Versions in this module Expand all Collapse all v0 v0.2.4 Jun 18, 2026retracted Changes in this version + var ErrAPIKeyValidatorMissing = errors.New("api key validator is required") + var ErrAccessTokenValidatorMissing = errors.New("access token validator is required") + func LoginRateLimit(opts *RateLimitOptions) func(stdhttp.Handler) stdhttp.Handler + func OptionalBearer(auth AccessTokenValidator) (func(stdhttp.Handler) stdhttp.Handler, error) + func RequireAPIKey(auth APIKeyValidator, header string) (func(stdhttp.Handler) stdhttp.Handler, error) + func RequireBearer(auth AccessTokenValidator) (func(stdhttp.Handler) stdhttp.Handler, error) + func ValidateStaticPassword(password string) error + func VerifyCredential(expected, got string) bool + type APIKeyValidator interface + ValidateAPIKey func(ctx context.Context, key string) (bool, error) + type APIKeyValidatorFunc func(ctx context.Context, key string) (bool, error) + func (f APIKeyValidatorFunc) ValidateAPIKey(ctx context.Context, key string) (bool, error) + type AccessTokenValidator = auth.AccessTokenValidator + type Events struct + Login func(context.Context, LoginEvent) error + type Handler struct + func NewHandler(manager TokenManager, opts Options) (*Handler, error) + func (h *Handler) Register(r chi.Router) error + func (h *Handler) Routes() []routes.Route + type LoginAuthenticator = auth.LoginAuthenticator + func NewStaticPassword(userID, expectedPassword string) (LoginAuthenticator, error) + type LoginAuthenticatorFunc = auth.LoginAuthenticatorFunc + type LoginEvent struct + AccessExpiresAt time.Time + RefreshExpiresAt time.Time + SessionOnly bool + UserID string + Username string + type Options struct + BasePath string + CSRFCookieName string + CSRFCookiePath string + CSRFHeaderName string + CookieSameSite http.SameSite + Events Events + Logger *slog.Logger + LoginAuthenticator LoginAuthenticator + MaxBodyBytes int64 + RateLimit *RateLimitOptions + RefreshCookieName string + RefreshCookiePath string + TrustedProxies []netip.Prefix + func DefaultOptions() Options + type RateLimitOptions struct + Disabled bool + IPv4PrefixBits int + IPv6PrefixBits int + KeyFunc httprate.KeyFunc + Requests int + TrustedProxies []netip.Prefix + Window time.Duration + func DefaultRateLimitOptions() RateLimitOptions + type TokenManager = auth.TokenManager