Documentation
¶
Overview ¶
Package grpcauth makes the caller's identity, carried in the "USER" gRPC metadata key, available to RPC handlers via context.Context.
This package only extracts and propagates whatever the "USER" metadata key says - it does not authenticate anything itself. It assumes something upstream of this server (a reverse proxy, an API gateway, mTLS termination, etc.) has already verified the caller and sets that metadata key to their login name before the request reaches here.
Index ¶
- Constants
- func FromContext(ctx context.Context) (login string, ok bool)
- func NewContext(ctx context.Context, login string) context.Context
- func StreamServerInterceptor(srv any, ss grpc.ServerStream, _ *grpc.StreamServerInfo, ...) error
- func UnaryServerInterceptor(ctx context.Context, req any, _ *grpc.UnaryServerInfo, ...) (any, error)
Constants ¶
const MetadataKey = "USER"
MetadataKey is the gRPC metadata key carrying the caller's login name. gRPC metadata keys are matched case-insensitively.
Variables ¶
This section is empty.
Functions ¶
func FromContext ¶
FromContext returns the authenticated login name attached to ctx by UnaryServerInterceptor/StreamServerInterceptor, and whether one was present. Handlers that require an authenticated caller should treat ok == false as unauthenticated.
func NewContext ¶
NewContext returns a copy of ctx with login attached, as if it had arrived via the "USER" gRPC metadata key. Intended for tests.
func StreamServerInterceptor ¶
func StreamServerInterceptor(srv any, ss grpc.ServerStream, _ *grpc.StreamServerInfo, handler grpc.StreamHandler) error
StreamServerInterceptor is the streaming-RPC equivalent of UnaryServerInterceptor.
func UnaryServerInterceptor ¶
func UnaryServerInterceptor(ctx context.Context, req any, _ *grpc.UnaryServerInfo, handler grpc.UnaryHandler) (any, error)
UnaryServerInterceptor extracts the "USER" gRPC metadata key from each incoming unary request and makes it available to the handler via FromContext.
Types ¶
This section is empty.
Source Files
¶
- grpcauth.go