Documentation
¶
Overview ¶
SPDX-License-Identifier: MPL-2.0
SPDX-License-Identifier: MPL-2.0
SPDX-License-Identifier: MPL-2.0 Package identity owns product-local accounts, password credentials and opaque server-side sessions. An authenticated principal conveys identity, never rights.
SPDX-License-Identifier: MPL-2.0
SPDX-License-Identifier: MPL-2.0
SPDX-License-Identifier: MPL-2.0
Index ¶
- Constants
- Variables
- func Migrate(ctx context.Context, dsn string) error
- type Account
- type Config
- type Module
- type PasswordPolicy
- type Service
- func (s *Service) Account(parent context.Context, actor achrix.Principal, id string) (Account, error)
- func (s *Service) Authenticate(parent context.Context, value string) (achrix.Principal, error)
- func (s *Service) ChangePassword(parent context.Context, value, current, next string) error
- func (s *Service) CreateAccount(parent context.Context, actor achrix.Principal, login, password string) (Account, error)
- func (s *Service) Login(parent context.Context, login, password, previousToken string) (Session, error)
- func (s *Service) Logout(parent context.Context, value string) error
- func (s *Service) LookupAccount(parent context.Context, actor achrix.Principal, login string) (Account, error)
- func (s *Service) RefreshCSRF(parent context.Context, value string) (string, error)
- func (s *Service) RevokeAll(parent context.Context, actor achrix.Principal, id string) error
- func (s *Service) Rotate(parent context.Context, value string) (Session, error)
- func (s *Service) SetEnabled(parent context.Context, actor achrix.Principal, id string, ...) error
- func (s *Service) SetPassword(parent context.Context, actor achrix.Principal, id string, ...) error
- func (s *Service) ValidateCSRF(parent context.Context, value, csrf string) (achrix.Principal, error)
- type Session
- type Web
Constants ¶
const ( AccountCreate = "achrix.identity.account.create" AccountRead = "achrix.identity.account.read" AccountLookup = "achrix.identity.account.lookup" CredentialSet = "achrix.identity.credential.set" AccountSetEnabled = "achrix.identity.account.set-enabled" SessionRevokeAll = "achrix.identity.session.revoke-all" Authentication = "achrix.identity.authenticate" PasswordChange = "achrix.identity.credential.change" )
const CookieName = "__Host-AChrix-Session"
const ModuleVersion = "0.2.0-development"
ModuleVersion is the unpublished source-line label, not the packaged build version. Deprecated: use Module.Descriptor().Version for component/update/recovery identity.
const PublicPrincipal achrix.Principal = "achrix.identity.public"
PublicPrincipal is only the principal for attempting credential/session authentication. A product must explicitly permit Authentication for this principal; it conveys no account identity or product permission.
Variables ¶
var ( ErrAuthentication = errors.New("authentication failed") ErrInvalid = errors.New("invalid identity input") ErrNotFound = errors.New("identity account not found") ErrConflict = errors.New("identity precondition conflict") ErrLimited = errors.New("identity admission limited") ErrConfiguration = errors.New("invalid identity configuration") )
Functions ¶
Types ¶
type Account ¶
Account exposes only the immutable opaque ID, login identifier and status. Login is a product-local authentication handle, never an email/profile contract.
type Config ¶
type Config struct {
Password PasswordPolicy
HashConcurrency int
SessionLifetime time.Duration
Now func() time.Time
}
Config is instance-owned. No environment/global configuration is read by Identity. Now controls security time decisions and must be trusted, monotonic in use and concurrency-safe. Zero fields use explicit bounded defaults.
type Module ¶
type Module struct {
// contains filtered or unexported fields
}
Module owns its pool and schema. Products explicitly compose it, install the immutable migration, and wire a Service after constructing their Application. Stop closes admission, cancels/drains owned DB work, then closes the pool.
func NewPostgres ¶
NewPostgres validates configuration without network/database side effects. Runtime DSN sources remain product-owned. Unix/loopback is the measured dev profile; a remote DSN requires certificate-verified TLS and earns no support claim merely by passing this defensive preflight.
func (*Module) Descriptor ¶
func (m *Module) Descriptor() achrix.Descriptor
func (*Module) FailureCount ¶
FailureCount is fixed-cardinality operational evidence, not durable Audit. Expected denial/authentication/invalid/limited traffic does not emit logs.
type PasswordPolicy ¶
PasswordPolicy uses KiB of memory. Defaults follow the reviewed OWASP Argon2id minimum; products must measure before changing the supported bounds.
func DefaultPasswordPolicy ¶
func DefaultPasswordPolicy() PasswordPolicy
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service routes authorized account management through the normal Application. Public login/session authentication is credential-based; it never grants any product capability. Products use Principal with their own authorized Service.
func NewService ¶
func (*Service) Account ¶
func (s *Service) Account(parent context.Context, actor achrix.Principal, id string) (Account, error)
Account is an authorized status/revision read for subsequent conditional management operations. It never returns credential or session material.
func (*Service) Authenticate ¶
func (*Service) ChangePassword ¶
ChangePassword reauthenticates the currently enabled session account, atomically replaces the expected credential and revokes all sessions. A new login is needed.
func (*Service) CreateAccount ¶
func (*Service) Login ¶
func (s *Service) Login(parent context.Context, login, password, previousToken string) (Session, error)
Login never adopts a client token. A supplied previous cookie is revoked in the same transaction as successful fresh issuance, including cross-account login. Unknown/disabled accounts undergo the bounded dummy hash; failures stay generic.
func (*Service) LookupAccount ¶
func (s *Service) LookupAccount(parent context.Context, actor achrix.Principal, login string) (Account, error)
LookupAccount reconciles one exact, validated login after an unknown create outcome. Its distinct permission targets that login, never an opaque ID or wildcard. Authentication and AccountRead do not implicitly grant this read. The result contains no credential/session material; no listing is provided.
func (*Service) RefreshCSRF ¶
RefreshCSRF serves a freshly generated synchronizer token through an authenticated same-origin response. Only its hash is persisted; adapters must prevent cross-origin reads and must not put it in URL/cookie/Web Storage.
func (*Service) SetEnabled ¶
func (*Service) SetPassword ¶
type Session ¶
type Session struct {
Principal achrix.Principal
Token string `json:"-"`
CSRF string `json:"-"`
ExpiresAt time.Time
}
Session secrets are returned only to the trusted adapter on issue/rotation. Default formatting deliberately redacts secret fields.
type Web ¶
type Web struct {
// contains filtered or unexported fields
}
Web owns a deliberately same-origin HTTPS browser boundary. It does not trust Forwarded/X-Forwarded-* or implement CORS. A product must terminate TLS here or compose a separately reviewed trusted proxy boundary before invoking this API.
func (*Web) AuthenticateRequest ¶
AuthenticateRequest validates cookie authentication and, for mutations, the synchronizer token and exact Origin/Referer. It returns no authority: the owning product Application operation must still authorize this principal.