auth

package
v1.18.12 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 26 Imported by: 0

Documentation

Overview

Package auth provides authentication methods.

Index

Constants

View Source
const (
	MtSCRAMSHA256       = "SCRAMSHA256"       // password
	MtSCRAMPBKDF2SHA256 = "SCRAMPBKDF2SHA256" // password pbkdf2
	MtX509              = "X509"              // client certificate
	MtJWT               = "JWT"               // json web token
	MtSessionCookie     = "SessionCookie"     // session cookie
	MtLDAP              = "LDAP"              // LDAP authentication
)

authentication method types supported by the driver:

  • basic authentication (username, password based) (whether SCRAMSHA256 or SCRAMPBKDF2SHA256) and
  • X509 (client certificate) authentication and
  • JWT (token) authentication
View Source
const (
	MoSessionCookie byte = iota
	MoX509
	MoJWT
	MoSCRAMPBKDF2SHA256
	MoSCRAMSHA256
	MoLDAP
)

authentication method orders.

Variables

View Source
var ErrAuthVerifyFailed = errors.New("authentication check failed")

ErrAuthVerifyFailed indicates that the server response failed client-side authentication verification (e.g. an invalid SCRAM server proof or an LDAP client challenge mismatch). It is a classification error: an authentication method codec fails with such an error if the corresponding verification cannot be performed (e.g. by a sniffer without the client credentials) and not because of malformed wire content.

Functions

func DecodeAndCheckNumPrm added in v1.16.2

func DecodeAndCheckNumPrm(dec *encoding.Decoder, expected int) error

DecodeAndCheckNumPrm decodes and checks the number of parameters and returns an error if not equal expected, nil otherwise.

Types

type CertKey added in v1.8.7

type CertKey struct {
	// contains filtered or unexported fields
}

CertKey represents an X509 certificate and key.

func NewCertKey added in v1.8.7

func NewCertKey(certHandle, keyHandle unique.Handle[string]) (*CertKey, error)

NewCertKey returns a new certificate and key instance.

func (*CertKey) Cert added in v1.8.7

func (ck *CertKey) Cert() []byte

Cert returns the certificate.

func (*CertKey) Equal added in v1.8.7

func (ck *CertKey) Equal(certHandle, keyHandle unique.Handle[string]) bool

Equal returns true if the certificate and key are equal to the instance data, false otherwise.

func (*CertKey) Key added in v1.8.7

func (ck *CertKey) Key() []byte

Key returns the key.

func (*CertKey) String added in v1.8.7

func (ck *CertKey) String() string

type CertValidationError added in v1.8.7

type CertValidationError struct {
	// contains filtered or unexported fields
}

CertValidationError is returned in case of X509 certificate validation errors.

func (CertValidationError) Error added in v1.8.7

func (e CertValidationError) Error() string

type CookieGetter added in v1.3.6

type CookieGetter interface {
	Cookie() (logonname string, cookie []byte)
}

CookieGetter is implemented by authentication methods supporting cookies to reconnect.

type JWT

type JWT struct {
	// contains filtered or unexported fields
}

JWT implements JWT authentication.

func NewJWT

func NewJWT(token string) *JWT

NewJWT creates a new JWT instance.

func (*JWT) AuthLoginName added in v1.18.5

func (a *JWT) AuthLoginName() string

AuthLoginName implements the Method interface.

func (*JWT) Cookie

func (a *JWT) Cookie() (string, []byte)

Cookie implements the AuthCookieGetter interface.

func (*JWT) DecodeFinalReply added in v1.18.5

func (a *JWT) DecodeFinalReply(dec *encoding.Decoder) error

DecodeFinalReply implements the Method interface.

func (*JWT) DecodeFinalReq added in v1.18.5

func (a *JWT) DecodeFinalReq(dec *encoding.Decoder, logonname string) error

DecodeFinalReq implements the Method interface.

func (*JWT) DecodeInitReply added in v1.18.5

func (a *JWT) DecodeInitReply(dec *encoding.Decoder) error

DecodeInitReply implements the Method interface.

func (*JWT) DecodeInitReq added in v1.18.5

func (a *JWT) DecodeInitReq(dec *encoding.Decoder) error

DecodeInitReq implements the Method interface.

func (*JWT) EncodeFinalReq added in v1.18.5

func (a *JWT) EncodeFinalReq(prms *Prms) error

EncodeFinalReq implements the Method interface.

func (*JWT) EncodeInitReq added in v1.18.5

func (a *JWT) EncodeInitReq(prms *Prms) error

EncodeInitReq implements the Method interface.

func (*JWT) Order

func (a *JWT) Order() byte

Order implements the Method interface.

func (*JWT) String

func (a *JWT) String() string

func (*JWT) Typ

func (a *JWT) Typ() string

Typ implements the Method interface.

type LDAP added in v1.16.0

type LDAP struct {
	// contains filtered or unexported fields
}

LDAP implements LDAP authentication.

func NewLDAP added in v1.16.0

func NewLDAP(username, password string) *LDAP

NewLDAP creates a new LDAP authentication instance.

func (*LDAP) AuthLoginName added in v1.18.5

func (a *LDAP) AuthLoginName() string

AuthLoginName implements the Method interface.

func (*LDAP) DecodeFinalReply added in v1.18.5

func (a *LDAP) DecodeFinalReply(dec *encoding.Decoder) error

DecodeFinalReply implements the Method interface.

func (*LDAP) DecodeFinalReq added in v1.18.5

func (a *LDAP) DecodeFinalReq(dec *encoding.Decoder, logonname string) error

DecodeFinalReq implements the Method interface.

func (*LDAP) DecodeInitReply added in v1.18.5

func (a *LDAP) DecodeInitReply(dec *encoding.Decoder) error

DecodeInitReply implements the Method interface.

func (*LDAP) DecodeInitReq added in v1.18.5

func (a *LDAP) DecodeInitReq(dec *encoding.Decoder) error

DecodeInitReq implements the Method interface.

func (*LDAP) EncodeFinalReq added in v1.18.5

func (a *LDAP) EncodeFinalReq(prms *Prms) error

EncodeFinalReq implements the Method interface.

func (*LDAP) EncodeInitReq added in v1.18.5

func (a *LDAP) EncodeInitReq(prms *Prms) error

EncodeInitReq implements the Method interface.

func (*LDAP) Order added in v1.16.0

func (a *LDAP) Order() byte

Order implements the Method interface.

func (*LDAP) String added in v1.16.0

func (a *LDAP) String() string

func (*LDAP) Typ added in v1.16.0

func (a *LDAP) Typ() string

Typ implements the Method interface.

type Method

type Method interface {
	fmt.Stringer
	Typ() string
	Order() byte
	AuthLoginName() string
	EncodeInitReq(prms *Prms) error
	DecodeInitReq(dec *encoding.Decoder) error
	DecodeInitReply(dec *encoding.Decoder) error
	EncodeFinalReq(prms *Prms) error
	DecodeFinalReq(dec *encoding.Decoder, logonname string) error
	DecodeFinalReply(dec *encoding.Decoder) error
}

A Method defines the interface for an authentication method.

The request codecs are symmetric: the generic part of the authentication protocol writes and reads the common framing - parameter count, logonname and method name - and delegates the method specific detail parameter to the dedicated methods below. The detail is a single parameter, which may be a nested sub-parameter vector.

func InitRepMethod added in v1.18.5

func InitRepMethod(dec *encoding.Decoder) (Method, error)

InitRepMethod interprets the method type of an authentication initial reply into a credential-free method instance. The reply tail is decoded by the returned method's DecodeInitReply.

func NewMethod added in v1.18.5

func NewMethod(mt string) (Method, bool)

NewMethod returns a new authentication method of the given type used to interpret authentication wire content. The returned method is created without any client credentials.

type Methods added in v1.3.6

type Methods map[string]Method // key equals authentication method type.

Methods defines a collection of methods.

func (Methods) Order added in v1.3.6

func (m Methods) Order() []Method

Order returns an ordered method slice.

type Prms

type Prms struct {
	// contains filtered or unexported fields
}

Prms represents authentication parameters.

func (*Prms) AddCESU8String

func (p *Prms) AddCESU8String(s string)

AddCESU8String adds a CESU8 string parameter.

func (*Prms) AddString added in v1.18.5

func (p *Prms) AddString(s string)

AddString adds a string parameter encoded as raw bytes to distinguish it from a unicode string parameter.

func (*Prms) Encode

func (p *Prms) Encode(enc *encoding.Encoder) error

Encode encodes the parameters.

type SCRAMPBKDF2SHA256

type SCRAMPBKDF2SHA256 struct {
	// contains filtered or unexported fields
}

SCRAMPBKDF2SHA256 implements SCRAMPBKDF2SHA256 authentication.

func NewSCRAMPBKDF2SHA256

func NewSCRAMPBKDF2SHA256(username, password string) *SCRAMPBKDF2SHA256

NewSCRAMPBKDF2SHA256 creates a new SCRAMPBKDF2SHA256 instance.

func (*SCRAMPBKDF2SHA256) AuthLoginName added in v1.18.5

func (a *SCRAMPBKDF2SHA256) AuthLoginName() string

AuthLoginName implements the Method interface.

func (*SCRAMPBKDF2SHA256) Compare added in v1.8.26

func (a *SCRAMPBKDF2SHA256) Compare(a1 *SCRAMPBKDF2SHA256) bool

Compare implements cache.Compare interface.

func (*SCRAMPBKDF2SHA256) DecodeFinalReply added in v1.18.5

func (a *SCRAMPBKDF2SHA256) DecodeFinalReply(dec *encoding.Decoder) error

DecodeFinalReply implements the Method interface.

func (*SCRAMPBKDF2SHA256) DecodeFinalReq added in v1.18.5

func (a *SCRAMPBKDF2SHA256) DecodeFinalReq(dec *encoding.Decoder, logonname string) error

DecodeFinalReq implements the Method interface.

func (*SCRAMPBKDF2SHA256) DecodeInitReply added in v1.18.5

func (a *SCRAMPBKDF2SHA256) DecodeInitReply(dec *encoding.Decoder) error

DecodeInitReply implements the Method interface.

func (*SCRAMPBKDF2SHA256) DecodeInitReq added in v1.18.5

func (a *SCRAMPBKDF2SHA256) DecodeInitReq(dec *encoding.Decoder) error

DecodeInitReq implements the Method interface.

func (*SCRAMPBKDF2SHA256) EncodeFinalReq added in v1.18.5

func (a *SCRAMPBKDF2SHA256) EncodeFinalReq(prms *Prms) error

EncodeFinalReq implements the Method interface.

func (*SCRAMPBKDF2SHA256) EncodeInitReq added in v1.18.5

func (a *SCRAMPBKDF2SHA256) EncodeInitReq(prms *Prms) error

EncodeInitReq implements the Method interface.

func (*SCRAMPBKDF2SHA256) Order

func (a *SCRAMPBKDF2SHA256) Order() byte

Order implements the Method interface.

func (*SCRAMPBKDF2SHA256) String

func (a *SCRAMPBKDF2SHA256) String() string

func (*SCRAMPBKDF2SHA256) Typ

func (a *SCRAMPBKDF2SHA256) Typ() string

Typ implements the Method interface.

type SCRAMSHA256

type SCRAMSHA256 struct {
	// contains filtered or unexported fields
}

SCRAMSHA256 implements SCRAMSHA256 authentication.

func NewSCRAMSHA256

func NewSCRAMSHA256(username, password string) *SCRAMSHA256

NewSCRAMSHA256 creates a new SCRAMSHA256 instance.

func (*SCRAMSHA256) AuthLoginName added in v1.18.5

func (a *SCRAMSHA256) AuthLoginName() string

AuthLoginName implements the Method interface.

func (*SCRAMSHA256) Compare added in v1.8.26

func (a *SCRAMSHA256) Compare(a1 *SCRAMSHA256) bool

Compare implements cache.Compare interface.

func (*SCRAMSHA256) DecodeFinalReply added in v1.18.5

func (a *SCRAMSHA256) DecodeFinalReply(dec *encoding.Decoder) error

DecodeFinalReply implements the Method interface.

func (*SCRAMSHA256) DecodeFinalReq added in v1.18.5

func (a *SCRAMSHA256) DecodeFinalReq(dec *encoding.Decoder, logonname string) error

DecodeFinalReq implements the Method interface.

func (*SCRAMSHA256) DecodeInitReply added in v1.18.5

func (a *SCRAMSHA256) DecodeInitReply(dec *encoding.Decoder) error

DecodeInitReply implements the Method interface.

func (*SCRAMSHA256) DecodeInitReq added in v1.18.5

func (a *SCRAMSHA256) DecodeInitReq(dec *encoding.Decoder) error

DecodeInitReq implements the Method interface.

func (*SCRAMSHA256) EncodeFinalReq added in v1.18.5

func (a *SCRAMSHA256) EncodeFinalReq(prms *Prms) error

EncodeFinalReq implements the Method interface.

func (*SCRAMSHA256) EncodeInitReq added in v1.18.5

func (a *SCRAMSHA256) EncodeInitReq(prms *Prms) error

EncodeInitReq implements the Method interface.

func (*SCRAMSHA256) Order

func (a *SCRAMSHA256) Order() byte

Order implements the Method interface.

func (*SCRAMSHA256) String

func (a *SCRAMSHA256) String() string

func (*SCRAMSHA256) Typ

func (a *SCRAMSHA256) Typ() string

Typ implements the Method interface.

type SessionCookie

type SessionCookie struct {
	// contains filtered or unexported fields
}

SessionCookie implements session cookie authentication.

func NewSessionCookie

func NewSessionCookie(cookie []byte, logonname, clientID string) *SessionCookie

NewSessionCookie creates a new SessionCookie instance.

func (*SessionCookie) AuthLoginName added in v1.18.5

func (a *SessionCookie) AuthLoginName() string

AuthLoginName implements the Method interface.

func (*SessionCookie) DecodeFinalReply added in v1.18.5

func (a *SessionCookie) DecodeFinalReply(dec *encoding.Decoder) error

DecodeFinalReply implements the Method interface.

func (*SessionCookie) DecodeFinalReq added in v1.18.5

func (a *SessionCookie) DecodeFinalReq(dec *encoding.Decoder, logonname string) error

DecodeFinalReq implements the Method interface.

func (*SessionCookie) DecodeInitReply added in v1.18.5

func (a *SessionCookie) DecodeInitReply(_ *encoding.Decoder) error

DecodeInitReply implements the Method interface.

func (*SessionCookie) DecodeInitReq added in v1.18.5

func (a *SessionCookie) DecodeInitReq(dec *encoding.Decoder) error

DecodeInitReq implements the Method interface.

func (*SessionCookie) EncodeFinalReq added in v1.18.5

func (a *SessionCookie) EncodeFinalReq(prms *Prms) error

EncodeFinalReq implements the Method interface.

func (*SessionCookie) EncodeInitReq added in v1.18.5

func (a *SessionCookie) EncodeInitReq(prms *Prms) error

EncodeInitReq implements the Method interface.

func (*SessionCookie) Order

func (a *SessionCookie) Order() byte

Order implements the Method interface.

func (*SessionCookie) String

func (a *SessionCookie) String() string

func (*SessionCookie) Typ

func (a *SessionCookie) Typ() string

Typ implements the Method interface.

type X509

type X509 struct {
	// contains filtered or unexported fields
}

X509 implements X509 authentication.

func NewX509

func NewX509(certKey *CertKey) *X509

NewX509 creates a new X509 instance.

func (*X509) AuthLoginName added in v1.18.5

func (a *X509) AuthLoginName() string

AuthLoginName implements the Method interface.

func (*X509) DecodeFinalReply added in v1.18.5

func (a *X509) DecodeFinalReply(dec *encoding.Decoder) error

DecodeFinalReply implements the Method interface.

func (*X509) DecodeFinalReq added in v1.18.5

func (a *X509) DecodeFinalReq(dec *encoding.Decoder, logonname string) error

DecodeFinalReq implements the Method interface.

func (*X509) DecodeInitReply added in v1.18.5

func (a *X509) DecodeInitReply(dec *encoding.Decoder) error

DecodeInitReply implements the Method interface.

func (*X509) DecodeInitReq added in v1.18.5

func (a *X509) DecodeInitReq(dec *encoding.Decoder) error

DecodeInitReq implements the Method interface.

func (*X509) EncodeFinalReq added in v1.18.5

func (a *X509) EncodeFinalReq(prms *Prms) error

EncodeFinalReq implements the Method interface.

func (*X509) EncodeInitReq added in v1.18.5

func (a *X509) EncodeInitReq(prms *Prms) error

EncodeInitReq implements the Method interface.

func (*X509) Order

func (a *X509) Order() byte

Order implements the Method interface.

func (*X509) String

func (a *X509) String() string

func (*X509) Typ

func (a *X509) Typ() string

Typ implements the Method interface.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL