Documentation
¶
Overview ¶
Package jwt provides JWT issuance and validation backed by user/session state. Package jwt 提供基于用户/会话状态的 JWT 签发与校验。
Index ¶
- Constants
- Variables
- func WithClaims(ctx context.Context, claims Claims) context.Context
- type Claims
- type Manager
- func (m *Manager) AuthenticateBearer(ctx context.Context, header string) (Claims, bool, int, string, string)
- func (m *Manager) IsAuthorized(ctx context.Context, header string) bool
- func (m *Manager) IssueSessionTokens(ctx context.Context, userID string) (access string, accessExp time.Time, refresh string, refreshExp time.Time, ...)
- func (m *Manager) RevokeAccess(ctx context.Context, tokenStr string) error
- func (m *Manager) RevokeAllSessions(ctx context.Context, userID string) error
- func (m *Manager) RevokeRefresh(ctx context.Context, tokenStr string) error
- func (m *Manager) RevokeSession(ctx context.Context, userID, sessionID string) (bool, error)
- func (m *Manager) RotateRefreshTokens(ctx context.Context, oldRefresh string) (access string, accessExp time.Time, newRefresh string, newRefreshExp time.Time, ...)
- func (m *Manager) ValidateBearer(ctx context.Context, header string) (ok bool, status int, code, msg string)
- func (m *Manager) ValidateRefreshToken(ctx context.Context, tokenStr string) (Claims, bool, error)
- func (m *Manager) WithAccessTTL(ttl time.Duration) *Manager
- func (m *Manager) WithAudience(audience string) *Manager
- func (m *Manager) WithIssuer(issuer string) *Manager
- func (m *Manager) WithRefreshTTL(ttl time.Duration) *Manager
- type ManagerOptions
Constants ¶
const ( TokenKindAccess = "access" TokenKindRefresh = "refresh" )
Variables ¶
var ( )
Functions ¶
Types ¶
type Claims ¶
type Claims struct {
Kind string `json:"kind"`
SessionID string `json:"sid"`
Version int64 `json:"ver"`
jwt.RegisteredClaims
}
Claims carries the authenticated principal and session metadata. Claims 携带已认证主体与会话元数据。
type Manager ¶
type Manager struct {
// contains filtered or unexported fields
}
Manager issues and validates access/refresh JWTs backed by SessionStore. Manager 负责签发与校验由 SessionStore 支撑的 access/refresh JWT。
func New ¶
func New(signingKey string, store authstore.SessionStore) (*Manager, error)
New builds a Manager using DefaultManagerOptions. New 使用默认选项构建 Manager。 The session store must be provided explicitly. session store 必须显式提供。
func NewWithOptions ¶
func NewWithOptions(signingKey string, store authstore.SessionStore, opts ManagerOptions) (*Manager, error)
NewWithOptions builds a Manager with explicit options. NewWithOptions 使用显式选项构建 Manager。 The session store must be provided explicitly. session store 必须显式提供。
func (*Manager) AuthenticateBearer ¶
func (m *Manager) AuthenticateBearer(ctx context.Context, header string) (Claims, bool, int, string, string)
AuthenticateBearer validates a Bearer header and returns claims on success. AuthenticateBearer 校验 Bearer 头,成功时返回 claims。
func (*Manager) IsAuthorized ¶
IsAuthorized reports whether the Bearer header is valid for an active session. IsAuthorized 判断 Bearer 是否有效且属于活跃 session。
func (*Manager) IssueSessionTokens ¶
func (m *Manager) IssueSessionTokens(ctx context.Context, userID string) (access string, accessExp time.Time, refresh string, refreshExp time.Time, err error)
IssueSessionTokens issues a paired access/refresh token set for a user. IssueSessionTokens 为某用户签发 access/refresh token 对。
func (*Manager) RevokeAccess ¶
RevokeAccess revokes the session bound to an access token. RevokeAccess 吊销 access token 所绑定的 session。
func (*Manager) RevokeAllSessions ¶
RevokeAllSessions revokes every outstanding session for a user. RevokeAllSessions 吊销某用户的全部 session。
func (*Manager) RevokeRefresh ¶
RevokeRefresh revokes the session bound to a refresh token. RevokeRefresh 吊销 refresh token 所绑定的 session。
func (*Manager) RevokeSession ¶
RevokeSession revokes a single session owned by a user. RevokeSession 吊销某用户的单个 session。
func (*Manager) RotateRefreshTokens ¶
func (m *Manager) RotateRefreshTokens(ctx context.Context, oldRefresh string) (access string, accessExp time.Time, newRefresh string, newRefreshExp time.Time, ok bool, err error)
RotateRefreshTokens validates old refresh and issues a new access/refresh pair. RotateRefreshTokens 校验旧 refresh 并签发新的 access/refresh 对。
func (*Manager) ValidateBearer ¶
func (m *Manager) ValidateBearer(ctx context.Context, header string) (ok bool, status int, code, msg string)
ValidateBearer validates a Bearer header and returns API-friendly status/code. ValidateBearer 校验 Bearer 头并返回 API 友好的状态码与错误码。
func (*Manager) ValidateRefreshToken ¶
ValidateRefreshToken checks a refresh token and returns claims on success. ValidateRefreshToken 校验 refresh token,成功则返回 claims。
func (*Manager) WithAccessTTL ¶
WithAccessTTL overrides access token TTL. WithAccessTTL 覆盖 access token 的过期时间。
func (*Manager) WithAudience ¶
WithAudience overrides the JWT audience claim. WithAudience 覆盖 JWT 的 audience 声明。
func (*Manager) WithIssuer ¶
WithIssuer overrides the JWT issuer claim. WithIssuer 覆盖 JWT 的 issuer 声明。
type ManagerOptions ¶
type ManagerOptions struct {
Issuer string
Audience string
AccessTTL time.Duration
RefreshTTL time.Duration
}
ManagerOptions configures Manager defaults at construction. ManagerOptions 用于构造时配置默认行为。
func DefaultManagerOptions ¶
func DefaultManagerOptions() ManagerOptions
DefaultManagerOptions returns safe generic defaults. DefaultManagerOptions 返回通用安全默认值。