authsqlite

package
v0.1.0-preview.28 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 11, 2026 License: MPL-2.0 Imports: 29 Imported by: 0

Documentation

Overview

Package authsqlite implements auth.Repository using a private no-CGO SQLite database and a namespaced schema.

Index

Constants

View Source
const MailSchemaVersion = 1
View Source
const SchemaVersion = 11

Variables

This section is empty.

Functions

This section is empty.

Types

type MailRepository

type MailRepository struct {
	// contains filtered or unexported fields
}

MailRepository is optional. Construction opens no new connection and performs no migration. The outbox shares this store's DB so account/audit/mail commits are atomic. Applications must check RequireMailSchema before enabling routes.

func (*MailRepository) Complete

func (repo *MailRepository) Complete(ctx context.Context, digest [32]byte, requestID, newHash string, notices []mail.Message, audit auth.AuditEvent) (bool, error)

func (*MailRepository) Issue

func (repo *MailRepository) Issue(ctx context.Context, request authmail.Request, messages []mail.Message, audit auth.AuditEvent) error

func (*MailRepository) OwnSubject

func (repo *MailRepository) OwnSubject(ctx context.Context, session [32]byte, now time.Time) (authmail.Subject, error)

func (*MailRepository) Pending

func (repo *MailRepository) Pending(ctx context.Context, digest [32]byte, now time.Time) (authmail.Pending, error)

func (*MailRepository) ResetSubject

func (repo *MailRepository) ResetSubject(ctx context.Context, email string, now time.Time) (authmail.Subject, error)

type OpenOptions

type OpenOptions struct {
	// Migrate preserves the historical Open behavior when true. Applications
	// with operator-controlled releases set it false and call Migrate only from
	// their explicit migration command.
	Migrate bool
}

type Store

type Store struct {
	// contains filtered or unexported fields
}

func Open

func Open(path string) (*Store, error)

func OpenWithOptions

func OpenWithOptions(path string, options OpenOptions) (*Store, error)

func (*Store) AcceptInvitation

func (store *Store) AcceptInvitation(ctx context.Context, digest [32]byte, userID string, acceptedAt time.Time, audit organizations.AuditEvent) error

func (*Store) AcceptInvitationWithRoles

func (store *Store) AcceptInvitationWithRoles(ctx context.Context, digest [32]byte, userID, ownerRole string, acceptedAt time.Time, audit organizations.AuditEvent) error

func (*Store) AccessAudit

func (store *Store) AccessAudit(ctx context.Context, organizationID string, limit int) ([]access.AuditEvent, error)

func (*Store) AccountMail

func (store *Store) AccountMail(options mailsqlite.Options) (*MailRepository, *mailsqlite.Queue, error)

func (*Store) ActiveBreakGlass

func (store *Store) ActiveBreakGlass(ctx context.Context, organizationID, userID string, now time.Time) ([]access.BreakGlass, error)

func (*Store) AddTeamMember

func (store *Store) AddTeamMember(ctx context.Context, membership organizations.TeamMembership, audit organizations.AuditEvent) error

func (*Store) AppendAccessAudit

func (store *Store) AppendAccessAudit(ctx context.Context, audit access.AuditEvent) error

func (*Store) AppendAudit

func (store *Store) AppendAudit(ctx context.Context, event auth.AuditEvent) error

func (*Store) AssistedRecoveryGrant

func (store *Store) AssistedRecoveryGrant(ctx context.Context, digest [32]byte, now time.Time) (authrecovery.AssistedGrant, auth.User, error)

func (*Store) ChangeMembershipStatus

func (store *Store) ChangeMembershipStatus(ctx context.Context, input organizations.MembershipStatusChange, ownerRole string, audit organizations.AuditEvent) error

func (*Store) ChangeOwnedMembershipStatus

func (store *Store) ChangeOwnedMembershipStatus(ctx context.Context, input organizations.MembershipStatusChange, ownerRole string, audit organizations.AuditEvent) error

func (*Store) Close

func (store *Store) Close() error

func (*Store) CompleteAssistedRecovery

func (store *Store) CompleteAssistedRecovery(ctx context.Context, completion authrecovery.AssistedCompletion) error

func (*Store) CompletePasskeyRecovery

func (store *Store) CompletePasskeyRecovery(ctx context.Context, completion authrecovery.PasskeyCompletion) error

func (*Store) CompleteRegistration

func (store *Store) CompleteRegistration(ctx context.Context, digest [32]byte, completion account.RegistrationCompletion) error

func (*Store) ConsumeEnrollmentToken

func (store *Store) ConsumeEnrollmentToken(ctx context.Context, digest [32]byte, now time.Time) (auth.User, error)

func (*Store) ConsumeRecoveryCodeAndCreateGrant

func (store *Store) ConsumeRecoveryCodeAndCreateGrant(ctx context.Context, userID string, codeDigest [32]byte, grant authrecovery.Grant, audit auth.AuditEvent) error

func (*Store) CreateApplicationService

func (store *Store) CreateApplicationService(ctx context.Context, application organizations.ApplicationService) error

func (*Store) CreateBreakGlass

func (store *Store) CreateBreakGlass(ctx context.Context, grant access.BreakGlass, audit access.AuditEvent) error

func (*Store) CreateCeremony

func (store *Store) CreateCeremony(ctx context.Context, ceremony authwebauthn.Ceremony) error

func (*Store) CreateEnvironment

func (store *Store) CreateEnvironment(ctx context.Context, environment organizations.Environment) error

func (*Store) CreateInitialOwner

func (store *Store) CreateInitialOwner(ctx context.Context, setup bootstrap.Setup) error

CreateInitialOwner commits the root-local bootstrap across identity, enrollment, organization, membership, owner access, and all audit records.

func (*Store) CreateInvitation

func (store *Store) CreateInvitation(ctx context.Context, invitation organizations.Invitation, ownerRole string, audit organizations.AuditEvent) error

func (*Store) CreateInvitationWithRoles

func (store *Store) CreateInvitationWithRoles(ctx context.Context, invitation organizations.Invitation, ownerRole string, audit organizations.AuditEvent) error

func (*Store) CreateOrganization

func (store *Store) CreateOrganization(ctx context.Context, organization organizations.Organization, owner organizations.Membership, audit organizations.AuditEvent) error

func (*Store) CreateOwnedOrganization

func (store *Store) CreateOwnedOrganization(ctx context.Context, setup organizations.OwnedOrganization) error

CreateOwnedOrganization atomically creates a new organization and its first direct owner. It never grants authority in an existing organization.

func (*Store) CreatePasskeyUser

func (store *Store) CreatePasskeyUser(ctx context.Context, user auth.User, enrollment authwebauthn.EnrollmentToken, audit auth.AuditEvent) error

func (*Store) CreateProject

func (store *Store) CreateProject(ctx context.Context, project organizations.Project) error

func (*Store) CreateRegistration

func (store *Store) CreateRegistration(ctx context.Context, registration account.Registration, passwordHash string, audit auth.AuditEvent) error

func (*Store) CreateSession

func (store *Store) CreateSession(ctx context.Context, session auth.Session) error

func (*Store) CreateTeam

func (store *Store) CreateTeam(ctx context.Context, team organizations.Team, audit organizations.AuditEvent) error

func (*Store) CreateUser

func (store *Store) CreateUser(ctx context.Context, user auth.User, passwordHash string) error

func (*Store) CredentialByIdentifier

func (store *Store) CredentialByIdentifier(ctx context.Context, identifier string) (auth.User, string, error)

func (*Store) CredentialByUserID

func (store *Store) CredentialByUserID(ctx context.Context, userID string) (auth.User, string, error)

func (*Store) CredentialCount

func (store *Store) CredentialCount(ctx context.Context, userID string) (int, error)

func (*Store) CredentialsByUserID

func (store *Store) CredentialsByUserID(ctx context.Context, userID string) ([]authwebauthn.Credential, error)

func (*Store) CurrentSchema

func (store *Store) CurrentSchema(ctx context.Context) (int, error)

func (*Store) DeleteCredential

func (store *Store) DeleteCredential(ctx context.Context, userID string, credentialID []byte, minimumRemaining int, audit auth.AuditEvent) error

func (*Store) DeleteSession

func (store *Store) DeleteSession(ctx context.Context, digest [32]byte) error

func (*Store) EffectiveBindings

func (store *Store) EffectiveBindings(ctx context.Context, organizationID, userID string) ([]access.Binding, error)

func (*Store) Grant

func (store *Store) Grant(ctx context.Context, binding access.Binding) error

func (*Store) GrantRole

func (store *Store) GrantRole(ctx context.Context, userID, role string, when time.Time) error

func (*Store) InvitationByDigest

func (store *Store) InvitationByDigest(ctx context.Context, digest [32]byte, now time.Time) (organizations.Invitation, error)

func (*Store) Invitations

func (store *Store) Invitations(ctx context.Context, organizationID string, limit int) ([]organizations.Invitation, error)

func (*Store) IssueAssistedRecovery

func (store *Store) IssueAssistedRecovery(ctx context.Context, grant authrecovery.AssistedGrant, ownerRole string, authAudit auth.AuditEvent, accessAudit access.AuditEvent) (auth.User, error)

func (*Store) MembershipsForUser

func (store *Store) MembershipsForUser(ctx context.Context, userID string) ([]organizations.Membership, error)

func (*Store) Migrate

func (store *Store) Migrate(ctx context.Context) error

func (*Store) MigrateMail

func (store *Store) MigrateMail(ctx context.Context) error

MigrateMail is an explicit operator migration, separate from schema 11. It creates no verified identities for existing users and touches no commerce data.

func (*Store) OrganizationByID

func (store *Store) OrganizationByID(ctx context.Context, organizationID string) (organizations.Organization, error)

func (*Store) OrganizationDirectory

func (store *Store) OrganizationDirectory(ctx context.Context, query organizations.DirectoryQuery) (organizations.DirectoryPage, error)

OrganizationDirectory reads all personal/business and active/archived records. It does not join membership, grant access, or choose a merchant. Search covers exact ID and literal slug/name text using SQLite's ASCII case folding.

func (*Store) OrganizationMemberships

func (store *Store) OrganizationMemberships(ctx context.Context, organizationID string, limit int) ([]organizations.Membership, error)

func (*Store) OrganizationUserBindings

func (store *Store) OrganizationUserBindings(ctx context.Context, organizationID string, limit int) ([]access.Binding, error)

func (*Store) OwnProfile

func (store *Store) OwnProfile(ctx context.Context, session [32]byte, now time.Time) (auth.OwnProfile, error)

func (*Store) PasswordCredentialExists

func (store *Store) PasswordCredentialExists(ctx context.Context, userID string) (bool, error)

func (*Store) Ping

func (store *Store) Ping(ctx context.Context) error

func (*Store) PrincipalBySession

func (store *Store) PrincipalBySession(ctx context.Context, digest [32]byte, now time.Time) (auth.Principal, auth.Session, error)

func (*Store) RecoverUser

func (store *Store) RecoverUser(ctx context.Context, identifier string, enrollment authwebauthn.EnrollmentToken, audit auth.AuditEvent) (auth.User, error)

func (*Store) RecoveryGrant

func (store *Store) RecoveryGrant(ctx context.Context, digest [32]byte, now time.Time) (auth.User, error)

func (*Store) Registration

func (store *Store) Registration(ctx context.Context, digest [32]byte, now time.Time) (account.Registration, error)

func (*Store) RemoveMembership

func (store *Store) RemoveMembership(ctx context.Context, organizationID, userID, ownerRole string, audit organizations.AuditEvent) error

func (*Store) RemoveMembershipIfCurrent

func (store *Store) RemoveMembershipIfCurrent(ctx context.Context, input organizations.MembershipRemoval, ownerRole string, audit organizations.AuditEvent) error

func (*Store) RemoveOwnedMembershipIfCurrent

func (store *Store) RemoveOwnedMembershipIfCurrent(ctx context.Context, input organizations.MembershipRemoval, ownerRole string, audit organizations.AuditEvent) error

func (*Store) RemoveTeamMember

func (store *Store) RemoveTeamMember(ctx context.Context, teamID, userID string, audit organizations.AuditEvent) error

func (*Store) ReplaceOrganizationUserRole

func (store *Store) ReplaceOrganizationUserRole(ctx context.Context, expected []string, replacement access.Binding, ownerRole string, audit access.AuditEvent) error

func (*Store) ReplaceOrganizationUserRoles

func (store *Store) ReplaceOrganizationUserRoles(ctx context.Context, expected []string, replacements []access.Binding, ownerRole string, audit access.AuditEvent) error

func (*Store) ReplacePasswordAndRevokeSessions

func (store *Store) ReplacePasswordAndRevokeSessions(ctx context.Context, userID, expectedHash, newHash string, changedAt time.Time) error

func (*Store) ReplaceRecoveryCodes

func (store *Store) ReplaceRecoveryCodes(ctx context.Context, userID string, digests [][32]byte, createdAt time.Time, audit auth.AuditEvent) error

func (*Store) RequireCurrentSchema

func (store *Store) RequireCurrentSchema(ctx context.Context) error

func (*Store) RequireMailSchema

func (store *Store) RequireMailSchema(ctx context.Context) error

func (*Store) ResetPasswordAndRevokeSessions

func (store *Store) ResetPasswordAndRevokeSessions(ctx context.Context, userID, expectedHash, newHash string, changedAt time.Time, audit auth.AuditEvent) error

func (*Store) Revoke

func (store *Store) Revoke(ctx context.Context, bindingID, actorUserID string, when time.Time) error

func (*Store) RevokeInvitation

func (store *Store) RevokeInvitation(ctx context.Context, organizationID, invitationID, ownerRole string, revokedAt time.Time, audit organizations.AuditEvent) error

func (*Store) RevokeUserSessions

func (store *Store) RevokeUserSessions(ctx context.Context, userID string) error

func (*Store) SaveCredential

func (store *Store) SaveCredential(ctx context.Context, credential authwebauthn.Credential, audit auth.AuditEvent) error

func (*Store) SaveCredentialAndRetirePassword

func (store *Store) SaveCredentialAndRetirePassword(ctx context.Context, credential authwebauthn.Credential, audit auth.AuditEvent) error

func (*Store) SeedAccessPolicy

func (store *Store) SeedAccessPolicy(ctx context.Context, policy access.Policy) error

func (*Store) SeedPolicy

func (store *Store) SeedPolicy(ctx context.Context, seed auth.PolicySeed) error

func (*Store) SetMembershipStatus

func (store *Store) SetMembershipStatus(ctx context.Context, organizationID, userID, status, ownerRole string, audit organizations.AuditEvent) error

func (*Store) TakeCeremony

func (store *Store) TakeCeremony(ctx context.Context, digest [32]byte, now time.Time) (authwebauthn.Ceremony, error)

func (*Store) TakeRecoveryGrant

func (store *Store) TakeRecoveryGrant(ctx context.Context, digest [32]byte, now time.Time) (auth.User, error)

func (*Store) TeamByID

func (store *Store) TeamByID(ctx context.Context, organizationID, teamID string) (organizations.Team, error)

func (*Store) TeamsForUser

func (store *Store) TeamsForUser(ctx context.Context, organizationID, userID string) ([]organizations.Team, error)

func (*Store) TouchSession

func (store *Store) TouchSession(ctx context.Context, digest [32]byte, when time.Time) error

func (*Store) UpdateCredential

func (store *Store) UpdateCredential(ctx context.Context, credential authwebauthn.Credential) error

func (*Store) UpdateLastLogin

func (store *Store) UpdateLastLogin(ctx context.Context, userID string, when time.Time) error

func (*Store) UpdateOrganization

func (store *Store) UpdateOrganization(ctx context.Context, value organizations.Organization, expectedRevision int64, audit organizations.AuditEvent) error

func (*Store) UpdateOwnProfile

func (store *Store) UpdateOwnProfile(ctx context.Context, change auth.ProfileEdit, audit auth.AuditEvent) (auth.OwnProfile, error)

func (*Store) UpdateOwnedOrganization

func (store *Store) UpdateOwnedOrganization(ctx context.Context, value organizations.Organization, expectedRevision int64, ownerRole string, audit organizations.AuditEvent) error

func (*Store) UpdateTeam

func (store *Store) UpdateTeam(ctx context.Context, value organizations.Team, expectedRevision int64, audit organizations.AuditEvent) error

func (*Store) UserByCredentialID

func (store *Store) UserByCredentialID(ctx context.Context, credentialID []byte) (auth.User, error)

func (*Store) UserByID

func (store *Store) UserByID(ctx context.Context, userID string) (auth.User, error)

func (*Store) UserByIdentifier

func (store *Store) UserByIdentifier(ctx context.Context, identifier string) (auth.User, error)

func (*Store) UserDirectory

func (store *Store) UserDirectory(ctx context.Context, query auth.UserDirectoryQuery) (auth.UserDirectoryPage, error)

UserDirectory is an administrative read; the adapter cannot infer application authorization. Search covers ID, username, email and display name. SQLite LIKE folds ASCII case; non-ASCII display-name text matches with its original case.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL