viewer

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: Apache-2.0 Imports: 6 Imported by: 0

Documentation

Overview

Package viewer signs and verifies the short-lived viewer tokens a runner attaches to every request it forwards to an app. A token is "v1." + base64url(JSON claims) + "." + base64url(Ed25519 signature over "aicoded-viewer.v1." + the encoded claims).

Index

Constants

View Source
const Header = "Aicoded-Viewer"

Header is the request header that carries the token.

View Source
const MaxLifetime = 60 * time.Second

MaxLifetime is the longest a token may be valid.

Variables

View Source
var (
	ErrMalformed = errors.New("viewer token: malformed")
	ErrSignature = errors.New("viewer token: bad signature")
	ErrExpired   = errors.New("viewer token: expired, not yet valid or too long-lived")
	ErrAudience  = errors.New("viewer token: issued for another app")
)

Functions

func Sign

func Sign(key ed25519.PrivateKey, c Claims) (string, error)

Sign returns a token for c signed with key.

Types

type Claims

type Claims struct {
	Subject  string   `json:"sub"`
	Name     string   `json:"name,omitempty"`
	Groups   []string `json:"groups,omitempty"`
	Roles    []string `json:"roles,omitempty"`
	Audience string   `json:"aud"`
	Caller   string   `json:"caller,omitempty"` // calling app, for service calls
	App      bool     `json:"app,omitempty"`    // the calling app calls as itself, with no viewer
	IssuedAt int64    `json:"iat"`
	Expires  int64    `json:"exp"`
}

Claims describe the viewer of one request. A token for a call another app makes as itself has App set and names only the calling app: no subject, name, groups or roles.

func Verify

func Verify(keys []ed25519.PublicKey, token, audience string, now time.Time) (Claims, error)

Verify checks token against keys and returns its claims if it is valid at now for audience.

func VerifyIssued

func VerifyIssued(keys []ed25519.PublicKey, token, audience string, now time.Time, maxAge time.Duration) (Claims, error)

VerifyIssued checks a token that was issued for audience and that the app hands back to the runner. It accepts the token for maxAge after it was issued, whether or not it has expired since, but refuses one issued in the future or with a lifetime over MaxLifetime.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL