Documentation
¶
Overview ¶
Package auth provides transport-neutral authentication flows. Package auth 提供与传输层无关的认证流程。
Index ¶
- Variables
- func ValidateStaticPasswordVisibleASCII(password string) error
- func VerifyCredential(expected, got string) bool
- type BearerAuthenticator
- type LoginAuthenticator
- type LoginAuthenticatorFunc
- type Service
- func (s *Service) Login(ctx context.Context, username, password string) (Tokens, bool, error)
- func (s *Service) Logout(ctx context.Context, refresh string) error
- func (s *Service) Refresh(ctx context.Context, refresh string) (Tokens, bool, error)
- func (s *Service) RevokeAllSessions(ctx context.Context, userID string) error
- func (s *Service) RevokeSession(ctx context.Context, userID, sessionID string) (bool, error)
- type TokenManager
- type Tokens
Constants ¶
This section is empty.
Variables ¶
var ( // ErrStaticPasswordUserIDEmpty reports an empty user ID for static password auth. // ErrStaticPasswordUserIDEmpty 表示固定密码认证使用了空 user ID。 ErrStaticPasswordUserIDEmpty = errors.New("static password user id is required") // ErrPasswordEmpty reports an empty password. // ErrPasswordEmpty 表示密码为空。 ErrPasswordEmpty = errors.New("password is empty") // ErrPasswordContainsSpace reports whitespace in a static password. // ErrPasswordContainsSpace 表示固定密码中包含空白字符。 ErrPasswordContainsSpace = errors.New("password must not contain whitespace") // ErrPasswordInvalidCharacter reports a character outside visible ASCII. // ErrPasswordInvalidCharacter 表示存在可见 ASCII 之外的字符。 ErrPasswordInvalidCharacter = errors.New("password must contain only ASCII letters, digits, and common symbols") )
var ( // ErrTokenManagerMissing reports a missing token/session dependency. // ErrTokenManagerMissing 表示缺少 token/session 依赖。 ErrTokenManagerMissing = errors.New("token manager is required") // ErrLoginAuthenticatorMissing reports a missing credential verifier. // ErrLoginAuthenticatorMissing 表示缺少凭据校验器。 ErrLoginAuthenticatorMissing = errors.New("login authenticator is required") // ErrUserIDEmpty reports a successful login that did not return a user ID. // ErrUserIDEmpty 表示登录成功但没有返回 user ID。 ErrUserIDEmpty = errors.New("authenticated user id is required") )
Functions ¶
func ValidateStaticPasswordVisibleASCII ¶
ValidateStaticPasswordVisibleASCII validates a static password using visible ASCII only. ValidateStaticPasswordVisibleASCII 使用仅可见 ASCII 规则校验静态密码。
func VerifyCredential ¶
VerifyCredential compares two credential strings using an exact byte match. VerifyCredential 使用精确字节匹配比较两段凭据。
Types ¶
type BearerAuthenticator ¶
type BearerAuthenticator interface {
AuthenticateBearer(ctx context.Context, header string) (authjwt.Claims, bool, int, string, string)
}
BearerAuthenticator describes bearer-token validation. BearerAuthenticator 描述 Bearer token 校验能力。
type LoginAuthenticator ¶
type LoginAuthenticator interface {
AuthenticateUserPassword(ctx context.Context, username, password string) (userID string, ok bool, err error)
}
LoginAuthenticator verifies login credentials and returns the authenticated user ID. Implementations may ignore username when the host application does not need it. LoginAuthenticator 负责校验登录凭据并返回认证成功后的用户 ID; 当宿主项目不需要用户名时,实现可以忽略 username。
func NewStaticPasswordAuthenticator ¶
func NewStaticPasswordAuthenticator(userID, expectedPassword string) (LoginAuthenticator, error)
NewStaticPasswordAuthenticator builds a LoginAuthenticator backed by one fixed password. NewStaticPasswordAuthenticator 构造一个使用固定密码的 LoginAuthenticator。
type LoginAuthenticatorFunc ¶
type LoginAuthenticatorFunc func(ctx context.Context, username, password string) (userID string, ok bool, err error)
LoginAuthenticatorFunc adapts a function into LoginAuthenticator. LoginAuthenticatorFunc 将函数适配为 LoginAuthenticator。
func (LoginAuthenticatorFunc) AuthenticateUserPassword ¶
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service runs authentication flows without binding them to HTTP or gRPC. Service 执行认证流程,但不绑定到 HTTP 或 gRPC。
func New ¶
func New(auth TokenManager, login LoginAuthenticator) (*Service, error)
New builds a Service from token/session and credential dependencies. New 使用 token/session 与凭据校验依赖构建 Service。
func (*Service) Login ¶
Login verifies credentials and issues a new token pair. Login 校验凭据并签发一组新 token。
func (*Service) Refresh ¶
Refresh rotates a refresh token and returns a new token pair. Refresh 轮换 refresh token 并返回一组新 token。
func (*Service) RevokeAllSessions ¶
RevokeAllSessions revokes all sessions for a user. RevokeAllSessions 吊销某用户的全部 session。
type TokenManager ¶
type TokenManager interface {
BearerAuthenticator
IssueSessionTokens(ctx context.Context, userID string) (access string, accessExp time.Time, refresh string, refreshExp time.Time, err error)
RotateRefreshTokens(ctx context.Context, oldRefresh string) (access string, accessExp time.Time, refresh string, refreshExp time.Time, ok bool, err error)
RevokeRefresh(ctx context.Context, refresh string) error
RevokeSession(ctx context.Context, userID, sessionID string) (bool, error)
RevokeAllSessions(ctx context.Context, userID string) error
}
TokenManager describes token and session operations required by auth flows. TokenManager 描述认证流程需要的 token 与 session 操作。
Directories
¶
| Path | Synopsis |
|---|---|
|
Package jwt provides JWT issuance and validation backed by user/session state.
|
Package jwt provides JWT issuance and validation backed by user/session state. |
|
Package session provides cookie helpers for auth flows.
|
Package session provides cookie helpers for auth flows. |
|
Package store defines auth session persistence used by auth/jwt.
|
Package store defines auth session persistence used by auth/jwt. |