auth

package
v0.1.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Apr 18, 2026 License: MIT Imports: 7 Imported by: 0

Documentation

Overview

Package auth provides transport-neutral authentication flows. Package auth 提供与传输层无关的认证流程。

Index

Constants

This section is empty.

Variables

View Source
var (
	// ErrStaticPasswordUserIDEmpty reports an empty user ID for static password auth.
	// ErrStaticPasswordUserIDEmpty 表示固定密码认证使用了空 user ID。
	ErrStaticPasswordUserIDEmpty = errors.New("static password user id is required")
	// ErrPasswordEmpty reports an empty password.
	// ErrPasswordEmpty 表示密码为空。
	ErrPasswordEmpty = errors.New("password is empty")
	// ErrPasswordContainsSpace reports whitespace in a static password.
	// ErrPasswordContainsSpace 表示固定密码中包含空白字符。
	ErrPasswordContainsSpace = errors.New("password must not contain whitespace")
	// ErrPasswordInvalidCharacter reports a character outside visible ASCII.
	// ErrPasswordInvalidCharacter 表示存在可见 ASCII 之外的字符。
	ErrPasswordInvalidCharacter = errors.New("password must contain only ASCII letters, digits, and common symbols")
)
View Source
var (
	// ErrTokenManagerMissing reports a missing token/session dependency.
	// ErrTokenManagerMissing 表示缺少 token/session 依赖。
	ErrTokenManagerMissing = errors.New("token manager is required")
	// ErrLoginAuthenticatorMissing reports a missing credential verifier.
	// ErrLoginAuthenticatorMissing 表示缺少凭据校验器。
	ErrLoginAuthenticatorMissing = errors.New("login authenticator is required")
	// ErrUserIDEmpty reports a successful login that did not return a user ID.
	// ErrUserIDEmpty 表示登录成功但没有返回 user ID。
	ErrUserIDEmpty = errors.New("authenticated user id is required")
)

Functions

func ValidateStaticPasswordVisibleASCII

func ValidateStaticPasswordVisibleASCII(password string) error

ValidateStaticPasswordVisibleASCII validates a static password using visible ASCII only. ValidateStaticPasswordVisibleASCII 使用仅可见 ASCII 规则校验静态密码。

func VerifyCredential

func VerifyCredential(expected, got string) bool

VerifyCredential compares two credential strings using an exact byte match. VerifyCredential 使用精确字节匹配比较两段凭据。

Types

type BearerAuthenticator

type BearerAuthenticator interface {
	AuthenticateBearer(ctx context.Context, header string) (authjwt.Claims, bool, int, string, string)
}

BearerAuthenticator describes bearer-token validation. BearerAuthenticator 描述 Bearer token 校验能力。

type LoginAuthenticator

type LoginAuthenticator interface {
	AuthenticateUserPassword(ctx context.Context, username, password string) (userID string, ok bool, err error)
}

LoginAuthenticator verifies login credentials and returns the authenticated user ID. Implementations may ignore username when the host application does not need it. LoginAuthenticator 负责校验登录凭据并返回认证成功后的用户 ID; 当宿主项目不需要用户名时,实现可以忽略 username。

func NewStaticPasswordAuthenticator

func NewStaticPasswordAuthenticator(userID, expectedPassword string) (LoginAuthenticator, error)

NewStaticPasswordAuthenticator builds a LoginAuthenticator backed by one fixed password. NewStaticPasswordAuthenticator 构造一个使用固定密码的 LoginAuthenticator。

type LoginAuthenticatorFunc

type LoginAuthenticatorFunc func(ctx context.Context, username, password string) (userID string, ok bool, err error)

LoginAuthenticatorFunc adapts a function into LoginAuthenticator. LoginAuthenticatorFunc 将函数适配为 LoginAuthenticator。

func (LoginAuthenticatorFunc) AuthenticateUserPassword

func (f LoginAuthenticatorFunc) AuthenticateUserPassword(ctx context.Context, username, password string) (userID string, ok bool, err error)

type Service

type Service struct {
	// contains filtered or unexported fields
}

Service runs authentication flows without binding them to HTTP or gRPC. Service 执行认证流程,但不绑定到 HTTP 或 gRPC。

func New

func New(auth TokenManager, login LoginAuthenticator) (*Service, error)

New builds a Service from token/session and credential dependencies. New 使用 token/session 与凭据校验依赖构建 Service。

func (*Service) Login

func (s *Service) Login(ctx context.Context, username, password string) (Tokens, bool, error)

Login verifies credentials and issues a new token pair. Login 校验凭据并签发一组新 token。

func (*Service) Logout

func (s *Service) Logout(ctx context.Context, refresh string) error

Logout revokes a refresh token. Logout 吊销 refresh token。

func (*Service) Refresh

func (s *Service) Refresh(ctx context.Context, refresh string) (Tokens, bool, error)

Refresh rotates a refresh token and returns a new token pair. Refresh 轮换 refresh token 并返回一组新 token。

func (*Service) RevokeAllSessions

func (s *Service) RevokeAllSessions(ctx context.Context, userID string) error

RevokeAllSessions revokes all sessions for a user. RevokeAllSessions 吊销某用户的全部 session。

func (*Service) RevokeSession

func (s *Service) RevokeSession(ctx context.Context, userID, sessionID string) (bool, error)

RevokeSession revokes one session for a user. RevokeSession 吊销某用户的一个 session。

type TokenManager

type TokenManager interface {
	BearerAuthenticator
	IssueSessionTokens(ctx context.Context, userID string) (access string, accessExp time.Time, refresh string, refreshExp time.Time, err error)
	RotateRefreshTokens(ctx context.Context, oldRefresh string) (access string, accessExp time.Time, refresh string, refreshExp time.Time, ok bool, err error)
	RevokeRefresh(ctx context.Context, refresh string) error
	RevokeSession(ctx context.Context, userID, sessionID string) (bool, error)
	RevokeAllSessions(ctx context.Context, userID string) error
}

TokenManager describes token and session operations required by auth flows. TokenManager 描述认证流程需要的 token 与 session 操作。

type Tokens

type Tokens struct {
	Access           string
	AccessExpiresAt  time.Time
	Refresh          string
	RefreshExpiresAt time.Time
}

Tokens contains an access/refresh token pair with their expirations. Tokens 包含一组 access/refresh token 及其过期时间。

Directories

Path Synopsis
Package jwt provides JWT issuance and validation backed by user/session state.
Package jwt provides JWT issuance and validation backed by user/session state.
Package session provides cookie helpers for auth flows.
Package session provides cookie helpers for auth flows.
Package store defines auth session persistence used by auth/jwt.
Package store defines auth session persistence used by auth/jwt.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL