Documentation
¶
Overview ¶
Package auth0 provides a verifier for Auth0 Management API tokens. It uses the Auth0 Management API GET /api/v2/ endpoint with Bearer auth to check token validity. The Auth0 Management API is tenant-scoped, so the target host must be explicitly trusted by the operator. Repository content and unverified JWT claims never select the request destination.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Verifier ¶
type Verifier struct {
// contains filtered or unexported fields
}
Verifier checks whether an Auth0 Management API token is active by calling the Auth0 Management API. It NEVER logs or persists raw token values.
func NewForTrustedInstance ¶ added in v1.8.0
NewForTrustedInstance constructs an Auth0 verifier for an origin explicitly supplied by the operator. It must never receive an issuer decoded from an unverified token or a URL extracted from scanned repository content.
func (*Verifier) Verify ¶
func (v *Verifier) Verify(ctx context.Context, raw detector.RawFinding) finding.VerificationResult
Verify checks if the detected Auth0 Management API token is valid/active.
Auth0 Management API tokens are tenant-scoped. Without an operator-trusted tenant origin the result is indeterminate and no request is sent.