Documentation
¶
Overview ¶
Package procedure is the stored-procedure backend of lookup: it calls the resolvespec_* functions (names from lookup.ProcNames) and keeps their p_success / p_error / p_data contract. Error texts match the ones the security package returned before the extraction.
Index ¶
- func IsClosed(err error) bool
- type Auth
- func (a *Auth) JWTLogin(ctx context.Context, req sectypes.LoginRequest) (*sectypes.LoginResponse, error)
- func (a *Auth) JWTLogout(ctx context.Context, req sectypes.LogoutRequest) error
- func (a *Auth) Login(ctx context.Context, req sectypes.LoginRequest) (*sectypes.LoginResponse, error)
- func (a *Auth) LoginAPIKey(ctx context.Context, rawKey string, claims map[string]any) (*sectypes.LoginResponse, error)
- func (a *Auth) Logout(ctx context.Context, req sectypes.LogoutRequest) error
- func (a *Auth) Refresh(ctx context.Context, refreshToken string) (*sectypes.LoginResponse, error)
- func (a *Auth) Register(ctx context.Context, req sectypes.RegisterRequest) (*sectypes.LoginResponse, error)
- func (a *Auth) ResetComplete(ctx context.Context, req sectypes.PasswordResetCompleteRequest) error
- func (a *Auth) ResetRequest(ctx context.Context, req sectypes.PasswordResetRequest) (*sectypes.PasswordResetResponse, error)
- func (a *Auth) Session(ctx context.Context, token, reference string) (*sectypes.UserContext, error)
- func (a *Auth) TouchSession(ctx context.Context, token string, user *sectypes.UserContext) error
- type DB
- type Keys
- func (k *Keys) Create(ctx context.Context, req sectypes.CreateKeyRequest, keyHash string) (*sectypes.UserKey, error)
- func (k *Keys) Delete(ctx context.Context, userID int, keyID int64) (string, error)
- func (k *Keys) List(ctx context.Context, userID int, keyType sectypes.KeyType) ([]sectypes.UserKey, error)
- func (k *Keys) Validate(ctx context.Context, keyHash string, keyType sectypes.KeyType) (*sectypes.UserKey, error)
- type OAuthClients
- func (o *OAuthClients) DeleteClient(ctx context.Context, clientID string) error
- func (o *OAuthClients) ExchangeCode(ctx context.Context, code string) (*sectypes.OAuthCode, error)
- func (o *OAuthClients) GetClient(ctx context.Context, clientID string) (*sectypes.OAuthServerClient, error)
- func (o *OAuthClients) Introspect(ctx context.Context, token string) (*sectypes.OAuthTokenInfo, error)
- func (o *OAuthClients) RegisterClient(ctx context.Context, client *sectypes.OAuthServerClient) (*sectypes.OAuthServerClient, error)
- func (o *OAuthClients) Revoke(ctx context.Context, token string) error
- func (o *OAuthClients) SaveCode(ctx context.Context, code *sectypes.OAuthCode) error
- func (o *OAuthClients) UpdateClient(ctx context.Context, client *sectypes.OAuthServerClient) error
- type OAuthGrants
- func (o *OAuthGrants) ConsumePushedRequest(ctx context.Context, requestURI string) (*lookup.PushedRequest, error)
- func (o *OAuthGrants) CreateDevice(ctx context.Context, d lookup.DeviceCode) error
- func (o *OAuthGrants) DeviceByUserCode(ctx context.Context, userCode string) (*lookup.DeviceCode, error)
- func (o *OAuthGrants) DeviceDecide(ctx context.Context, userCode string, approve bool, userID int, ...) error
- func (o *OAuthGrants) DevicePoll(ctx context.Context, deviceHash string) (*lookup.DeviceCode, error)
- func (o *OAuthGrants) GetConsent(ctx context.Context, userID int, clientID string) (*lookup.Consent, error)
- func (o *OAuthGrants) PeekRefresh(ctx context.Context, hash string) (*lookup.RefreshToken, error)
- func (o *OAuthGrants) RevokeConsent(ctx context.Context, userID int, clientID string) error
- func (o *OAuthGrants) RevokeRefreshBySession(ctx context.Context, sessionToken string) error
- func (o *OAuthGrants) RevokeRefreshFamily(ctx context.Context, familyID string) error
- func (o *OAuthGrants) RotateRefresh(ctx context.Context, oldHash string, next lookup.RefreshToken) (*lookup.RefreshToken, error)
- func (o *OAuthGrants) SaveConsent(ctx context.Context, c lookup.Consent) error
- func (o *OAuthGrants) SavePushedRequest(ctx context.Context, r lookup.PushedRequest) error
- func (o *OAuthGrants) SaveRefresh(ctx context.Context, t lookup.RefreshToken) error
- func (o *OAuthGrants) SeenJTI(ctx context.Context, key string, expires time.Time) (bool, error)
- type OAuthUsers
- func (o *OAuthUsers) CreateSession(ctx context.Context, s lookup.OAuthSession) error
- func (o *OAuthUsers) GetByRefreshToken(ctx context.Context, refreshToken string) (*lookup.OAuthRefreshSession, error)
- func (o *OAuthUsers) GetOrCreateUser(ctx context.Context, user *sectypes.UserContext, provider string) (int, error)
- func (o *OAuthUsers) GetUser(ctx context.Context, userID int) (*sectypes.UserContext, error)
- func (o *OAuthUsers) UpdateRefreshToken(ctx context.Context, userID int, ...) error
- type Passkey
- func (p *Passkey) ByUsername(ctx context.Context, username string) (int, []lookup.PasskeyCredentialRef, error)
- func (p *Passkey) Delete(ctx context.Context, userID int, credentialID string) error
- func (p *Passkey) Get(ctx context.Context, credentialID string) (userID int, signCount uint32, err error)
- func (p *Passkey) List(ctx context.Context, userID int) ([]sectypes.PasskeyCredential, error)
- func (p *Passkey) Login(ctx context.Context, userID int, claims map[string]any) (*sectypes.LoginResponse, error)
- func (p *Passkey) Rename(ctx context.Context, userID int, credentialID, name string) error
- func (p *Passkey) Store(ctx context.Context, rec lookup.PasskeyCredentialRecord) (int64, error)
- func (p *Passkey) UpdateCounter(ctx context.Context, credentialID string, newCounter uint32) (bool, error)
- type Policy
- type RunFunc
- type Runner
- type TOTP
- func (t *TOTP) Disable(ctx context.Context, userID int) error
- func (t *TOTP) Enable(ctx context.Context, userID int, secret string, hashedCodes []string) error
- func (t *TOTP) RegenerateBackupCodes(ctx context.Context, userID int, hashedCodes []string) error
- func (t *TOTP) Secret(ctx context.Context, userID int) (string, error)
- func (t *TOTP) Status(ctx context.Context, userID int) (bool, error)
- func (t *TOTP) ValidateBackupCode(ctx context.Context, userID int, codeHash string) (bool, error)
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
Types ¶
type Auth ¶
type Auth struct {
// contains filtered or unexported fields
}
Auth implements lookup.AuthStore with stored procedures.
func (*Auth) JWTLogin ¶
func (a *Auth) JWTLogin(ctx context.Context, req sectypes.LoginRequest) (*sectypes.LoginResponse, error)
JWTLogin implements lookup.AuthStore. The password is verified inside the procedure; the hash is never returned. The token is a placeholder until JWT signing is wired in.
func (*Auth) Login ¶
func (a *Auth) Login(ctx context.Context, req sectypes.LoginRequest) (*sectypes.LoginResponse, error)
Login implements lookup.AuthStore.
func (*Auth) LoginAPIKey ¶
func (a *Auth) LoginAPIKey(ctx context.Context, rawKey string, claims map[string]any) (*sectypes.LoginResponse, error)
LoginAPIKey implements lookup.AuthStore. Unknown, expired and inactive keys all return lookup.ErrInvalidAPIKey; the raw key is never logged.
func (*Auth) Register ¶
func (a *Auth) Register(ctx context.Context, req sectypes.RegisterRequest) (*sectypes.LoginResponse, error)
Register implements lookup.AuthStore.
func (*Auth) ResetComplete ¶
ResetComplete implements lookup.AuthStore.
func (*Auth) ResetRequest ¶
func (a *Auth) ResetRequest(ctx context.Context, req sectypes.PasswordResetRequest) (*sectypes.PasswordResetResponse, error)
ResetRequest implements lookup.AuthStore.
func (*Auth) TouchSession ¶
TouchSession implements lookup.AuthStore.
type DB ¶
type DB struct {
// contains filtered or unexported fields
}
DB is a standalone Runner over a *sql.DB with an optional reconnect factory.
type Keys ¶
type Keys struct {
// contains filtered or unexported fields
}
Keys implements lookup.KeyStore with the resolvespec_keystore_* procedures.
func (*Keys) Create ¶
func (k *Keys) Create(ctx context.Context, req sectypes.CreateKeyRequest, keyHash string) (*sectypes.UserKey, error)
Create implements lookup.KeyStore.
type OAuthClients ¶
type OAuthClients struct {
// contains filtered or unexported fields
}
OAuthClients implements lookup.OAuthClientStore with the resolvespec_oauth_* server procedures.
func NewOAuthClients ¶
func NewOAuthClients(run Runner, procs lookup.ProcNames) *OAuthClients
NewOAuthClients creates the procedure-backed OAuthClientStore.
func (*OAuthClients) DeleteClient ¶
func (o *OAuthClients) DeleteClient(ctx context.Context, clientID string) error
DeleteClient implements lookup.OAuthClientStore.
func (*OAuthClients) ExchangeCode ¶
ExchangeCode implements lookup.OAuthClientStore.
func (*OAuthClients) GetClient ¶
func (o *OAuthClients) GetClient(ctx context.Context, clientID string) (*sectypes.OAuthServerClient, error)
GetClient implements lookup.OAuthClientStore.
func (*OAuthClients) Introspect ¶
func (o *OAuthClients) Introspect(ctx context.Context, token string) (*sectypes.OAuthTokenInfo, error)
Introspect implements lookup.OAuthClientStore.
func (*OAuthClients) RegisterClient ¶
func (o *OAuthClients) RegisterClient(ctx context.Context, client *sectypes.OAuthServerClient) (*sectypes.OAuthServerClient, error)
RegisterClient implements lookup.OAuthClientStore.
func (*OAuthClients) Revoke ¶
func (o *OAuthClients) Revoke(ctx context.Context, token string) error
Revoke implements lookup.OAuthClientStore.
func (*OAuthClients) UpdateClient ¶
func (o *OAuthClients) UpdateClient(ctx context.Context, client *sectypes.OAuthServerClient) error
UpdateClient implements lookup.OAuthClientStore.
type OAuthGrants ¶
type OAuthGrants struct {
// contains filtered or unexported fields
}
OAuthGrants implements lookup.OAuthGrantStore with the resolvespec_oauth_* grant procedures. Every procedure takes one jsonb request and returns (p_success, p_error, p_data). A failure that maps to a lookup sentinel carries a stable code in p_error (see the grantErrors table).
func NewOAuthGrants ¶
func NewOAuthGrants(run Runner, procs lookup.ProcNames) *OAuthGrants
NewOAuthGrants creates the procedure-backed OAuthGrantStore.
func (*OAuthGrants) ConsumePushedRequest ¶
func (o *OAuthGrants) ConsumePushedRequest(ctx context.Context, requestURI string) (*lookup.PushedRequest, error)
ConsumePushedRequest implements lookup.OAuthGrantStore.
func (*OAuthGrants) CreateDevice ¶
func (o *OAuthGrants) CreateDevice(ctx context.Context, d lookup.DeviceCode) error
CreateDevice implements lookup.OAuthGrantStore.
func (*OAuthGrants) DeviceByUserCode ¶
func (o *OAuthGrants) DeviceByUserCode(ctx context.Context, userCode string) (*lookup.DeviceCode, error)
DeviceByUserCode implements lookup.OAuthGrantStore.
func (*OAuthGrants) DeviceDecide ¶
func (o *OAuthGrants) DeviceDecide(ctx context.Context, userCode string, approve bool, userID int, sessionToken string) error
DeviceDecide implements lookup.OAuthGrantStore.
func (*OAuthGrants) DevicePoll ¶
func (o *OAuthGrants) DevicePoll(ctx context.Context, deviceHash string) (*lookup.DeviceCode, error)
DevicePoll implements lookup.OAuthGrantStore.
func (*OAuthGrants) GetConsent ¶
func (o *OAuthGrants) GetConsent(ctx context.Context, userID int, clientID string) (*lookup.Consent, error)
GetConsent implements lookup.OAuthGrantStore.
func (*OAuthGrants) PeekRefresh ¶
func (o *OAuthGrants) PeekRefresh(ctx context.Context, hash string) (*lookup.RefreshToken, error)
PeekRefresh implements lookup.OAuthGrantStore.
func (*OAuthGrants) RevokeConsent ¶
RevokeConsent implements lookup.OAuthGrantStore.
func (*OAuthGrants) RevokeRefreshBySession ¶
func (o *OAuthGrants) RevokeRefreshBySession(ctx context.Context, sessionToken string) error
RevokeRefreshBySession implements lookup.OAuthGrantStore.
func (*OAuthGrants) RevokeRefreshFamily ¶
func (o *OAuthGrants) RevokeRefreshFamily(ctx context.Context, familyID string) error
RevokeRefreshFamily implements lookup.OAuthGrantStore.
func (*OAuthGrants) RotateRefresh ¶
func (o *OAuthGrants) RotateRefresh(ctx context.Context, oldHash string, next lookup.RefreshToken) (*lookup.RefreshToken, error)
RotateRefresh implements lookup.OAuthGrantStore.
func (*OAuthGrants) SaveConsent ¶
SaveConsent implements lookup.OAuthGrantStore.
func (*OAuthGrants) SavePushedRequest ¶
func (o *OAuthGrants) SavePushedRequest(ctx context.Context, r lookup.PushedRequest) error
SavePushedRequest implements lookup.OAuthGrantStore.
func (*OAuthGrants) SaveRefresh ¶
func (o *OAuthGrants) SaveRefresh(ctx context.Context, t lookup.RefreshToken) error
SaveRefresh implements lookup.OAuthGrantStore.
type OAuthUsers ¶
type OAuthUsers struct {
// contains filtered or unexported fields
}
OAuthUsers implements lookup.OAuthUserStore with the resolvespec_oauth_* procedures.
func NewOAuthUsers ¶
func NewOAuthUsers(run Runner, procs lookup.ProcNames) *OAuthUsers
NewOAuthUsers creates the procedure-backed OAuthUserStore.
func (*OAuthUsers) CreateSession ¶
func (o *OAuthUsers) CreateSession(ctx context.Context, s lookup.OAuthSession) error
CreateSession implements lookup.OAuthUserStore.
func (*OAuthUsers) GetByRefreshToken ¶
func (o *OAuthUsers) GetByRefreshToken(ctx context.Context, refreshToken string) (*lookup.OAuthRefreshSession, error)
GetByRefreshToken implements lookup.OAuthUserStore.
func (*OAuthUsers) GetOrCreateUser ¶
func (o *OAuthUsers) GetOrCreateUser(ctx context.Context, user *sectypes.UserContext, provider string) (int, error)
GetOrCreateUser implements lookup.OAuthUserStore.
func (*OAuthUsers) GetUser ¶
func (o *OAuthUsers) GetUser(ctx context.Context, userID int) (*sectypes.UserContext, error)
GetUser implements lookup.OAuthUserStore.
func (*OAuthUsers) UpdateRefreshToken ¶
func (o *OAuthUsers) UpdateRefreshToken(ctx context.Context, userID int, oldRefreshToken, newSessionToken, newAccessToken, newRefreshToken string, expiresAt time.Time) error
UpdateRefreshToken implements lookup.OAuthUserStore.
type Passkey ¶
type Passkey struct {
// contains filtered or unexported fields
}
Passkey implements lookup.PasskeyStore with the resolvespec_passkey_* procedures. Credential ids cross the lookup interface as base64 text; the procedures that take a bytea credential id receive the decoded bytes.
func NewPasskey ¶
NewPasskey creates the procedure-backed PasskeyStore.
func (*Passkey) ByUsername ¶
func (p *Passkey) ByUsername(ctx context.Context, username string) (int, []lookup.PasskeyCredentialRef, error)
ByUsername implements lookup.PasskeyStore.
func (*Passkey) Get ¶
func (p *Passkey) Get(ctx context.Context, credentialID string) (userID int, signCount uint32, err error)
Get implements lookup.PasskeyStore.
func (*Passkey) Login ¶
func (p *Passkey) Login(ctx context.Context, userID int, claims map[string]any) (*sectypes.LoginResponse, error)
Login implements lookup.PasskeyStore: it creates the session for a user whose passkey assertion was already verified.
func (*Passkey) UpdateCounter ¶
func (p *Passkey) UpdateCounter(ctx context.Context, credentialID string, newCounter uint32) (bool, error)
UpdateCounter implements lookup.PasskeyStore. Like the code it replaces, it only reports an error when the query itself fails; the procedure's success flag is not checked.
type Policy ¶
type Policy struct {
// contains filtered or unexported fields
}
Policy implements lookup.PolicyStore with the column and row security procedures.
func (*Policy) ColumnSecurity ¶
func (p *Policy) ColumnSecurity(ctx context.Context, userID int, schema, table string) ([]sectypes.ColumnSecurity, error)
ColumnSecurity implements lookup.PolicyStore.
func (*Policy) RowSecurity ¶
func (p *Policy) RowSecurity(ctx context.Context, userRef any, schema, table string) (sectypes.RowSecurity, error)
RowSecurity implements lookup.PolicyStore. userRef is unwrapped to a scalar user id because the procedure's p_user_id is an integer.
type RunFunc ¶
RunFunc adapts a function to Runner. The security package passes its own reconnecting helper this way.
type TOTP ¶
type TOTP struct {
// contains filtered or unexported fields
}
TOTP implements lookup.TOTPStore with the resolvespec_totp_* procedures.
func (*TOTP) RegenerateBackupCodes ¶
RegenerateBackupCodes implements lookup.TOTPStore.