auth

package
v1.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package auth handles passwords, session and API tokens, roles and the identity of the caller.

Index

Constants

View Source
const (
	APITokenPrefix = "stp_"
	SessionPrefix  = "sts_"
)

Token prefixes.

View Source
const (
	PermView          = RoleViewer
	PermRun           = RoleRunner // start, stop and kill runs
	PermEditScenarios = RoleEditor // scenarios, targets, secrets
	PermEditSchedules = RoleEditor // create, change and delete schedules
	PermManageUsers   = RoleAdmin  // users, audit log
	PermManageOwners  = RoleOwner  // grant or remove the owner role
)

Permissions map actions to the minimum role. Keeping them in one place makes the role model easy to review.

View Source
const MinPasswordLen = 10

MinPasswordLen is the shortest accepted password.

Variables

This section is empty.

Functions

func CheckDummy

func CheckDummy(pw string)

CheckDummy burns the same time as a real password check.

func CheckPassword

func CheckPassword(encoded, pw string) bool

CheckPassword reports whether pw matches an encoded hash, in constant time with respect to the hash contents.

func HashPassword

func HashPassword(pw string) (string, error)

HashPassword returns an encoded argon2id hash.

func HashToken

func HashToken(token string) []byte

HashToken hashes a presented token for lookup. Tokens are 256-bit random values, so a fast hash is sufficient.

func NewToken

func NewToken(prefix string) (token string, hash []byte)

NewToken returns a random token with a prefix and its SHA-256 hash. Only the hash is stored.

func WithPrincipal

func WithPrincipal(ctx context.Context, p *Principal) context.Context

WithPrincipal stores the principal in a context.

Types

type Limiter

type Limiter struct {
	// contains filtered or unexported fields
}

Limiter throttles repeated failures per key (email or IP) with a sliding window, to slow down password guessing.

func NewLimiter

func NewLimiter(max int, window time.Duration) *Limiter

NewLimiter allows max failures per key within window.

func (*Limiter) Allowed

func (l *Limiter) Allowed(key string) bool

Allowed reports whether key may try again.

func (*Limiter) Fail

func (l *Limiter) Fail(key string)

Fail records a failure for key.

func (*Limiter) Reset

func (l *Limiter) Reset(key string)

Reset clears key after a success.

type Principal

type Principal struct {
	UserID  uuid.UUID
	OrgID   uuid.UUID
	Email   string
	Name    string
	OrgName string
	// Role is the caller's role in the organisation (for a token, the
	// lower of the token's and its owner's), or in one project once
	// InProject has applied that project's override.
	Role Role
	// OrgRole is the member's own organisation role and TokenRole the
	// role an API token was created with (empty for sessions). They let a
	// project override replace the organisation role while a token still
	// never grants more than its own role.
	OrgRole, TokenRole Role
	// Via is "session" or "token:<name>".
	Via string
	// SessionHash is set for cookie sessions (used by logout).
	SessionHash []byte
}

Principal is the authenticated caller.

func FromContext

func FromContext(ctx context.Context) *Principal

FromContext returns the principal or nil.

func (*Principal) Actor

func (p *Principal) Actor() string

Actor describes the principal for the audit log.

func (*Principal) Can

func (p *Principal) Can(min Role) bool

Can reports whether the principal holds at least role min.

func (*Principal) InProject

func (p *Principal) InProject(override Role) *Principal

InProject returns a copy of p acting in one project, where override ("" for none) is the member's per-project role. The override replaces the organisation role, higher or lower, except that owners are owners everywhere; a token still never grants more than its own role.

type Role

type Role string

Role is an organisation role.

const (
	RoleOwner  Role = "owner"
	RoleAdmin  Role = "admin"
	RoleEditor Role = "editor"
	RoleRunner Role = "runner"
	RoleViewer Role = "viewer"
)

Roles from most to least privileged.

func Lower

func Lower(a, b Role) Role

Lower returns the less privileged of two roles. A token can never grant more than its owner currently has.

func (Role) AtLeast

func (r Role) AtLeast(min Role) bool

AtLeast reports whether r grants everything min does.

func (Role) Valid

func (r Role) Valid() bool

Valid reports whether r is a known role.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL