Documentation
¶
Overview ¶
Package auth handles passwords, session and API tokens, roles and the identity of the caller.
Index ¶
- Constants
- func CheckDummy(pw string)
- func CheckPassword(encoded, pw string) bool
- func HashPassword(pw string) (string, error)
- func HashToken(token string) []byte
- func NewToken(prefix string) (token string, hash []byte)
- func WithPrincipal(ctx context.Context, p *Principal) context.Context
- type Limiter
- type Principal
- type Role
Constants ¶
const ( APITokenPrefix = "stp_" SessionPrefix = "sts_" )
Token prefixes.
const ( PermView = RoleViewer PermRun = RoleRunner // start, stop and kill runs PermEditScenarios = RoleEditor // scenarios, targets, secrets PermEditSchedules = RoleEditor // create, change and delete schedules PermManageUsers = RoleAdmin // users, audit log PermManageOwners = RoleOwner // grant or remove the owner role )
Permissions map actions to the minimum role. Keeping them in one place makes the role model easy to review.
const MinPasswordLen = 10
MinPasswordLen is the shortest accepted password.
Variables ¶
This section is empty.
Functions ¶
func CheckDummy ¶
func CheckDummy(pw string)
CheckDummy burns the same time as a real password check.
func CheckPassword ¶
CheckPassword reports whether pw matches an encoded hash, in constant time with respect to the hash contents.
func HashPassword ¶
HashPassword returns an encoded argon2id hash.
func HashToken ¶
HashToken hashes a presented token for lookup. Tokens are 256-bit random values, so a fast hash is sufficient.
Types ¶
type Limiter ¶
type Limiter struct {
// contains filtered or unexported fields
}
Limiter throttles repeated failures per key (email or IP) with a sliding window, to slow down password guessing.
func NewLimiter ¶
NewLimiter allows max failures per key within window.
type Principal ¶
type Principal struct {
UserID uuid.UUID
OrgID uuid.UUID
Email string
Name string
OrgName string
// Role is the caller's role in the organisation (for a token, the
// lower of the token's and its owner's), or in one project once
// InProject has applied that project's override.
Role Role
// OrgRole is the member's own organisation role and TokenRole the
// role an API token was created with (empty for sessions). They let a
// project override replace the organisation role while a token still
// never grants more than its own role.
OrgRole, TokenRole Role
// Via is "session" or "token:<name>".
Via string
// SessionHash is set for cookie sessions (used by logout).
SessionHash []byte
}
Principal is the authenticated caller.
func FromContext ¶
FromContext returns the principal or nil.
func (*Principal) InProject ¶
InProject returns a copy of p acting in one project, where override ("" for none) is the member's per-project role. The override replaces the organisation role, higher or lower, except that owners are owners everywhere; a token still never grants more than its own role.
type Role ¶
type Role string
Role is an organisation role.
const ( RoleOwner Role = "owner" RoleAdmin Role = "admin" RoleEditor Role = "editor" RoleRunner Role = "runner" RoleViewer Role = "viewer" )
Roles from most to least privileged.
func Lower ¶
Lower returns the less privileged of two roles. A token can never grant more than its owner currently has.