Documentation
¶
Overview ¶
Package authcache implements a cache for token auth to hold auth- results with cpu/mem inexpensive methods instead of always using secure but expensive methods to validate the token
Index ¶
Constants ¶
const AuthBackendAny = "*"
AuthBackendAny signals any backend can answer the validity of the token and no specific backend is selected
Variables ¶
ErrUnauthorized denotes the token could not be found in any backend auth method and therefore is not an user
Functions ¶
This section is empty.
Types ¶
type AuthFunc ¶
AuthFunc is a backend-function to resolve a token to a list of modules the token is authorized for, an expiry-time and an error. The error MUST be ErrUnauthorized in case the user is not found, if the error is another, the backend resolve will be cancelled and no further backends are queried.
type CacheEntry ¶
type CacheEntry struct {
AuthResult error // Allows for negative caching
ExpiresAt time.Time
Modules []string
}
CacheEntry represents an entry in the cache Service
type CreateOpt ¶ added in v3.40.0
type CreateOpt func(*Service)
CreateOpt supplies options to the creation of the cache
func WithAuthBackend ¶ added in v3.40.0
WithAuthBackend adds a new auth backend which is tried in order of begin added
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service manages the cached auth results
func (*Service) ValidateTokenFor ¶
ValidateTokenFor checks backends whether the given token has access to the given modules and caches the result
func (*Service) ValidateTokenForWithTokenType ¶ added in v3.40.0
func (s *Service) ValidateTokenForWithTokenType(token string, authBackendName string, modules ...string) error
ValidateTokenForWithTokenType checks the configured backends whether the given token has access to the given modules and caches the result for the selected auth backend name.