Documentation
¶
Index ¶
- Constants
- Variables
- func UserFromContext(c *gin.Context) (*models.User, bool)
- type AuthService
- func (a *AuthService) AdminOnly() gin.HandlerFunc
- func (a *AuthService) AuthMiddleware() gin.HandlerFunc
- func (a *AuthService) GetAuthenticatedUser(c *gin.Context) *models.User
- func (a *AuthService) LoadUserFromContext(c *gin.Context) (*models.User, error)
- func (a *AuthService) Login(c *gin.Context, email, password string) error
- func (a *AuthService) Logout(c *gin.Context) error
- func (a *AuthService) Register(email, name, password string, showPortal, showChat bool) error
- func (a *AuthService) ResendVerificationEmail(email string) error
- func (a *AuthService) ResetPassword(email string) error
- func (a *AuthService) SSOOnly() gin.HandlerFunc
- func (a *AuthService) SendEmail(to, subject, body string) error
- func (a *AuthService) SetUserSession(c *gin.Context, user *models.User) error
- func (a *AuthService) UpdatePassword(user *models.User, oldPassword, newPassword string) error
- func (a *AuthService) ValidatePasswordComplexity(password string) error
- func (a *AuthService) ValidateResetToken(token string) (*models.User, error)
- func (a *AuthService) VerifyEmail(token string) error
- type Authenticator
- type Config
Constants ¶
const ( AuthMethodKey = models.AuthMethodContextKey AuthMethodSession = models.AuthMethodSession AuthMethodAPIKey = models.AuthMethodAPIKey AuthMethodHost = models.AuthMethodHost )
Context key under which the middleware records how the request was authenticated, so downstream consumers (the audit trail) can tell a browser session from an API key. Defined on models so packages that cannot import auth can read it.
Variables ¶
var ErrUserDisabled = errors.New("account is disabled")
ErrUserDisabled is returned by the password-reset flow for a disabled account, so a user the IdP has switched off cannot mint a local password.
Functions ¶
Types ¶
type AuthService ¶
type AuthService struct {
Config *Config
DB *gorm.DB
Service services.ServiceInterface
TokenStore map[string]*models.User
MailService *notifications.MailService // Exported for testing
NotificationService *services.NotificationService
// contains filtered or unexported fields
}
func NewAuthService ¶
func NewAuthService(config *Config, mailService *notifications.MailService, service services.ServiceInterface, notificationService *services.NotificationService) *AuthService
func (*AuthService) AdminOnly ¶
func (a *AuthService) AdminOnly() gin.HandlerFunc
func (*AuthService) AuthMiddleware ¶
func (a *AuthService) AuthMiddleware() gin.HandlerFunc
func (*AuthService) GetAuthenticatedUser ¶
func (a *AuthService) GetAuthenticatedUser(c *gin.Context) *models.User
func (*AuthService) LoadUserFromContext ¶
func (*AuthService) Login ¶
func (a *AuthService) Login(c *gin.Context, email, password string) error
func (*AuthService) Register ¶
func (a *AuthService) Register(email, name, password string, showPortal, showChat bool) error
func (*AuthService) ResendVerificationEmail ¶
func (a *AuthService) ResendVerificationEmail(email string) error
func (*AuthService) ResetPassword ¶
func (a *AuthService) ResetPassword(email string) error
func (*AuthService) SSOOnly ¶
func (a *AuthService) SSOOnly() gin.HandlerFunc
func (*AuthService) SendEmail ¶
func (a *AuthService) SendEmail(to, subject, body string) error
func (*AuthService) SetUserSession ¶
func (*AuthService) UpdatePassword ¶
func (a *AuthService) UpdatePassword(user *models.User, oldPassword, newPassword string) error
func (*AuthService) ValidatePasswordComplexity ¶
func (a *AuthService) ValidatePasswordComplexity(password string) error
func (*AuthService) ValidateResetToken ¶
func (a *AuthService) ValidateResetToken(token string) (*models.User, error)
func (*AuthService) VerifyEmail ¶
func (a *AuthService) VerifyEmail(token string) error
type Authenticator ¶
type Authenticator interface {
Authenticate(r *http.Request) (*services.HostIdentity, error)
}
Authenticator authenticates a request on behalf of a host application. It returns the user the host has signed in, or nil (and no error) when the request carries no host identity, in which case Studio's own API keys may still authenticate it. An error rejects the request.
type Config ¶
type Config struct {
DB *gorm.DB
Service services.ServiceInterface
CookieName string
CookieSecure bool
CookieDomain string
// CookiePath scopes the session cookie; empty means "/". Set it to the
// base path when Studio is served under one.
CookiePath string
ResetTokenExpiry time.Duration
SessionDuration time.Duration
FrontendURL string
CookieHTTPOnly bool
CookieSameSite http.SameSite
RegistrationAllowed bool
AdminEmail string
TestMode bool
AllowedRegisterDomains []string
TIBAPISecret string
TIBEnabled bool
OCIConfig interface{} // Holds OCI configuration for plugin security
// AllowSSOUserAPIKeys permits issuing API keys to SSO-provisioned
// users; SSOAPIKeyLiveness rejects such a key once the user has gone
// that long without an SSO login (0 = no limit). See config.Config.
AllowSSOUserAPIKeys bool
SSOAPIKeyLiveness time.Duration
// APIKeyTouchInterval throttles the api_key_last_used_at stamp (zero
// means the default); SyncAPIKeyTouch stamps on every request, on the
// request goroutine, which is what tests on a shared SQLite DB need.
APIKeyTouchInterval time.Duration
SyncAPIKeyTouch bool
// HostAuth authenticates requests for a host application Studio is
// embedded in. When set it is asked first on every request, and the
// identity it returns is turned into a Studio user by
// ProvisionHostUser. Studio's own password login, registration and SSO
// are then switched off (see LocalAccountsEnabled).
HostAuth Authenticator
ProvisionHostUser func(services.HostIdentity) (*models.User, error)
// HostLoginURL and HostLogoutURL are where the console sends a user to
// sign in or out when the host authenticates. The console fills in a
// "{return_to}" placeholder in HostLoginURL (see studio.Options.LoginURL).
HostLoginURL string
HostLogoutURL string
// CSRF, when set, replaces Studio's own CSRF protection for
// cookie-authenticated requests: a host application can apply its own.
// It must call the handler it wraps only for requests that pass.
// CSRFTokenHeader and CSRFTokenURL tell the console which header carries
// the token and where to fetch it (defaults: X-CSRF-Token and Studio's
// /csrf-token).
CSRF func(http.Handler) http.Handler
CSRFTokenHeader string
CSRFTokenURL string
// Chromeless tells the console to leave out its own top bar and
// navigation drawers, because the host application draws them.
Chromeless bool
}
func (*Config) LocalAccountsEnabled ¶
LocalAccountsEnabled reports whether Studio manages sign-in itself (passwords, registration, SSO), which it does unless a host authenticates.