Versions in this module Expand all Collapse all v0 v0.3.0 Oct 5, 2026 Changes in this version type Config + MaxConns int32 + MaxOperations int v0.2.0 Oct 3, 2026 Changes in this version + const AccountCreate + const AccountLookup + const AccountRead + const AccountSetEnabled + const Authentication + const CookieName + const CredentialSet + const ModuleVersion + const PasswordChange + const PublicPrincipal + const SessionRevokeAll + var ErrAuthentication = errors.New("authentication failed") + var ErrConfiguration = errors.New("invalid identity configuration") + var ErrConflict = errors.New("identity precondition conflict") + var ErrInvalid = errors.New("invalid identity input") + var ErrLimited = errors.New("identity admission limited") + var ErrNotFound = errors.New("identity account not found") + var ErrUnavailable = errors.New("identity unavailable") + func Migrate(ctx context.Context, dsn string) error + type Account struct + Enabled bool + ID string + Login string + Revision int64 + type Config struct + HashConcurrency int + Now func() time.Time + Password PasswordPolicy + SessionLifetime time.Duration + type Module struct + func NewPostgres(dsn string, config Config, logger *slog.Logger) (*Module, error) + func (m *Module) Descriptor() achrix.Descriptor + func (m *Module) FailureCount() uint64 + func (m *Module) Ready(parent context.Context) error + func (m *Module) Start(ctx context.Context) error + func (m *Module) Stop(ctx context.Context) error + type PasswordPolicy struct + Iterations uint32 + Memory uint32 + Parallelism uint8 + func DefaultPasswordPolicy() PasswordPolicy + type Service struct + func NewService(app *achrix.Application, module *Module, accountability *audit.Service) (*Service, error) + func (s *Service) Account(parent context.Context, actor achrix.Principal, id string) (Account, error) + func (s *Service) Authenticate(parent context.Context, value string) (achrix.Principal, error) + func (s *Service) ChangePassword(parent context.Context, value, current, next string) error + func (s *Service) CreateAccount(parent context.Context, actor achrix.Principal, login, password string) (Account, error) + func (s *Service) Login(parent context.Context, login, password, previousToken string) (Session, error) + func (s *Service) Logout(parent context.Context, value string) error + func (s *Service) LookupAccount(parent context.Context, actor achrix.Principal, login string) (Account, error) + func (s *Service) RefreshCSRF(parent context.Context, value string) (string, error) + func (s *Service) RevokeAll(parent context.Context, actor achrix.Principal, id string) error + func (s *Service) Rotate(parent context.Context, value string) (Session, error) + func (s *Service) SetEnabled(parent context.Context, actor achrix.Principal, id string, ...) error + func (s *Service) SetPassword(parent context.Context, actor achrix.Principal, id string, ...) error + func (s *Service) ValidateCSRF(parent context.Context, value, csrf string) (achrix.Principal, error) + type Session struct + CSRF string + ExpiresAt time.Time + Principal achrix.Principal + Token string + func (s Session) GoString() string + func (s Session) LogValue() slog.Value + func (s Session) String() string + type Web struct + func NewWeb(service *Service, origin string) (*Web, error) + func (w *Web) AuthenticateRequest(r *http.Request, mutation bool) (achrix.Principal, error) + func (w *Web) Handler() http.Handler