auth

package
v2.2.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 2, 2026 License: AGPL-3.0 Imports: 20 Imported by: 0

Documentation

Index

Constants

View Source
const (
	AuthMethodKey     = models.AuthMethodContextKey
	AuthMethodSession = models.AuthMethodSession
	AuthMethodAPIKey  = models.AuthMethodAPIKey
	AuthMethodHost    = models.AuthMethodHost
)

Context key under which the middleware records how the request was authenticated, so downstream consumers (the audit trail) can tell a browser session from an API key. Defined on models so packages that cannot import auth can read it.

Variables

View Source
var ErrUserDisabled = errors.New("account is disabled")

ErrUserDisabled is returned by the password-reset flow for a disabled account, so a user the IdP has switched off cannot mint a local password.

Functions

func UserFromContext

func UserFromContext(c *gin.Context) (*models.User, bool)

UserFromContext returns the user AuthMiddleware stored on the request. Prefer this over inline c.Get("user") type assertions.

Types

type AuthService

type AuthService struct {
	Config              *Config
	DB                  *gorm.DB
	Service             services.ServiceInterface
	TokenStore          map[string]*models.User
	MailService         *notifications.MailService // Exported for testing
	NotificationService *services.NotificationService
	// contains filtered or unexported fields
}

func NewAuthService

func NewAuthService(config *Config, mailService *notifications.MailService, service services.ServiceInterface, notificationService *services.NotificationService) *AuthService

func (*AuthService) AdminOnly

func (a *AuthService) AdminOnly() gin.HandlerFunc

func (*AuthService) AuthMiddleware

func (a *AuthService) AuthMiddleware() gin.HandlerFunc

func (*AuthService) GetAuthenticatedUser

func (a *AuthService) GetAuthenticatedUser(c *gin.Context) *models.User

func (*AuthService) LoadUserFromContext

func (a *AuthService) LoadUserFromContext(c *gin.Context) (*models.User, error)

func (*AuthService) Login

func (a *AuthService) Login(c *gin.Context, email, password string) error

func (*AuthService) Logout

func (a *AuthService) Logout(c *gin.Context) error

func (*AuthService) Register

func (a *AuthService) Register(email, name, password string, showPortal, showChat bool) error

func (*AuthService) ResendVerificationEmail

func (a *AuthService) ResendVerificationEmail(email string) error

func (*AuthService) ResetPassword

func (a *AuthService) ResetPassword(email string) error

func (*AuthService) SSOOnly

func (a *AuthService) SSOOnly() gin.HandlerFunc

func (*AuthService) SendEmail

func (a *AuthService) SendEmail(to, subject, body string) error

func (*AuthService) SetUserSession

func (a *AuthService) SetUserSession(c *gin.Context, user *models.User) error

func (*AuthService) UpdatePassword

func (a *AuthService) UpdatePassword(user *models.User, oldPassword, newPassword string) error

func (*AuthService) ValidatePasswordComplexity

func (a *AuthService) ValidatePasswordComplexity(password string) error

func (*AuthService) ValidateResetToken

func (a *AuthService) ValidateResetToken(token string) (*models.User, error)

func (*AuthService) VerifyEmail

func (a *AuthService) VerifyEmail(token string) error

type Authenticator

type Authenticator interface {
	Authenticate(r *http.Request) (*services.HostIdentity, error)
}

Authenticator authenticates a request on behalf of a host application. It returns the user the host has signed in, or nil (and no error) when the request carries no host identity, in which case Studio's own API keys may still authenticate it. An error rejects the request.

type Config

type Config struct {
	DB           *gorm.DB
	Service      services.ServiceInterface
	CookieName   string
	CookieSecure bool

	CookieDomain string
	// CookiePath scopes the session cookie; empty means "/". Set it to the
	// base path when Studio is served under one.
	CookiePath       string
	ResetTokenExpiry time.Duration
	SessionDuration  time.Duration
	FrontendURL      string

	CookieHTTPOnly         bool
	CookieSameSite         http.SameSite
	RegistrationAllowed    bool
	AdminEmail             string
	TestMode               bool
	AllowedRegisterDomains []string
	TIBAPISecret           string
	TIBEnabled             bool
	OCIConfig              interface{} // Holds OCI configuration for plugin security

	// AllowSSOUserAPIKeys permits issuing API keys to SSO-provisioned
	// users; SSOAPIKeyLiveness rejects such a key once the user has gone
	// that long without an SSO login (0 = no limit). See config.Config.
	AllowSSOUserAPIKeys bool
	SSOAPIKeyLiveness   time.Duration
	// APIKeyTouchInterval throttles the api_key_last_used_at stamp (zero
	// means the default); SyncAPIKeyTouch stamps on every request, on the
	// request goroutine, which is what tests on a shared SQLite DB need.
	APIKeyTouchInterval time.Duration
	SyncAPIKeyTouch     bool

	// HostAuth authenticates requests for a host application Studio is
	// embedded in. When set it is asked first on every request, and the
	// identity it returns is turned into a Studio user by
	// ProvisionHostUser. Studio's own password login, registration and SSO
	// are then switched off (see LocalAccountsEnabled).
	HostAuth          Authenticator
	ProvisionHostUser func(services.HostIdentity) (*models.User, error)
	// HostLoginURL and HostLogoutURL are where the console sends a user to
	// sign in or out when the host authenticates. The console fills in a
	// "{return_to}" placeholder in HostLoginURL (see studio.Options.LoginURL).
	HostLoginURL  string
	HostLogoutURL string

	// CSRF, when set, replaces Studio's own CSRF protection for
	// cookie-authenticated requests: a host application can apply its own.
	// It must call the handler it wraps only for requests that pass.
	// CSRFTokenHeader and CSRFTokenURL tell the console which header carries
	// the token and where to fetch it (defaults: X-CSRF-Token and Studio's
	// /csrf-token).
	CSRF            func(http.Handler) http.Handler
	CSRFTokenHeader string
	CSRFTokenURL    string

	// Chromeless tells the console to leave out its own top bar and
	// navigation drawers, because the host application draws them.
	Chromeless bool
}

func (*Config) LocalAccountsEnabled

func (c *Config) LocalAccountsEnabled() bool

LocalAccountsEnabled reports whether Studio manages sign-in itself (passwords, registration, SSO), which it does unless a host authenticates.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL