Documentation
¶
Overview ¶
Package webapi is the JSON API the web UI talks to: accounts, sessions and the data of the central.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ParseOrigins ¶
ParseOrigins checks the allowed web origins: each is scheme://host[:port], with no path and no wildcard, so that what a browser may do is always named.
Types ¶
type Config ¶
type Config struct {
// AllowedOrigins are the web origins that may call the API from a browser,
// as scheme://host[:port]. Empty: no browser origin is allowed.
AllowedOrigins []string
// SessionTTL is how long a login lasts; zero means 12 hours.
SessionTTL time.Duration
// Sender delivers the test notifications of a channel; nil posts to its
// webhook.
Sender alert.Sender
// HSTS tells browsers to use HTTPS only; set it when the API serves TLS.
HSTS bool
// Policy is where a test notification may not connect; nil means the
// default ranges, a pointer to the zero value nowhere.
Policy *probe.Policy
// TrustedProxies are the reverse proxies trusted to say who the client is.
// Without them a failed login is counted against the address of the proxy,
// and every user would be locked out together.
TrustedProxies auth.Proxies
}
Config is what the UI API needs besides the store.
type Server ¶
type Server struct {
// contains filtered or unexported fields
}
Server is the JSON API of the web UI. It authenticates with bearer tokens: there are no cookies, so there is nothing for another site to forge.
Click to show internal directories.
Click to hide internal directories.