Documentation
¶
Overview ¶
Package auth provides authentication methods.
Index ¶
- Constants
- Variables
- func DecodeAndCheckNumPrm(dec *encoding.Decoder, expected int) error
- type CertKey
- type CertValidationError
- type CookieGetter
- type JWT
- func (a *JWT) AuthLoginName() string
- func (a *JWT) Cookie() (string, []byte)
- func (a *JWT) DecodeFinalReply(dec *encoding.Decoder) error
- func (a *JWT) DecodeFinalReq(dec *encoding.Decoder, logonname string) error
- func (a *JWT) DecodeInitReply(dec *encoding.Decoder) error
- func (a *JWT) DecodeInitReq(dec *encoding.Decoder) error
- func (a *JWT) EncodeFinalReq(prms *Prms) error
- func (a *JWT) EncodeInitReq(prms *Prms) error
- func (a *JWT) Order() byte
- func (a *JWT) String() string
- func (a *JWT) Typ() string
- type LDAP
- func (a *LDAP) AuthLoginName() string
- func (a *LDAP) DecodeFinalReply(dec *encoding.Decoder) error
- func (a *LDAP) DecodeFinalReq(dec *encoding.Decoder, logonname string) error
- func (a *LDAP) DecodeInitReply(dec *encoding.Decoder) error
- func (a *LDAP) DecodeInitReq(dec *encoding.Decoder) error
- func (a *LDAP) EncodeFinalReq(prms *Prms) error
- func (a *LDAP) EncodeInitReq(prms *Prms) error
- func (a *LDAP) Order() byte
- func (a *LDAP) String() string
- func (a *LDAP) Typ() string
- type Method
- type Methods
- type Prms
- type SCRAMPBKDF2SHA256
- func (a *SCRAMPBKDF2SHA256) AuthLoginName() string
- func (a *SCRAMPBKDF2SHA256) Compare(a1 *SCRAMPBKDF2SHA256) bool
- func (a *SCRAMPBKDF2SHA256) DecodeFinalReply(dec *encoding.Decoder) error
- func (a *SCRAMPBKDF2SHA256) DecodeFinalReq(dec *encoding.Decoder, logonname string) error
- func (a *SCRAMPBKDF2SHA256) DecodeInitReply(dec *encoding.Decoder) error
- func (a *SCRAMPBKDF2SHA256) DecodeInitReq(dec *encoding.Decoder) error
- func (a *SCRAMPBKDF2SHA256) EncodeFinalReq(prms *Prms) error
- func (a *SCRAMPBKDF2SHA256) EncodeInitReq(prms *Prms) error
- func (a *SCRAMPBKDF2SHA256) Order() byte
- func (a *SCRAMPBKDF2SHA256) String() string
- func (a *SCRAMPBKDF2SHA256) Typ() string
- type SCRAMSHA256
- func (a *SCRAMSHA256) AuthLoginName() string
- func (a *SCRAMSHA256) Compare(a1 *SCRAMSHA256) bool
- func (a *SCRAMSHA256) DecodeFinalReply(dec *encoding.Decoder) error
- func (a *SCRAMSHA256) DecodeFinalReq(dec *encoding.Decoder, logonname string) error
- func (a *SCRAMSHA256) DecodeInitReply(dec *encoding.Decoder) error
- func (a *SCRAMSHA256) DecodeInitReq(dec *encoding.Decoder) error
- func (a *SCRAMSHA256) EncodeFinalReq(prms *Prms) error
- func (a *SCRAMSHA256) EncodeInitReq(prms *Prms) error
- func (a *SCRAMSHA256) Order() byte
- func (a *SCRAMSHA256) String() string
- func (a *SCRAMSHA256) Typ() string
- type SessionCookie
- func (a *SessionCookie) AuthLoginName() string
- func (a *SessionCookie) DecodeFinalReply(dec *encoding.Decoder) error
- func (a *SessionCookie) DecodeFinalReq(dec *encoding.Decoder, logonname string) error
- func (a *SessionCookie) DecodeInitReply(_ *encoding.Decoder) error
- func (a *SessionCookie) DecodeInitReq(dec *encoding.Decoder) error
- func (a *SessionCookie) EncodeFinalReq(prms *Prms) error
- func (a *SessionCookie) EncodeInitReq(prms *Prms) error
- func (a *SessionCookie) Order() byte
- func (a *SessionCookie) String() string
- func (a *SessionCookie) Typ() string
- type X509
- func (a *X509) AuthLoginName() string
- func (a *X509) DecodeFinalReply(dec *encoding.Decoder) error
- func (a *X509) DecodeFinalReq(dec *encoding.Decoder, logonname string) error
- func (a *X509) DecodeInitReply(dec *encoding.Decoder) error
- func (a *X509) DecodeInitReq(dec *encoding.Decoder) error
- func (a *X509) EncodeFinalReq(prms *Prms) error
- func (a *X509) EncodeInitReq(prms *Prms) error
- func (a *X509) Order() byte
- func (a *X509) String() string
- func (a *X509) Typ() string
Constants ¶
const ( MtSCRAMSHA256 = "SCRAMSHA256" // password MtSCRAMPBKDF2SHA256 = "SCRAMPBKDF2SHA256" // password pbkdf2 MtX509 = "X509" // client certificate MtJWT = "JWT" // json web token MtSessionCookie = "SessionCookie" // session cookie MtLDAP = "LDAP" // LDAP authentication )
authentication method types supported by the driver:
- basic authentication (username, password based) (whether SCRAMSHA256 or SCRAMPBKDF2SHA256) and
- X509 (client certificate) authentication and
- JWT (token) authentication
const ( MoSessionCookie byte = iota MoX509 MoJWT MoSCRAMPBKDF2SHA256 MoSCRAMSHA256 MoLDAP )
authentication method orders.
Variables ¶
var ErrAuthVerifyFailed = errors.New("authentication check failed")
ErrAuthVerifyFailed indicates that the server response failed client-side authentication verification (e.g. an invalid SCRAM server proof or an LDAP client challenge mismatch). It is a classification error: an authentication method codec fails with such an error if the corresponding verification cannot be performed (e.g. by a sniffer without the client credentials) and not because of malformed wire content.
Functions ¶
Types ¶
type CertKey ¶ added in v1.8.7
type CertKey struct {
// contains filtered or unexported fields
}
CertKey represents an X509 certificate and key.
func NewCertKey ¶ added in v1.8.7
NewCertKey returns a new certificate and key instance.
type CertValidationError ¶ added in v1.8.7
type CertValidationError struct {
// contains filtered or unexported fields
}
CertValidationError is returned in case of X509 certificate validation errors.
func (CertValidationError) Error ¶ added in v1.8.7
func (e CertValidationError) Error() string
type CookieGetter ¶ added in v1.3.6
CookieGetter is implemented by authentication methods supporting cookies to reconnect.
type JWT ¶
type JWT struct {
// contains filtered or unexported fields
}
JWT implements JWT authentication.
func (*JWT) AuthLoginName ¶ added in v1.18.5
AuthLoginName implements the Method interface.
func (*JWT) DecodeFinalReply ¶ added in v1.18.5
DecodeFinalReply implements the Method interface.
func (*JWT) DecodeFinalReq ¶ added in v1.18.5
DecodeFinalReq implements the Method interface.
func (*JWT) DecodeInitReply ¶ added in v1.18.5
DecodeInitReply implements the Method interface.
func (*JWT) DecodeInitReq ¶ added in v1.18.5
DecodeInitReq implements the Method interface.
func (*JWT) EncodeFinalReq ¶ added in v1.18.5
EncodeFinalReq implements the Method interface.
func (*JWT) EncodeInitReq ¶ added in v1.18.5
EncodeInitReq implements the Method interface.
type LDAP ¶ added in v1.16.0
type LDAP struct {
// contains filtered or unexported fields
}
LDAP implements LDAP authentication.
func (*LDAP) AuthLoginName ¶ added in v1.18.5
AuthLoginName implements the Method interface.
func (*LDAP) DecodeFinalReply ¶ added in v1.18.5
DecodeFinalReply implements the Method interface.
func (*LDAP) DecodeFinalReq ¶ added in v1.18.5
DecodeFinalReq implements the Method interface.
func (*LDAP) DecodeInitReply ¶ added in v1.18.5
DecodeInitReply implements the Method interface.
func (*LDAP) DecodeInitReq ¶ added in v1.18.5
DecodeInitReq implements the Method interface.
func (*LDAP) EncodeFinalReq ¶ added in v1.18.5
EncodeFinalReq implements the Method interface.
func (*LDAP) EncodeInitReq ¶ added in v1.18.5
EncodeInitReq implements the Method interface.
type Method ¶
type Method interface {
fmt.Stringer
Typ() string
Order() byte
AuthLoginName() string
EncodeInitReq(prms *Prms) error
DecodeInitReq(dec *encoding.Decoder) error
DecodeInitReply(dec *encoding.Decoder) error
EncodeFinalReq(prms *Prms) error
DecodeFinalReq(dec *encoding.Decoder, logonname string) error
DecodeFinalReply(dec *encoding.Decoder) error
}
A Method defines the interface for an authentication method.
The request codecs are symmetric: the generic part of the authentication protocol writes and reads the common framing - parameter count, logonname and method name - and delegates the method specific detail parameter to the dedicated methods below. The detail is a single parameter, which may be a nested sub-parameter vector.
func InitRepMethod ¶ added in v1.18.5
InitRepMethod interprets the method type of an authentication initial reply into a credential-free method instance. The reply tail is decoded by the returned method's DecodeInitReply.
type Prms ¶
type Prms struct {
// contains filtered or unexported fields
}
Prms represents authentication parameters.
func (*Prms) AddCESU8String ¶
AddCESU8String adds a CESU8 string parameter.
type SCRAMPBKDF2SHA256 ¶
type SCRAMPBKDF2SHA256 struct {
// contains filtered or unexported fields
}
SCRAMPBKDF2SHA256 implements SCRAMPBKDF2SHA256 authentication.
func NewSCRAMPBKDF2SHA256 ¶
func NewSCRAMPBKDF2SHA256(username, password string) *SCRAMPBKDF2SHA256
NewSCRAMPBKDF2SHA256 creates a new SCRAMPBKDF2SHA256 instance.
func (*SCRAMPBKDF2SHA256) AuthLoginName ¶ added in v1.18.5
func (a *SCRAMPBKDF2SHA256) AuthLoginName() string
AuthLoginName implements the Method interface.
func (*SCRAMPBKDF2SHA256) Compare ¶ added in v1.8.26
func (a *SCRAMPBKDF2SHA256) Compare(a1 *SCRAMPBKDF2SHA256) bool
Compare implements cache.Compare interface.
func (*SCRAMPBKDF2SHA256) DecodeFinalReply ¶ added in v1.18.5
func (a *SCRAMPBKDF2SHA256) DecodeFinalReply(dec *encoding.Decoder) error
DecodeFinalReply implements the Method interface.
func (*SCRAMPBKDF2SHA256) DecodeFinalReq ¶ added in v1.18.5
func (a *SCRAMPBKDF2SHA256) DecodeFinalReq(dec *encoding.Decoder, logonname string) error
DecodeFinalReq implements the Method interface.
func (*SCRAMPBKDF2SHA256) DecodeInitReply ¶ added in v1.18.5
func (a *SCRAMPBKDF2SHA256) DecodeInitReply(dec *encoding.Decoder) error
DecodeInitReply implements the Method interface.
func (*SCRAMPBKDF2SHA256) DecodeInitReq ¶ added in v1.18.5
func (a *SCRAMPBKDF2SHA256) DecodeInitReq(dec *encoding.Decoder) error
DecodeInitReq implements the Method interface.
func (*SCRAMPBKDF2SHA256) EncodeFinalReq ¶ added in v1.18.5
func (a *SCRAMPBKDF2SHA256) EncodeFinalReq(prms *Prms) error
EncodeFinalReq implements the Method interface.
func (*SCRAMPBKDF2SHA256) EncodeInitReq ¶ added in v1.18.5
func (a *SCRAMPBKDF2SHA256) EncodeInitReq(prms *Prms) error
EncodeInitReq implements the Method interface.
func (*SCRAMPBKDF2SHA256) Order ¶
func (a *SCRAMPBKDF2SHA256) Order() byte
Order implements the Method interface.
func (*SCRAMPBKDF2SHA256) String ¶
func (a *SCRAMPBKDF2SHA256) String() string
func (*SCRAMPBKDF2SHA256) Typ ¶
func (a *SCRAMPBKDF2SHA256) Typ() string
Typ implements the Method interface.
type SCRAMSHA256 ¶
type SCRAMSHA256 struct {
// contains filtered or unexported fields
}
SCRAMSHA256 implements SCRAMSHA256 authentication.
func NewSCRAMSHA256 ¶
func NewSCRAMSHA256(username, password string) *SCRAMSHA256
NewSCRAMSHA256 creates a new SCRAMSHA256 instance.
func (*SCRAMSHA256) AuthLoginName ¶ added in v1.18.5
func (a *SCRAMSHA256) AuthLoginName() string
AuthLoginName implements the Method interface.
func (*SCRAMSHA256) Compare ¶ added in v1.8.26
func (a *SCRAMSHA256) Compare(a1 *SCRAMSHA256) bool
Compare implements cache.Compare interface.
func (*SCRAMSHA256) DecodeFinalReply ¶ added in v1.18.5
func (a *SCRAMSHA256) DecodeFinalReply(dec *encoding.Decoder) error
DecodeFinalReply implements the Method interface.
func (*SCRAMSHA256) DecodeFinalReq ¶ added in v1.18.5
func (a *SCRAMSHA256) DecodeFinalReq(dec *encoding.Decoder, logonname string) error
DecodeFinalReq implements the Method interface.
func (*SCRAMSHA256) DecodeInitReply ¶ added in v1.18.5
func (a *SCRAMSHA256) DecodeInitReply(dec *encoding.Decoder) error
DecodeInitReply implements the Method interface.
func (*SCRAMSHA256) DecodeInitReq ¶ added in v1.18.5
func (a *SCRAMSHA256) DecodeInitReq(dec *encoding.Decoder) error
DecodeInitReq implements the Method interface.
func (*SCRAMSHA256) EncodeFinalReq ¶ added in v1.18.5
func (a *SCRAMSHA256) EncodeFinalReq(prms *Prms) error
EncodeFinalReq implements the Method interface.
func (*SCRAMSHA256) EncodeInitReq ¶ added in v1.18.5
func (a *SCRAMSHA256) EncodeInitReq(prms *Prms) error
EncodeInitReq implements the Method interface.
func (*SCRAMSHA256) Order ¶
func (a *SCRAMSHA256) Order() byte
Order implements the Method interface.
func (*SCRAMSHA256) String ¶
func (a *SCRAMSHA256) String() string
type SessionCookie ¶
type SessionCookie struct {
// contains filtered or unexported fields
}
SessionCookie implements session cookie authentication.
func NewSessionCookie ¶
func NewSessionCookie(cookie []byte, logonname, clientID string) *SessionCookie
NewSessionCookie creates a new SessionCookie instance.
func (*SessionCookie) AuthLoginName ¶ added in v1.18.5
func (a *SessionCookie) AuthLoginName() string
AuthLoginName implements the Method interface.
func (*SessionCookie) DecodeFinalReply ¶ added in v1.18.5
func (a *SessionCookie) DecodeFinalReply(dec *encoding.Decoder) error
DecodeFinalReply implements the Method interface.
func (*SessionCookie) DecodeFinalReq ¶ added in v1.18.5
func (a *SessionCookie) DecodeFinalReq(dec *encoding.Decoder, logonname string) error
DecodeFinalReq implements the Method interface.
func (*SessionCookie) DecodeInitReply ¶ added in v1.18.5
func (a *SessionCookie) DecodeInitReply(_ *encoding.Decoder) error
DecodeInitReply implements the Method interface.
func (*SessionCookie) DecodeInitReq ¶ added in v1.18.5
func (a *SessionCookie) DecodeInitReq(dec *encoding.Decoder) error
DecodeInitReq implements the Method interface.
func (*SessionCookie) EncodeFinalReq ¶ added in v1.18.5
func (a *SessionCookie) EncodeFinalReq(prms *Prms) error
EncodeFinalReq implements the Method interface.
func (*SessionCookie) EncodeInitReq ¶ added in v1.18.5
func (a *SessionCookie) EncodeInitReq(prms *Prms) error
EncodeInitReq implements the Method interface.
func (*SessionCookie) Order ¶
func (a *SessionCookie) Order() byte
Order implements the Method interface.
func (*SessionCookie) String ¶
func (a *SessionCookie) String() string
func (*SessionCookie) Typ ¶
func (a *SessionCookie) Typ() string
Typ implements the Method interface.
type X509 ¶
type X509 struct {
// contains filtered or unexported fields
}
X509 implements X509 authentication.
func (*X509) AuthLoginName ¶ added in v1.18.5
AuthLoginName implements the Method interface.
func (*X509) DecodeFinalReply ¶ added in v1.18.5
DecodeFinalReply implements the Method interface.
func (*X509) DecodeFinalReq ¶ added in v1.18.5
DecodeFinalReq implements the Method interface.
func (*X509) DecodeInitReply ¶ added in v1.18.5
DecodeInitReply implements the Method interface.
func (*X509) DecodeInitReq ¶ added in v1.18.5
DecodeInitReq implements the Method interface.
func (*X509) EncodeFinalReq ¶ added in v1.18.5
EncodeFinalReq implements the Method interface.
func (*X509) EncodeInitReq ¶ added in v1.18.5
EncodeInitReq implements the Method interface.