authlab

package
v1.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: Apache-2.0 Imports: 14 Imported by: 0

Documentation

Overview

Package authlab is AuthLab, a small OAuth 2.0 and OpenID Connect token service: password, refresh-token and client-credentials grants, userinfo, introspection and revocation, with Ed25519-signed JWT access tokens. It is the reference app for the identity pack.

Planted bottlenecks (see README.md), each switched off by a fix flag:

  • lock: password hashes are checked while holding the store's single lock, so logins run one at a time and refreshes wait behind them (fix "lock" hashes outside the lock).
  • index: refresh tokens live in a list that is never pruned and is scanned with a constant-time compare on every refresh and revocation, so each refresh costs more the more tokens were ever issued (fix "index" uses a map and drops expired tokens).

Index

Constants

View Source
const (
	Users    = 1000
	Password = "authlab-pass" //nolint:gosec // demo password, published in the README
)

Users is how many accounts AuthLab seeds: user0001@authlab.test to user1000@authlab.test, all with the password Password.

Variables

This section is empty.

Functions

func New

func New(cfg labkit.Config) http.Handler

New returns AuthLab's handler.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL