Documentation
¶
Overview ¶
Package gitlab provides a verifier for GitLab personal access tokens. It uses the GitLab API GET /api/v4/user endpoint to check token validity.
Index ¶
- type Verifier
- func (v *Verifier) Type() string
- func (*Verifier) VerificationRequestBudget() int
- func (v *Verifier) Verify(ctx context.Context, raw detector.RawFinding) finding.VerificationResult
- func (v *Verifier) VerifyWithRequestGate(ctx context.Context, raw detector.RawFinding, gate verifier.RequestGate) finding.VerificationResult
- func (*Verifier) WithTrustedInstance(instanceURL string) (verifier.Verifier, error)
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Verifier ¶
type Verifier struct {
// contains filtered or unexported fields
}
Verifier checks whether a GitLab personal access token is active by calling the GitLab API. It NEVER logs or persists raw token values.
func NewForTrustedInstance ¶ added in v1.8.0
NewForTrustedInstance constructs a GitLab verifier for an API origin explicitly supplied by the operator. Finding metadata and scanned URLs are deliberately never accepted as routing authority.
func (*Verifier) VerificationRequestBudget ¶ added in v1.8.0
VerificationRequestBudget covers the identity probe, the optional PAT self-metadata probe, and at most one bounded 429 retry for each GET.
func (*Verifier) Verify ¶
func (v *Verifier) Verify(ctx context.Context, raw detector.RawFinding) finding.VerificationResult
Verify checks if the detected GitLab personal access token is valid/active. Raw contains the token value. Only personal access tokens (`glpat-`) can use the read-only `/user` probe. Other GitLab credential families have different authentication contracts and remain unverified.
func (*Verifier) VerifyWithRequestGate ¶ added in v1.8.0
func (v *Verifier) VerifyWithRequestGate( ctx context.Context, raw detector.RawFinding, gate verifier.RequestGate, ) finding.VerificationResult
VerifyWithRequestGate admits every actual identity/metadata request (and any bounded GET retry) at its send point.