runtimecred

package
v1.0.63 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 3, 2026 License: Apache-2.0 Imports: 5 Imported by: 0

Documentation

Overview

Package runtimecred provides an in-memory credential broker for event bus processes. Runtime credentials are never persisted by this package.

Index

Constants

View Source
const DefaultMaxTokenBytes = 64 << 10

DefaultMaxTokenBytes bounds credentials accepted over the local IPC channel. Access tokens are normally only a few KiB; the larger limit leaves ample room for future token formats while avoiding accidental large secret allocations.

Variables

View Source
var (
	ErrEmptyToken              = errors.New("runtime credential: token is empty")
	ErrTokenTooLarge           = errors.New("runtime credential: token exceeds size limit")
	ErrCredentialUnavailable   = errors.New("runtime credential: no credential resolver is available")
	ErrLocalRefreshUnavailable = errors.New("runtime credential: no local refresh callback is available")
	ErrRuntimeTokenRejected    = &RuntimeTokenRejectedError{}
)

Functions

This section is empty.

Types

type Broker

type Broker struct {
	// contains filtered or unexported fields
}

Broker holds at most one runtime credential. All state, including the credential generation, is process-local and concurrency-safe.

func New

func New(cfg Config) *Broker

func (*Broker) Activate

func (b *Broker) Activate(expectedGeneration uint64) (uint64, error)

Activate publishes a pending first runtime credential after the bus has registered the initiating consumer. It is an idempotent generation-checked no-op for brokers that do not require activation.

func (*Broker) ClassifyRejectedAfterRetry

func (b *Broker) ClassifyRejectedAfterRetry(rejectedToken string) (superseded bool, err error)

ClassifyRejectedAfterRetry is called when a token returned by RefreshRejected was itself rejected. When a still newer runtime credential is already installed, superseded is true so the source may reconnect and resolve that generation without a second in-attempt retry. When the rejected token is still current, the fixed typed rejection is returned. With no runtime credential installed it preserves local OAuth behavior by returning (false, nil).

func (*Broker) Generation

func (b *Broker) Generation() uint64

Generation returns the current runtime credential generation. Generation 0 means that no runtime credential has been installed yet.

func (*Broker) RefreshRejected

func (b *Broker) RefreshRejected(ctx context.Context, rejectedToken string) (string, error)

RefreshRejected returns a newer runtime token if one was installed after rejectedToken was used. If the installed runtime token itself was rejected, it returns RuntimeTokenRejectedError and never invokes local OAuth refresh.

func (*Broker) Resolve

func (b *Broker) Resolve(ctx context.Context) (string, error)

Resolve returns the runtime credential when installed. In RequireSeed mode it waits until Update installs one; otherwise it preserves the existing local resolver behavior until a runtime credential arrives.

func (*Broker) Update

func (b *Broker) Update(expectedGeneration uint64, token string) (uint64, error)

Update atomically installs token when expectedGeneration matches the current generation. Reinstalling the same token is idempotent, including when another concurrent writer already installed it.

type Config

type Config struct {
	LocalResolve ResolveFunc
	LocalRefresh RefreshFunc
	RequireSeed  bool
	// RequireActivation keeps the first installed runtime credential pending
	// until Activate is called. Detached buses use it to register the consumer
	// before ticket acquisition can emit or fail.
	RequireActivation bool
	MaxTokenBytes     int
}

type GenerationConflictError

type GenerationConflictError struct {
	Expected uint64
	Actual   uint64
}

GenerationConflictError reports a failed compare-and-swap update.

func (*GenerationConflictError) Error

func (e *GenerationConflictError) Error() string

type RefreshFunc

type RefreshFunc func(context.Context, string) (string, error)

RefreshFunc refreshes a rejected local OAuth credential. It is never called after a runtime credential has been installed.

type ResolveFunc

type ResolveFunc func(context.Context) (string, error)

ResolveFunc resolves the existing local OAuth credential when no runtime credential has been installed.

type RuntimeTokenRejectedError

type RuntimeTokenRejectedError struct{}

RuntimeTokenRejectedError means the currently installed runtime token was rejected and no newer runtime token is available. It deliberately carries no token or server response data so it is safe to surface to users and logs.

func (*RuntimeTokenRejectedError) Error

func (*RuntimeTokenRejectedError) Is

func (*RuntimeTokenRejectedError) Is(target error) bool

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL