Documentation
¶
Overview ¶
Package authlab is AuthLab, a small OAuth 2.0 and OpenID Connect token service: password, refresh-token and client-credentials grants, userinfo, introspection and revocation, with Ed25519-signed JWT access tokens. It is the reference app for the identity pack.
Planted bottlenecks (see README.md), each switched off by a fix flag:
- lock: password hashes are checked while holding the store's single lock, so logins run one at a time and refreshes wait behind them (fix "lock" hashes outside the lock).
- index: refresh tokens live in a list that is never pruned and is scanned with a constant-time compare on every refresh and revocation, so each refresh costs more the more tokens were ever issued (fix "index" uses a map and drops expired tokens).
Index ¶
Constants ¶
View Source
const ( Users = 1000 Password = "authlab-pass" //nolint:gosec // demo password, published in the README )
Users is how many accounts AuthLab seeds: user0001@authlab.test to user1000@authlab.test, all with the password Password.
Variables ¶
This section is empty.
Functions ¶
Types ¶
This section is empty.
Click to show internal directories.
Click to hide internal directories.