Documentation
¶
Overview ¶
Package runtimecred provides an in-memory credential broker for event bus processes. Runtime credentials are never persisted by this package.
Index ¶
- Constants
- Variables
- type Broker
- func (b *Broker) Activate(expectedGeneration uint64) (uint64, error)
- func (b *Broker) ClassifyRejectedAfterRetry(rejectedToken string) (superseded bool, err error)
- func (b *Broker) Generation() uint64
- func (b *Broker) RefreshRejected(ctx context.Context, rejectedToken string) (string, error)
- func (b *Broker) Resolve(ctx context.Context) (string, error)
- func (b *Broker) Update(expectedGeneration uint64, token string) (uint64, error)
- type Config
- type GenerationConflictError
- type RefreshFunc
- type ResolveFunc
- type RuntimeTokenRejectedError
Constants ¶
const DefaultMaxTokenBytes = 64 << 10
DefaultMaxTokenBytes bounds credentials accepted over the local IPC channel. Access tokens are normally only a few KiB; the larger limit leaves ample room for future token formats while avoiding accidental large secret allocations.
Variables ¶
var ( ErrEmptyToken = errors.New("runtime credential: token is empty") ErrTokenTooLarge = errors.New("runtime credential: token exceeds size limit") ErrRuntimeTokenRejected = &RuntimeTokenRejectedError{} )
Functions ¶
This section is empty.
Types ¶
type Broker ¶
type Broker struct {
// contains filtered or unexported fields
}
Broker holds at most one runtime credential. All state, including the credential generation, is process-local and concurrency-safe.
func (*Broker) Activate ¶
Activate publishes a pending first runtime credential after the bus has registered the initiating consumer. It is an idempotent generation-checked no-op for brokers that do not require activation.
func (*Broker) ClassifyRejectedAfterRetry ¶
ClassifyRejectedAfterRetry is called when a token returned by RefreshRejected was itself rejected. When a still newer runtime credential is already installed, superseded is true so the source may reconnect and resolve that generation without a second in-attempt retry. When the rejected token is still current, the fixed typed rejection is returned. With no runtime credential installed it preserves local OAuth behavior by returning (false, nil).
func (*Broker) Generation ¶
Generation returns the current runtime credential generation. Generation 0 means that no runtime credential has been installed yet.
func (*Broker) RefreshRejected ¶
RefreshRejected returns a newer runtime token if one was installed after rejectedToken was used. If the installed runtime token itself was rejected, it returns RuntimeTokenRejectedError and never invokes local OAuth refresh.
type Config ¶
type Config struct {
LocalResolve ResolveFunc
LocalRefresh RefreshFunc
RequireSeed bool
// RequireActivation keeps the first installed runtime credential pending
// until Activate is called. Detached buses use it to register the consumer
// before ticket acquisition can emit or fail.
RequireActivation bool
MaxTokenBytes int
}
type GenerationConflictError ¶
GenerationConflictError reports a failed compare-and-swap update.
func (*GenerationConflictError) Error ¶
func (e *GenerationConflictError) Error() string
type RefreshFunc ¶
RefreshFunc refreshes a rejected local OAuth credential. It is never called after a runtime credential has been installed.
type ResolveFunc ¶
ResolveFunc resolves the existing local OAuth credential when no runtime credential has been installed.
type RuntimeTokenRejectedError ¶
type RuntimeTokenRejectedError struct{}
RuntimeTokenRejectedError means the currently installed runtime token was rejected and no newer runtime token is available. It deliberately carries no token or server response data so it is safe to surface to users and logs.
func (*RuntimeTokenRejectedError) Error ¶
func (*RuntimeTokenRejectedError) Error() string
func (*RuntimeTokenRejectedError) Is ¶
func (*RuntimeTokenRejectedError) Is(target error) bool