middleware

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Mar 11, 2026 License: AGPL-3.0 Imports: 5 Imported by: 0

Documentation

Overview

Package middleware provides HTTP middleware for the orchestrator service.

This package contains middleware for authentication, authorization, and request processing. It integrates with the extensions package to support enterprise features.

Authentication Flow

The auth middleware extracts a bearer token from the Authorization header, validates it using the configured AuthProvider, and stores the resulting AuthInfo in the Gin context for downstream handlers.

Request
   │
   ▼
AuthMiddleware
   │
   ├─► Extract token from "Authorization: Bearer <token>"
   │
   ├─► provider.Validate(ctx, token)
   │
   └─► Store AuthInfo in context
           │
           ▼
       Handler (retrieves via GetAuthInfo)

Open Source Behavior

When using NopAuthProvider (default), all requests are authenticated as "local-user" with admin privileges. This enables the CLI to function without any authentication infrastructure.

Enterprise Behavior

Enterprise implementations validate tokens against identity providers (Okta, Auth0, Azure AD) and return real user identity information.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func AuthMiddleware

func AuthMiddleware(provider extensions.AuthProvider) gin.HandlerFunc

AuthMiddleware creates a Gin middleware that authenticates requests.

Description

Extracts the bearer token from the Authorization header, validates it using the provided AuthProvider, and stores the resulting AuthInfo in the context for downstream handlers.

Token Extraction

The middleware expects tokens in the Authorization header:

Authorization: Bearer <token>

If the header is missing or malformed, the token passed to Validate will be empty string. NopAuthProvider accepts this and returns local-user.

Inputs

  • provider: AuthProvider to validate tokens. Must not be nil.

Outputs

  • gin.HandlerFunc: Middleware function ready for use with Gin

Examples

// Apply to route group
v1 := router.Group("/v1")
v1.Use(middleware.AuthMiddleware(opts.AuthProvider))

// Apply to single route
router.GET("/protected", middleware.AuthMiddleware(provider), handler)

Limitations

  • Only supports Bearer token authentication
  • Does not support multiple authentication schemes
  • Does not cache validation results (validates every request)

Assumptions

  • Provider is non-nil and ready for use
  • Provider.Validate is safe for concurrent calls
  • ErrUnauthorized is used for auth failures (other errors treated as failures too)

Thread Safety

Thread-safe. The returned middleware can be used concurrently.

func GetAuthInfo

func GetAuthInfo(c *gin.Context) *extensions.AuthInfo

GetAuthInfo retrieves the authenticated user info from the Gin context.

Description

Called by handlers to access the authenticated user's identity. Returns nil if no AuthInfo is present (request not authenticated).

Inputs

  • c: Gin context. Must not be nil.

Outputs

  • *extensions.AuthInfo: User info, or nil if not authenticated

Examples

func (h *handler) HandleRequest(c *gin.Context) {
    authInfo := middleware.GetAuthInfo(c)
    if authInfo == nil {
        c.JSON(401, gin.H{"error": "not authenticated"})
        return
    }
    // Use authInfo.UserID, authInfo.Roles, etc.
}

Limitations

  • Returns nil if SetAuthInfo was not called or called with nil
  • Returns nil if stored value is wrong type (defensive)

Assumptions

  • Gin context is valid and not nil
  • AuthMiddleware has already processed the request

Thread Safety

Safe to call concurrently (Gin context is request-scoped).

func SetAuthInfo

func SetAuthInfo(c *gin.Context, info *extensions.AuthInfo)

SetAuthInfo stores the authenticated user info in the Gin context.

Description

Called by AuthMiddleware after successful authentication. The stored AuthInfo can be retrieved by handlers via GetAuthInfo.

Inputs

  • c: Gin context. Must not be nil.
  • info: Authenticated user information. May be nil.

Outputs

None.

Examples

// In middleware after successful auth
authInfo, _ := provider.Validate(ctx, token)
SetAuthInfo(c, authInfo)

Limitations

  • Only valid for current request (context is request-scoped)
  • Overwrites any previously set auth info

Assumptions

  • Gin context is valid and not nil
  • Called within request lifecycle

Thread Safety

Safe to call concurrently (Gin context is request-scoped).

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL