auth

package
v1.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 8, 2026 License: Apache-2.0 Imports: 14 Imported by: 0

Documentation

Overview

Package auth hashes passwords, enforces their policy and throttles login attempts.

Index

Constants

View Source
const (
	// MinPasswordLength and MaxPasswordLength bound what is accepted: the lower
	// bound against guessing, the upper against a request that makes the
	// server hash megabytes.
	MinPasswordLength = 12
	MaxPasswordLength = 128
)

Variables

View Source
var ErrBusy = errors.New("too many passwords are being checked at once")

ErrBusy is returned when too many passwords are being hashed at once.

Functions

func BearerToken added in v1.1.0

func BearerToken(r *http.Request) (string, bool)

BearerToken returns the token of an "Authorization: Bearer" header.

func HashPassword

func HashPassword(password string) (string, error)

HashPassword returns an encoded argon2id hash with a random salt.

func PeerHost added in v1.1.0

func PeerHost(r *http.Request) string

PeerHost is the address of the connection, not of a client behind a proxy.

func SpendHashingTime added in v1.1.0

func SpendHashingTime(password string)

SpendHashingTime does the work of a verification that cannot succeed, so that answering for an unknown user takes as long as for a known one.

func ValidatePassword

func ValidatePassword(username, password string) error

ValidatePassword reports why a password is refused.

func VerifyPassword

func VerifyPassword(password, encoded string) (bool, error)

VerifyPassword compares a password with an encoded hash in constant time. An error means the hash itself is unusable, not that the password is wrong.

Types

type Limiter added in v1.1.0

type Limiter struct {
	// contains filtered or unexported fields
}

Limiter refuses a key once it failed too many times within a window.

func NewLimiter added in v1.1.0

func NewLimiter(max int, window time.Duration) *Limiter

NewLimiter allows max failures per key in each window.

func (*Limiter) Blocked added in v1.1.0

func (l *Limiter) Blocked(key string) bool

Blocked reports whether the key used up its failures.

func (*Limiter) Fail added in v1.1.0

func (l *Limiter) Fail(key string)

Fail records a failure of the key.

func (*Limiter) Reset added in v1.1.0

func (l *Limiter) Reset(key string)

Reset forgets the failures of the key, after a success.

type Proxies added in v1.1.0

type Proxies struct {
	// contains filtered or unexported fields
}

Proxies are the reverse proxies trusted to say who the client is. Behind a proxy every request shares its address, so the failure limits would lock everyone out together. The zero value trusts none.

func ParseProxies added in v1.1.0

func ParseProxies(values []string) (Proxies, error)

ParseProxies reads addresses or CIDR ranges of proxies. A range that holds every address is refused: it would trust every sender.

func (Proxies) ClientIP added in v1.1.0

func (p Proxies) ClientIP(r *http.Request) string

ClientIP is the address a request is counted under: the peer, or when that is a trusted proxy the first address of X-Forwarded-For, from the right, that is not one itself.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL