Documentation
¶
Index ¶
- Constants
- func AgentIDFromContext(ctx interface{ ... }) uuid.UUID
- func AgentMiddleware(jwtSecret string) func(http.Handler) http.Handler
- func CheckPassword(hash, password string) error
- func HashPassword(password string) (string, error)
- func IssueAgentToken(secret string, agentID uuid.UUID) (string, error)
- func IssueRefreshToken(secret string, userID uuid.UUID, email, tenantRole string) (string, error)
- func IssueToken(secret string, userID uuid.UUID, email, tenantRole string) (string, error)
- func IssueTokenWithDuration(secret string, userID uuid.UUID, email, tenantRole string, ...) (string, error)
- func Middleware(jwtSecret string) func(http.Handler) http.Handler
- func RequireTenantRole(minRole string) func(http.Handler) http.Handler
- func RoleAtLeast(userRole, minRole string) bool
- func UserIDFromContext(ctx context.Context) uuid.UUID
- type AgentClaims
- type Claims
Constants ¶
const ( AccessTokenDuration = 15 * time.Minute RefreshTokenDuration = 7 * 24 * time.Hour )
Variables ¶
This section is empty.
Functions ¶
func AgentIDFromContext ¶
AgentIDFromContext returns the agent UUID from context, set by AgentMiddleware.
func AgentMiddleware ¶
AgentMiddleware validates the agent JWT Bearer token and injects AgentClaims into context.
func CheckPassword ¶
CheckPassword compares a plaintext password with a bcrypt hash. Returns nil on success, error on mismatch.
func HashPassword ¶
HashPassword hashes a plaintext password using bcrypt.
func IssueAgentToken ¶
IssueAgentToken creates a signed JWT for an agent container (100-year expiry).
func IssueRefreshToken ¶
IssueRefreshToken creates a signed refresh token (7 days).
func IssueToken ¶
IssueToken creates a signed access token (15 min).
func IssueTokenWithDuration ¶
func IssueTokenWithDuration(secret string, userID uuid.UUID, email, tenantRole string, duration time.Duration) (string, error)
IssueTokenWithDuration creates a signed token with a custom duration.
func Middleware ¶
Middleware validates the JWT Bearer token and injects claims into context. It returns 401 for missing, invalid, or expired tokens.
func RequireTenantRole ¶
RequireTenantRole returns middleware that checks the user has at least the given role. Uses hierarchy: admin > manager > user. Returns 403 if not authorized.
func RoleAtLeast ¶
RoleAtLeast returns true if the user's role is >= the minimum required role.
Types ¶
type AgentClaims ¶
type AgentClaims struct {
jwt.RegisteredClaims
AgentID string `json:"agent_id"`
}
AgentClaims are the JWT claims for agent tokens.
func ValidateAgentToken ¶
func ValidateAgentToken(secret, tokenString string) (*AgentClaims, error)
ValidateAgentToken validates a JWT and returns the agent claims. Rejects tokens that do not have an AgentID claim.
type Claims ¶
type Claims struct {
jwt.RegisteredClaims
Email string `json:"email"`
TenantRole string `json:"tenant_role"`
}
Claims are the JWT claims for Airlock tokens.
func ClaimsFromContext ¶
ClaimsFromContext retrieves the JWT claims from the context.
func ValidateToken ¶
ValidateToken validates a JWT and returns the claims.