Documentation
¶
Overview ¶
Package viewer signs and verifies the short-lived viewer tokens a runner attaches to every request it forwards to an app. A token is "v1." + base64url(JSON claims) + "." + base64url(Ed25519 signature over "aicoded-viewer.v1." + the encoded claims).
Index ¶
Constants ¶
const Header = "Aicoded-Viewer"
Header is the request header that carries the token.
const MaxLifetime = 60 * time.Second
MaxLifetime is the longest a token may be valid.
Variables ¶
Functions ¶
Types ¶
type Claims ¶
type Claims struct {
Subject string `json:"sub"`
Name string `json:"name,omitempty"`
Groups []string `json:"groups,omitempty"`
Roles []string `json:"roles,omitempty"`
Audience string `json:"aud"`
Caller string `json:"caller,omitempty"` // calling app, for service calls
App bool `json:"app,omitempty"` // the calling app calls as itself, with no viewer
IssuedAt int64 `json:"iat"`
Expires int64 `json:"exp"`
}
Claims describe the viewer of one request. A token for a call another app makes as itself has App set and names only the calling app: no subject, name, groups or roles.
func Verify ¶
Verify checks token against keys and returns its claims if it is valid at now for audience.
func VerifyIssued ¶
func VerifyIssued(keys []ed25519.PublicKey, token, audience string, now time.Time, maxAge time.Duration) (Claims, error)
VerifyIssued checks a token that was issued for audience and that the app hands back to the runner. It accepts the token for maxAge after it was issued, whether or not it has expired since, but refuses one issued in the future or with a lifetime over MaxLifetime.