("Failed to load the env vars: %v", err)
        	}

        	auth, err := authenticator.New()
        	if err != nil {
        		log.Fatalf("Failed to initialize the authenticator: %v", err)
        	}

        	rtr := router.New(auth)

        	log.Print("Server listening on http://localhost:3000/")
        	if err := http.ListenAndServe("0.0.0.0:3000", rtr); err != nil {
        		log.Fatalf("There was an error with the http server: %v", err)
        	}
        }
        ```

        ```golang router.go lines  theme={null}
        // Save this file in ./platform/router/router.go

        package router

        import (
        	"encoding/gob"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-contrib/sessions/cookie"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/middleware"
        	"01-Login/web/app/callback"
        	"01-Login/web/app/login"
        	"01-Login/web/app/logout"
        	"01-Login/web/app/user"
        )

        // New registers the routes and returns the router.
        func New(auth *authenticator.Authenticator) *gin.Engine {
        	router := gin.Default()

        	// To store custom types in our cookies,
        	// we must first register them using gob.Register
        	gob.Register(map[string]interface{}{})

        	store := cookie.NewStore([]byte("secret"))
        	router.Use(sessions.Sessions("auth-session", store))

        	router.Static("/public", "web/static")
        	router.LoadHTMLGlob("web/template/*")

        	router.GET("/", func(ctx *gin.Context) {
        		ctx.HTML(http.StatusOK, "home.html", nil)
        	})
        	router.GET("/login", login.Handler(auth))
        	router.GET("/callback", callback.Handler(auth))
        	router.GET("/user", user.Handler)
        	router.GET("/logout", logout.Handler)

        	return router
        }
        ```
      </AuthCodeGroup>
    </SideMenuSectionItem>

    <SideMenuSectionItem id={sections[8].id}>
      <AuthCodeGroup>
        ```golang logout.go lines  theme={null}
        // Save this file in ./web/app/logout/logout.go

        package logout

        import (
        	"net/http"
        	"net/url"
        	"os"

        	"github.com/gin-gonic/gin"
        )

        // Handler for our logout.
        func Handler(ctx *gin.Context) {
        	logoutUrl, err := url.Parse("https://" + os.Getenv("AUTH0_DOMAIN") + "/v2/logout")
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	scheme := "http"
        	if ctx.Request.TLS != nil {
        		scheme = "https"
        	}

        	returnTo, err := url.Parse(scheme + "://" + ctx.Request.Host)
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	parameters := url.Values{}
        	parameters.Add("returnTo", returnTo.String())
        	parameters.Add("client_id", os.Getenv("AUTH0_CLIENT_ID"))
        	logoutUrl.RawQuery = parameters.Encode()

        	ctx.Redirect(http.StatusTemporaryRedirect, logoutUrl.String())
        }
        ```

        ```golang auth.go lines  theme={null}
        // Save this file in ./platform/authenticator/auth.go

        package authenticator

        import (
        	"context"
        	"errors"
        	"os"

        	"github.com/coreos/go-oidc/v3/oidc"
        	"golang.org/x/oauth2"
        )

        // Authenticator is used to authenticate our users.
        type Authenticator struct {
        	*oidc.Provider
        	oauth2.Config
        }

        // New instantiates the *Authenticator.
        func New() (*Authenticator, error) {
        	provider, err := oidc.NewProvider(
        		context.Background(),
        		"https://"+os.Getenv("AUTH0_DOMAIN")+"/",
        	)
        	if err != nil {
        		return nil, err
        	}

        	conf := oauth2.Config{
        		ClientID:     os.Getenv("AUTH0_CLIENT_ID"),
        		ClientSecret: os.Getenv("AUTH0_CLIENT_SECRET"),
        		RedirectURL:  os.Getenv("AUTH0_CALLBACK_URL"),
        		Endpoint:     provider.Endpoint(),
        		Scopes:       []string{oidc.ScopeOpenID, "profile"},
        	}

        	return &Authenticator{
        		Provider: provider,
        		Config:   conf,
        	}, nil
        }

        // VerifyIDToken verifies that an *oauth2.Token is a valid *oidc.IDToken.
        func (a *Authenticator) VerifyIDToken(ctx context.Context, token *oauth2.Token) (*oidc.IDToken, error) {
        	rawIDToken, ok := token.Extra("id_token").(string)
        	if !ok {
        		return nil, errors.New("no id_token field in oauth2 token")
        	}

        	oidcConfig := &oidc.Config{
        		ClientID: a.ClientID,
        	}

        	return a.Verifier(oidcConfig).Verify(ctx, rawIDToken)
        }
        ```

        ```golang callback.go lines  theme={null}
        / Save this file in ./web/app/callback/callback.go

        package callback

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our callback.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		session := sessions.Default(ctx)
        		if ctx.Query("state") != session.Get("state") {
        			ctx.String(http.StatusBadRequest, "Invalid state parameter.")
        			return
        		}

        		// Exchange an authorization code for a token.
        		token, err := auth.Exchange(ctx.Request.Context(), ctx.Query("code"))
        		if err != nil {
        			ctx.String(http.StatusUnauthorized, "Failed to exchange an authorization code for a token.")
        			return
        		}

        		idToken, err := auth.VerifyIDToken(ctx.Request.Context(), token)
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, "Failed to verify ID Token.")
        			return
        		}

        		var profile map[string]interface{}
        		if err := idToken.Claims(&profile); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		session.Set("access_token", token.AccessToken)
        		session.Set("profile", profile)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Redirect to logged in page.
        		ctx.Redirect(http.StatusTemporaryRedirect, "/user")
        	}
        }
        ```

        ```env .env lines theme={null}
        # Save this file in ./.env

        # The URL of our Auth0 Tenant Domain.
        # If you're using a Custom Domain, be sure to set this to that value instead.
        AUTH0_DOMAIN='{yourDomain}'

        # Our Auth0 application's Client ID.
        AUTH0_CLIENT_ID='{yourClientId}'

        # Our Auth0 application's Client Secret.
        AUTH0_CLIENT_SECRET='{yourClientSecret}'

        # The Callback URL of our application.
        AUTH0_CALLBACK_URL='http://localhost:3000/callback'
        ```

        ```mod go.mod lines theme={null}
        // Save this file in ./go.mod

        module 01-Login

        go 1.21

        require (
        	github.com/coreos/go-oidc/v3 v3.8.0
        	github.com/gin-contrib/sessions v0.0.5
        	github.com/gin-gonic/gin v1.9.1
        	github.com/joho/godotenv v1.5.1
        	golang.org/x/oauth2 v0.15.0
        )
        ```

        ```golang isAuthenticated.go lines theme={null}
        // Save this file in ./platform/middleware/isAuthenticated.go

        package middleware

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // IsAuthenticated is a middleware that checks if
        // the user has already been authenticated previously.
        func IsAuthenticated(ctx *gin.Context) {
        	if sessions.Default(ctx).Get("profile") == nil {
        		ctx.Redirect(http.StatusSeeOther, "/")
        	} else {
        		ctx.Next()
        	}
        }
        ```

        ```golang login.go lines  theme={null}
        // Save this file in ./web/app/login/login.go

        package login

        import (
        	"crypto/rand"
        	"encoding/base64"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our login.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		state, err := generateRandomState()
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Save the state inside the session.
        		session := sessions.Default(ctx)
        		session.Set("state", state)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		ctx.Redirect(http.StatusTemporaryRedirect, auth.AuthCodeURL(state))
        	}
        }

        func generateRandomState() (string, error) {
        	b := make([]byte, 32)
        	_, err := rand.Read(b)
        	if err != nil {
        		return "", err
        	}

        	state := base64.StdEncoding.EncodeToString(b)

        	return state, nil
        }
        ```

        ```golang main.go lines  theme={null}
        // Save this file in ./main.go

        package main

        import (
        	"log"
        	"net/http"

        	"github.com/joho/godotenv"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/router"
        )

        func main() {
        	if err := godotenv.Load(); err != nil {
        		log.Fatalf("Failed to load the env vars: %v", err)
        	}

        	auth, err := authenticator.New()
        	if err != nil {
        		log.Fatalf("Failed to initialize the authenticator: %v", err)
        	}

        	rtr := router.New(auth)

        	log.Print("Server listening on http://localhost:3000/")
        	if err := http.ListenAndServe("0.0.0.0:3000", rtr); err != nil {
        		log.Fatalf("There was an error with the http server: %v", err)
        	}
        }
        ```

        ```golang router.go lines  theme={null}
        // Save this file in ./platform/router/router.go

        package router

        import (
        	"encoding/gob"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-contrib/sessions/cookie"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/middleware"
        	"01-Login/web/app/callback"
        	"01-Login/web/app/login"
        	"01-Login/web/app/logout"
        	"01-Login/web/app/user"
        )

        // New registers the routes and returns the router.
        func New(auth *authenticator.Authenticator) *gin.Engine {
        	router := gin.Default()

        	// To store custom types in our cookies,
        	// we must first register them using gob.Register
        	gob.Register(map[string]interface{}{})

        	store := cookie.NewStore([]byte("secret"))
        	router.Use(sessions.Sessions("auth-session", store))

        	router.Static("/public", "web/static")
        	router.LoadHTMLGlob("web/template/*")

        	router.GET("/", func(ctx *gin.Context) {
        		ctx.HTML(http.StatusOK, "home.html", nil)
        	})
        	router.GET("/login", login.Handler(auth))
        	router.GET("/callback", callback.Handler(auth))
        	router.GET("/user", user.Handler)
        	router.GET("/logout", logout.Handler)

        	return router
        }
        ```

        ```golang user.go lines theme={null}
        // Save this file in ./web/app/user/user.go

        package user

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // Handler for our logged-in user page.
        func Handler(ctx *gin.Context) {
        	session := sessions.Default(ctx)
        	profile := session.Get("profile")

        	ctx.HTML(http.StatusOK, "user.html", profile)
        }
        ```
      </AuthCodeGroup>
    </SideMenuSectionItem>

    <SideMenuSectionItem id={sections[9].id}>
      <AuthCodeGroup>
        ```golang isAuthenticated.go lines theme={null}
        // Save this file in ./platform/middleware/isAuthenticated.go

        package middleware

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // IsAuthenticated is a middleware that checks if
        // the user has already been authenticated previously.
        func IsAuthenticated(ctx *gin.Context) {
        	if sessions.Default(ctx).Get("profile") == nil {
        		ctx.Redirect(http.StatusSeeOther, "/")
        	} else {
        		ctx.Next()
        	}
        }
        ```

        ```golang auth.go lines  theme={null}
        // Save this file in ./platform/authenticator/auth.go

        package authenticator

        import (
        	"context"
        	"errors"
        	"os"

        	"github.com/coreos/go-oidc/v3/oidc"
        	"golang.org/x/oauth2"
        )

        // Authenticator is used to authenticate our users.
        type Authenticator struct {
        	*oidc.Provider
        	oauth2.Config
        }

        // New instantiates the *Authenticator.
        func New() (*Authenticator, error) {
        	provider, err := oidc.NewProvider(
        		context.Background(),
        		"https://"+os.Getenv("AUTH0_DOMAIN")+"/",
        	)
        	if err != nil {
        		return nil, err
        	}

        	conf := oauth2.Config{
        		ClientID:     os.Getenv("AUTH0_CLIENT_ID"),
        		ClientSecret: os.Getenv("AUTH0_CLIENT_SECRET"),
        		RedirectURL:  os.Getenv("AUTH0_CALLBACK_URL"),
        		Endpoint:     provider.Endpoint(),
        		Scopes:       []string{oidc.ScopeOpenID, "profile"},
        	}

        	return &Authenticator{
        		Provider: provider,
        		Config:   conf,
        	}, nil
        }

        // VerifyIDToken verifies that an *oauth2.Token is a valid *oidc.IDToken.
        func (a *Authenticator) VerifyIDToken(ctx context.Context, token *oauth2.Token) (*oidc.IDToken, error) {
        	rawIDToken, ok := token.Extra("id_token").(string)
        	if !ok {
        		return nil, errors.New("no id_token field in oauth2 token")
        	}

        	oidcConfig := &oidc.Config{
        		ClientID: a.ClientID,
        	}

        	return a.Verifier(oidcConfig).Verify(ctx, rawIDToken)
        }
        ```

        ```golang callback.go lines  theme={null}
        / Save this file in ./web/app/callback/callback.go

        package callback

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our callback.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		session := sessions.Default(ctx)
        		if ctx.Query("state") != session.Get("state") {
        			ctx.String(http.StatusBadRequest, "Invalid state parameter.")
        			return
        		}

        		// Exchange an authorization code for a token.
        		token, err := auth.Exchange(ctx.Request.Context(), ctx.Query("code"))
        		if err != nil {
        			ctx.String(http.StatusUnauthorized, "Failed to exchange an authorization code for a token.")
        			return
        		}

        		idToken, err := auth.VerifyIDToken(ctx.Request.Context(), token)
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, "Failed to verify ID Token.")
        			return
        		}

        		var profile map[string]interface{}
        		if err := idToken.Claims(&profile); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		session.Set("access_token", token.AccessToken)
        		session.Set("profile", profile)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Redirect to logged in page.
        		ctx.Redirect(http.StatusTemporaryRedirect, "/user")
        	}
        }
        ```

        ```env .env lines theme={null}
        # Save this file in ./.env

        # The URL of our Auth0 Tenant Domain.
        # If you're using a Custom Domain, be sure to set this to that value instead.
        AUTH0_DOMAIN='{yourDomain}'

        # Our Auth0 application's Client ID.
        AUTH0_CLIENT_ID='{yourClientId}'

        # Our Auth0 application's Client Secret.
        AUTH0_CLIENT_SECRET='{yourClientSecret}'

        # The Callback URL of our application.
        AUTH0_CALLBACK_URL='http://localhost:3000/callback'
        ```

        ```mod go.mod lines theme={null}
        // Save this file in ./go.mod

        module 01-Login

        go 1.21

        require (
        	github.com/coreos/go-oidc/v3 v3.8.0
        	github.com/gin-contrib/sessions v0.0.5
        	github.com/gin-gonic/gin v1.9.1
        	github.com/joho/godotenv v1.5.1
        	golang.org/x/oauth2 v0.15.0
        )
        ```

        ```golang login.go lines  theme={null}
        // Save this file in ./web/app/login/login.go

        package login

        import (
        	"crypto/rand"
        	"encoding/base64"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our login.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		state, err := generateRandomState()
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Save the state inside the session.
        		session := sessions.Default(ctx)
        		session.Set("state", state)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		ctx.Redirect(http.StatusTemporaryRedirect, auth.AuthCodeURL(state))
        	}
        }

        func generateRandomState() (string, error) {
        	b := make([]byte, 32)
        	_, err := rand.Read(b)
        	if err != nil {
        		return "", err
        	}

        	state := base64.StdEncoding.EncodeToString(b)

        	return state, nil
        }
        ```

        ```golang logout.go lines  theme={null}
        // Save this file in ./web/app/logout/logout.go

        package logout

        import (
        	"net/http"
        	"net/url"
        	"os"

        	"github.com/gin-gonic/gin"
        )

        // Handler for our logout.
        func Handler(ctx *gin.Context) {
        	logoutUrl, err := url.Parse("https://" + os.Getenv("AUTH0_DOMAIN") + "/v2/logout")
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	scheme := "http"
        	if ctx.Request.TLS != nil {
        		scheme = "https"
        	}

        	returnTo, err := url.Parse(scheme + "://" + ctx.Request.Host)
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	parameters := url.Values{}
        	parameters.Add("returnTo", returnTo.String())
        	parameters.Add("client_id", os.Getenv("AUTH0_CLIENT_ID"))
        	logoutUrl.RawQuery = parameters.Encode()

        	ctx.Redirect(http.StatusTemporaryRedirect, logoutUrl.String())
        }
        ```

        ```golang main.go lines  theme={null}
        // Save this file in ./main.go

        package main

        import (
        	"log"
        	"net/http"

        	"github.com/joho/godotenv"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/router"
        )

        func main() {
        	if err := godotenv.Load(); err != nil {
        		log.Fatalf("Failed to load the env vars: %v", err)
        	}

        	auth, err := authenticator.New()
        	if err != nil {
        		log.Fatalf("Failed to initialize the authenticator: %v", err)
        	}

        	rtr := router.New(auth)

        	log.Print("Server listening on http://localhost:3000/")
        	if err := http.ListenAndServe("0.0.0.0:3000", rtr); err != nil {
        		log.Fatalf("There was an error with the http server: %v", err)
        	}
        }
        ```

        ```golang router.go lines  theme={null}
        // Save this file in ./platform/router/router.go

        package router

        import (
        	"encoding/gob"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-contrib/sessions/cookie"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/middleware"
        	"01-Login/web/app/callback"
        	"01-Login/web/app/login"
        	"01-Login/web/app/logout"
        	"01-Login/web/app/user"
        )

        // New registers the routes and returns the router.
        func New(auth *authenticator.Authenticator) *gin.Engine {
        	router := gin.Default()

        	// To store custom types in our cookies,
        	// we must first register them using gob.Register
        	gob.Register(map[string]interface{}{})

        	store := cookie.NewStore([]byte("secret"))
        	router.Use(sessions.Sessions("auth-session", store))

        	router.Static("/public", "web/static")
        	router.LoadHTMLGlob("web/template/*")

        	router.GET("/", func(ctx *gin.Context) {
        		ctx.HTML(http.StatusOK, "home.html", nil)
        	})
        	router.GET("/login", login.Handler(auth))
        	router.GET("/callback", callback.Handler(auth))
        	router.GET("/user", user.Handler)
        	router.GET("/logout", logout.Handler)

        	return router
        }
        ```

        ```golang user.go lines theme={null}
        // Save this file in ./web/app/user/user.go

        package user

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // Handler for our logged-in user page.
        func Handler(ctx *gin.Context) {
        	session := sessions.Default(ctx)
        	profile := session.Get("profile")

        	ctx.HTML(http.StatusOK, "user.html", profile)
        }
        ```
      </AuthCodeGroup>
    </SideMenuSectionItem>

    <SideMenuSectionItem id={sections[10].id}>
      <AuthCodeGroup>
        ```golang main.go lines  theme={null}
        // Save this file in ./main.go

        package main

        import (
        	"log"
        	"net/http"

        	"github.com/joho/godotenv"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/router"
        )

        func main() {
        	if err := godotenv.Load(); err != nil {
        		log.Fatalf("Failed to load the env vars: %v", err)
        	}

        	auth, err := authenticator.New()
        	if err != nil {
        		log.Fatalf("Failed to initialize the authenticator: %v", err)
        	}

        	rtr := router.New(auth)

        	log.Print("Server listening on http://localhost:3000/")
        	if err := http.ListenAndServe("0.0.0.0:3000", rtr); err != nil {
        		log.Fatalf("There was an error with the http server: %v", err)
        	}
        }
        ```

        ```golang auth.go lines  theme={null}
        // Save this file in ./platform/authenticator/auth.go

        package authenticator

        import (
        	"context"
        	"errors"
        	"os"

        	"github.com/coreos/go-oidc/v3/oidc"
        	"golang.org/x/oauth2"
        )

        // Authenticator is used to authenticate our users.
        type Authenticator struct {
        	*oidc.Provider
        	oauth2.Config
        }

        // New instantiates the *Authenticator.
        func New() (*Authenticator, error) {
        	provider, err := oidc.NewProvider(
        		context.Background(),
        		"https://"+os.Getenv("AUTH0_DOMAIN")+"/",
        	)
        	if err != nil {
        		return nil, err
        	}

        	conf := oauth2.Config{
        		ClientID:     os.Getenv("AUTH0_CLIENT_ID"),
        		ClientSecret: os.Getenv("AUTH0_CLIENT_SECRET"),
        		RedirectURL:  os.Getenv("AUTH0_CALLBACK_URL"),
        		Endpoint:     provider.Endpoint(),
        		Scopes:       []string{oidc.ScopeOpenID, "profile"},
        	}

        	return &Authenticator{
        		Provider: provider,
        		Config:   conf,
        	}, nil
        }

        // VerifyIDToken verifies that an *oauth2.Token is a valid *oidc.IDToken.
        func (a *Authenticator) VerifyIDToken(ctx context.Context, token *oauth2.Token) (*oidc.IDToken, error) {
        	rawIDToken, ok := token.Extra("id_token").(string)
        	if !ok {
        		return nil, errors.New("no id_token field in oauth2 token")
        	}

        	oidcConfig := &oidc.Config{
        		ClientID: a.ClientID,
        	}

        	return a.Verifier(oidcConfig).Verify(ctx, rawIDToken)
        }
        ```

        ```golang callback.go lines  theme={null}
        / Save this file in ./web/app/callback/callback.go

        package callback

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our callback.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		session := sessions.Default(ctx)
        		if ctx.Query("state") != session.Get("state") {
        			ctx.String(http.StatusBadRequest, "Invalid state parameter.")
        			return
        		}

        		// Exchange an authorization code for a token.
        		token, err := auth.Exchange(ctx.Request.Context(), ctx.Query("code"))
        		if err != nil {
        			ctx.String(http.StatusUnauthorized, "Failed to exchange an authorization code for a token.")
        			return
        		}

        		idToken, err := auth.VerifyIDToken(ctx.Request.Context(), token)
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, "Failed to verify ID Token.")
        			return
        		}

        		var profile map[string]interface{}
        		if err := idToken.Claims(&profile); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		session.Set("access_token", token.AccessToken)
        		session.Set("profile", profile)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Redirect to logged in page.
        		ctx.Redirect(http.StatusTemporaryRedirect, "/user")
        	}
        }
        ```

        ```env .env lines theme={null}
        # Save this file in ./.env

        # The URL of our Auth0 Tenant Domain.
        # If you're using a Custom Domain, be sure to set this to that value instead.
        AUTH0_DOMAIN='{yourDomain}'

        # Our Auth0 application's Client ID.
        AUTH0_CLIENT_ID='{yourClientId}'

        # Our Auth0 application's Client Secret.
        AUTH0_CLIENT_SECRET='{yourClientSecret}'

        # The Callback URL of our application.
        AUTH0_CALLBACK_URL='http://localhost:3000/callback'
        ```

        ```mod go.mod lines theme={null}
        // Save this file in ./go.mod

        module 01-Login

        go 1.21

        require (
        	github.com/coreos/go-oidc/v3 v3.8.0
        	github.com/gin-contrib/sessions v0.0.5
        	github.com/gin-gonic/gin v1.9.1
        	github.com/joho/godotenv v1.5.1
        	golang.org/x/oauth2 v0.15.0
        )
        ```

        ```golang isAuthenticated.go lines theme={null}
        // Save this file in ./platform/middleware/isAuthenticated.go

        package middleware

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // IsAuthenticated is a middleware that checks if
        // the user has already been authenticated previously.
        func IsAuthenticated(ctx *gin.Context) {
        	if sessions.Default(ctx).Get("profile") == nil {
        		ctx.Redirect(http.StatusSeeOther, "/")
        	} else {
        		ctx.Next()
        	}
        }
        ```

        ```golang login.go lines  theme={null}
        // Save this file in ./web/app/login/login.go

        package login

        import (
        	"crypto/rand"
        	"encoding/base64"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        )

        // Handler for our login.
        func Handler(auth *authenticator.Authenticator) gin.HandlerFunc {
        	return func(ctx *gin.Context) {
        		state, err := generateRandomState()
        		if err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		// Save the state inside the session.
        		session := sessions.Default(ctx)
        		session.Set("state", state)
        		if err := session.Save(); err != nil {
        			ctx.String(http.StatusInternalServerError, err.Error())
        			return
        		}

        		ctx.Redirect(http.StatusTemporaryRedirect, auth.AuthCodeURL(state))
        	}
        }

        func generateRandomState() (string, error) {
        	b := make([]byte, 32)
        	_, err := rand.Read(b)
        	if err != nil {
        		return "", err
        	}

        	state := base64.StdEncoding.EncodeToString(b)

        	return state, nil
        }
        ```

        ```golang logout.go lines  theme={null}
        // Save this file in ./web/app/logout/logout.go

        package logout

        import (
        	"net/http"
        	"net/url"
        	"os"

        	"github.com/gin-gonic/gin"
        )

        // Handler for our logout.
        func Handler(ctx *gin.Context) {
        	logoutUrl, err := url.Parse("https://" + os.Getenv("AUTH0_DOMAIN") + "/v2/logout")
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	scheme := "http"
        	if ctx.Request.TLS != nil {
        		scheme = "https"
        	}

        	returnTo, err := url.Parse(scheme + "://" + ctx.Request.Host)
        	if err != nil {
        		ctx.String(http.StatusInternalServerError, err.Error())
        		return
        	}

        	parameters := url.Values{}
        	parameters.Add("returnTo", returnTo.String())
        	parameters.Add("client_id", os.Getenv("AUTH0_CLIENT_ID"))
        	logoutUrl.RawQuery = parameters.Encode()

        	ctx.Redirect(http.StatusTemporaryRedirect, logoutUrl.String())
        }
        ```

        ```golang router.go lines  theme={null}
        // Save this file in ./platform/router/router.go

        package router

        import (
        	"encoding/gob"
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-contrib/sessions/cookie"
        	"github.com/gin-gonic/gin"

        	"01-Login/platform/authenticator"
        	"01-Login/platform/middleware"
        	"01-Login/web/app/callback"
        	"01-Login/web/app/login"
        	"01-Login/web/app/logout"
        	"01-Login/web/app/user"
        )

        // New registers the routes and returns the router.
        func New(auth *authenticator.Authenticator) *gin.Engine {
        	router := gin.Default()

        	// To store custom types in our cookies,
        	// we must first register them using gob.Register
        	gob.Register(map[string]interface{}{})

        	store := cookie.NewStore([]byte("secret"))
        	router.Use(sessions.Sessions("auth-session", store))

        	router.Static("/public", "web/static")
        	router.LoadHTMLGlob("web/template/*")

        	router.GET("/", func(ctx *gin.Context) {
        		ctx.HTML(http.StatusOK, "home.html", nil)
        	})
        	router.GET("/login", login.Handler(auth))
        	router.GET("/callback", callback.Handler(auth))
        	router.GET("/user", user.Handler)
        	router.GET("/logout", logout.Handler)

        	return router
        }
        ```

        ```golang user.go lines theme={null}
        // Save this file in ./web/app/user/user.go

        package user

        import (
        	"net/http"

        	"github.com/gin-contrib/sessions"
        	"github.com/gin-gonic/gin"
        )

        // Handler for our logged-in user page.
        func Handler(ctx *gin.Context) {
        	session := sessions.Default(ctx)
        	profile := session.Get("profile")

        	ctx.HTML(http.StatusOK, "user.html", profile)
        }
        ```
      </AuthCodeGroup>
    </SideMenuSectionItem>
  </SideMenu>
</Recipe>
