config

package
v0.6.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 4, 2026 License: MIT Imports: 4 Imported by: 0

Documentation

Overview

Package config parses the authio.yaml desired-state file consumed by `authio check` and `authio apply` (config-as-code, Phase 3 of the 2026-09 platform program).

One file describes one project's declarative surface:

version: 1
prune: false                # delete live resources missing from this file
redirect_uris:
  - uri: https://app.example.com/api/auth/callback
    kind: oauth_callback    # oauth_callback | magic_link_redirect | custom_app_callback
webhooks:
  - url: https://app.example.com/api/authio/webhook
    events: ["session.revoked", "user.created"]   # default ["*"]
    description: main receiver
risk_policy:
  threshold_step_up: 50
  threshold_block: 90
  signal_weights: { new_device: 25 }
  enabled_signals: [new_device]
sso_connections:
  - organization_id: org_...
    external_id: acme-okta  # stable identity for diffing (required)
    provider: saml
    display_name: Acme Okta
    saml: { metadata_url: ..., sso_url: ..., certificate: ... }

Identity keys for diffing: redirect_uris by uri, webhooks by url, sso_connections by organization_id + external_id, risk_policy is a singleton. Webhook secrets are write-only: they are returned exactly once at create/replace time and never stored in the file.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type File

type File struct {
	Version        int             `yaml:"version"`
	Prune          bool            `yaml:"prune"`
	RedirectURIs   []RedirectURI   `yaml:"redirect_uris"`
	Webhooks       []Webhook       `yaml:"webhooks"`
	RiskPolicy     *RiskPolicy     `yaml:"risk_policy"`
	SSOConnections []SSOConnection `yaml:"sso_connections"`
	// Clearance is the agent-authorization block (profiles, agents,
	// providers). It is captured verbatim and validated server-side by
	// the Clearance engine via POST /v1/clearance/import (the workspace
	// API-key surface `authio apply`/`check` use — not
	// /v1/session/clearance/import, which needs a dashboard session JWT)
	// — the CLI does not duplicate that schema. `providers` inside it is
	// read locally by `authio clearance serve`.
	Clearance yaml.Node `yaml:"clearance"`
}

File is the root of authio.yaml.

func Load

func Load(path string) (*File, error)

Load reads and validates an authio.yaml file. Validation is shape-level only — URL reachability, redirect-URI policy, and signal names are the management API's call, surfaced per-action at apply.

func (*File) ClearanceYAML

func (f *File) ClearanceYAML() (string, error)

ClearanceYAML re-serialises the clearance block as a standalone document (`clearance: …`) for the import route.

func (*File) Empty

func (f *File) Empty() bool

Empty reports whether the file declares nothing to manage — almost always a mistake (wrong file), so the commands refuse it explicitly.

func (*File) HasClearance

func (f *File) HasClearance() bool

HasClearance reports whether the file declares a clearance: block.

type RedirectURI

type RedirectURI struct {
	URI  string `yaml:"uri"`
	Kind string `yaml:"kind"` // default oauth_callback
}

RedirectURI declares one allowed redirect URI. Identity: URI.

type RiskPolicy

type RiskPolicy struct {
	ThresholdStepUp int            `yaml:"threshold_step_up"`
	ThresholdBlock  int            `yaml:"threshold_block"`
	SignalWeights   map[string]int `yaml:"signal_weights"`
	EnabledSignals  []string       `yaml:"enabled_signals"`
}

RiskPolicy declares the project's risk-engine policy (singleton, PUT /v1/risk/policy upsert).

type SSOConnection

type SSOConnection struct {
	OrganizationID  string            `yaml:"organization_id"`
	ExternalID      string            `yaml:"external_id"`
	Provider        string            `yaml:"provider"` // saml | oidc
	DisplayName     string            `yaml:"display_name"`
	IdPProvider     string            `yaml:"idp_provider"`
	SAML            map[string]any    `yaml:"saml"`
	OIDC            map[string]any    `yaml:"oidc"`
	AttributeMap    map[string]string `yaml:"attribute_map"`
	JITProvisioning *bool             `yaml:"jit_provisioning"`
	DefaultRole     string            `yaml:"default_role"`
	Status          string            `yaml:"status"`
}

SSOConnection declares one org SSO connection. Identity: organization_id + external_id (the management API's idempotent-create key). The saml/oidc config blocks are write-only from the API's list surface, so they are sent on create but cannot be drift-detected — changing IdP config on an existing connection is a dashboard job.

type Webhook

type Webhook struct {
	URL            string   `yaml:"url"`
	Events         []string `yaml:"events"` // default ["*"]
	Description    string   `yaml:"description"`
	OrganizationID string   `yaml:"organization_id"`
}

Webhook declares one webhook endpoint. Identity: URL. The management API has no update endpoint — event/description drift is resolved by replace (revoke + recreate), which rotates the secret.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL