auth

package
v0.4.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 22 Imported by: 0

Documentation

Overview

Package auth resolves Taiga credentials: env, session cache, refresh and secret sources.

Index

Constants

This section is empty.

Variables

View Source
var ErrReadOnly = errors.New("session store is read-only")

Functions

func JWTExpiry

func JWTExpiry(token string) (time.Time, error)

JWTExpiry reads the exp claim without verifying the signature (the server verifies it).

func RefreshToken

func RefreshToken(ctx context.Context, hc *http.Client, baseURL, refresh string) (string, string, error)

RefreshToken renews the session; Taiga may rotate the refresh token.

func SessionRef

func SessionRef(url, username string) string

Types

type Check

type Check struct {
	Name   string `json:"name"`
	Status string `json:"status"`
	Detail string `json:"detail,omitempty"`
	// Data is the structured form of Detail, for checks that have one (project).
	Data map[string]any `json:"data,omitempty"`
}

func Diagnose

func Diagnose(ctx context.Context, in DiagnoseInput) []Check

type CommandSecret

type CommandSecret struct{ Args []string }

func (CommandSecret) Name

func (CommandSecret) Name() string

func (CommandSecret) Password

func (c CommandSecret) Password(ctx context.Context) ([]byte, error)

type DiagnoseInput

type DiagnoseInput struct {
	Env          func(string) string
	Store        Store
	Ref          string
	Secret       SecretSource
	KeyringProbe func(context.Context) error
	StdinTTY     bool
	Now          func() time.Time
	// Project, when set, adds the project check at the end.
	Project *ProjectInput
}

type EnvPassword

type EnvPassword struct{ Env func(string) string }

func (EnvPassword) Configured

func (e EnvPassword) Configured() bool

func (EnvPassword) Name

func (EnvPassword) Name() string

func (EnvPassword) Password

func (e EnvPassword) Password(context.Context) ([]byte, error)

type FileSecret

type FileSecret struct{ Path string }

func (FileSecret) Name

func (FileSecret) Name() string

func (FileSecret) Password

func (f FileSecret) Password(context.Context) ([]byte, error)

func (FileSecret) Put

func (f FileSecret) Put(pw []byte) error

type FirstOf

type FirstOf []SecretSource

FirstOf tries each source in order.

func (FirstOf) Name

func (f FirstOf) Name() string

func (FirstOf) Password

func (f FirstOf) Password(ctx context.Context) ([]byte, error)

type Keyring

type Keyring struct{ Ref string }

Keyring stores the password in the Secret Service under the given reference. It never invokes Unlock or Prompt: an agent must not wait for desktop interaction.

func (Keyring) Available

func (Keyring) Available(parent context.Context) error

Available reports whether a Secret Service owns its name on the session bus.

func (Keyring) Delete

func (k Keyring) Delete(ctx context.Context) error

func (Keyring) Name

func (Keyring) Name() string

func (Keyring) Password

func (k Keyring) Password(ctx context.Context) ([]byte, error)

func (Keyring) Put

func (k Keyring) Put(ctx context.Context, value []byte) error

type LoginResult

type LoginResult struct {
	AuthToken string `json:"auth_token"`
	Refresh   string `json:"refresh"`
	UserID    int64  `json:"id"`
	Username  string `json:"username"`
}

func Login

func Login(ctx context.Context, hc *http.Client, baseURL, username string, password []byte) (LoginResult, error)

Login exchanges username/password for tokens.

type ProjectInput added in v0.3.0

type ProjectInput struct {
	Selected   string
	Source     string
	AuthFailed bool
	Load       func(context.Context) (map[string]any, error)
}

ProjectInput is the selected project and how to read it. Load reads the project object as Taiga answers GET projects/<id> or projects/by_slug; it is not called when the check is skipped.

type Resolver

type Resolver struct {
	URL, Username string
	Env           func(string) string
	Store         Store
	Secret        SecretSource
	HTTP          *http.Client
	Now           func() time.Time
	Warn          func(code, message string)
}

func (*Resolver) ForceRefresh

func (r *Resolver) ForceRefresh(ctx context.Context) (Session, error)

ForceRefresh renews the stored session regardless of its expiry (taiga auth refresh).

func (*Resolver) LoginWith

func (r *Resolver) LoginWith(ctx context.Context, password []byte) (Session, error)

LoginWith authenticates with a password and stores the new session.

func (*Resolver) Token

func (r *Resolver) Token(ctx context.Context) (taiga.Token, error)

type SecretSource

type SecretSource interface {
	Name() string
	Password(ctx context.Context) ([]byte, error)
}

type Session

type Session struct {
	URL       string    `json:"url"`
	Username  string    `json:"username"`
	AuthToken string    `json:"auth_token"`
	Refresh   string    `json:"refresh"`
	UserID    int64     `json:"user_id"`
	Expiry    time.Time `json:"exp"`
}

type Store

type Store struct{ Dir string }

func (Store) Delete

func (s Store) Delete(ref string) error

func (Store) Load

func (s Store) Load(ref string) (Session, error)

func (Store) Lock

func (s Store) Lock(ctx context.Context, ref string) (func(), error)

Lock takes an exclusive flock so concurrent processes do not refresh the same session twice.

func (Store) Path

func (s Store) Path(ref string) string

func (Store) Save

func (s Store) Save(ref string, sess Session) error

func (Store) Writable

func (s Store) Writable() bool

Writable reports whether the sessions directory accepts new files.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL