procedure

package
v1.3.9 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package procedure is the stored-procedure backend of lookup: it calls the resolvespec_* functions (names from lookup.ProcNames) and keeps their p_success / p_error / p_data contract. Error texts match the ones the security package returned before the extraction.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func IsClosed

func IsClosed(err error) bool

IsClosed reports whether err indicates the *sql.DB has been closed.

Types

type Auth

type Auth struct {
	// contains filtered or unexported fields
}

Auth implements lookup.AuthStore with stored procedures.

func NewAuth

func NewAuth(run Runner, procs lookup.ProcNames) *Auth

NewAuth creates the procedure-backed AuthStore.

func (*Auth) JWTLogin

JWTLogin implements lookup.AuthStore. The password is verified inside the procedure; the hash is never returned. The token is a placeholder until JWT signing is wired in.

func (*Auth) JWTLogout

func (a *Auth) JWTLogout(ctx context.Context, req sectypes.LogoutRequest) error

JWTLogout implements lookup.AuthStore.

func (*Auth) Login

Login implements lookup.AuthStore.

func (*Auth) LoginAPIKey

func (a *Auth) LoginAPIKey(ctx context.Context, rawKey string, claims map[string]any) (*sectypes.LoginResponse, error)

LoginAPIKey implements lookup.AuthStore. Unknown, expired and inactive keys all return lookup.ErrInvalidAPIKey; the raw key is never logged.

func (*Auth) Logout

func (a *Auth) Logout(ctx context.Context, req sectypes.LogoutRequest) error

Logout implements lookup.AuthStore.

func (*Auth) Refresh

func (a *Auth) Refresh(ctx context.Context, refreshToken string) (*sectypes.LoginResponse, error)

Refresh implements lookup.AuthStore.

func (*Auth) Register

Register implements lookup.AuthStore.

func (*Auth) ResetComplete

func (a *Auth) ResetComplete(ctx context.Context, req sectypes.PasswordResetCompleteRequest) error

ResetComplete implements lookup.AuthStore.

func (*Auth) ResetRequest

ResetRequest implements lookup.AuthStore.

func (*Auth) Session

func (a *Auth) Session(ctx context.Context, token, reference string) (*sectypes.UserContext, error)

Session implements lookup.AuthStore.

func (*Auth) TouchSession

func (a *Auth) TouchSession(ctx context.Context, token string, user *sectypes.UserContext) error

TouchSession implements lookup.AuthStore.

type DB

type DB struct {
	// contains filtered or unexported fields
}

DB is a standalone Runner over a *sql.DB with an optional reconnect factory.

func NewDB

func NewDB(db *sql.DB, factory func() (*sql.DB, error), onReconnect func()) *DB

NewDB wraps db. factory (optional) is called to obtain a fresh handle when the current one is closed; onReconnect (optional) runs after a successful reconnect, e.g. to reset cached procedure probes.

func (*DB) Get

func (d *DB) Get() *sql.DB

Get returns the current handle.

func (*DB) Run

func (d *DB) Run(run func(*sql.DB) error) error

Run implements Runner.

type Keys

type Keys struct {
	// contains filtered or unexported fields
}

Keys implements lookup.KeyStore with the resolvespec_keystore_* procedures.

func NewKeys

func NewKeys(run Runner, procs lookup.ProcNames) *Keys

NewKeys creates the procedure-backed KeyStore.

func (*Keys) Create

func (k *Keys) Create(ctx context.Context, req sectypes.CreateKeyRequest, keyHash string) (*sectypes.UserKey, error)

Create implements lookup.KeyStore.

func (*Keys) Delete

func (k *Keys) Delete(ctx context.Context, userID int, keyID int64) (string, error)

Delete implements lookup.KeyStore. The procedure returns the key hash.

func (*Keys) List

func (k *Keys) List(ctx context.Context, userID int, keyType sectypes.KeyType) ([]sectypes.UserKey, error)

List implements lookup.KeyStore.

func (*Keys) Validate

func (k *Keys) Validate(ctx context.Context, keyHash string, keyType sectypes.KeyType) (*sectypes.UserKey, error)

Validate implements lookup.KeyStore.

type OAuthClients

type OAuthClients struct {
	// contains filtered or unexported fields
}

OAuthClients implements lookup.OAuthClientStore with the resolvespec_oauth_* server procedures.

func NewOAuthClients

func NewOAuthClients(run Runner, procs lookup.ProcNames) *OAuthClients

NewOAuthClients creates the procedure-backed OAuthClientStore.

func (*OAuthClients) DeleteClient

func (o *OAuthClients) DeleteClient(ctx context.Context, clientID string) error

DeleteClient implements lookup.OAuthClientStore.

func (*OAuthClients) ExchangeCode

func (o *OAuthClients) ExchangeCode(ctx context.Context, code string) (*sectypes.OAuthCode, error)

ExchangeCode implements lookup.OAuthClientStore.

func (*OAuthClients) GetClient

func (o *OAuthClients) GetClient(ctx context.Context, clientID string) (*sectypes.OAuthServerClient, error)

GetClient implements lookup.OAuthClientStore.

func (*OAuthClients) Introspect

func (o *OAuthClients) Introspect(ctx context.Context, token string) (*sectypes.OAuthTokenInfo, error)

Introspect implements lookup.OAuthClientStore.

func (*OAuthClients) RegisterClient

RegisterClient implements lookup.OAuthClientStore.

func (*OAuthClients) Revoke

func (o *OAuthClients) Revoke(ctx context.Context, token string) error

Revoke implements lookup.OAuthClientStore.

func (*OAuthClients) SaveCode

func (o *OAuthClients) SaveCode(ctx context.Context, code *sectypes.OAuthCode) error

SaveCode implements lookup.OAuthClientStore.

func (*OAuthClients) UpdateClient

func (o *OAuthClients) UpdateClient(ctx context.Context, client *sectypes.OAuthServerClient) error

UpdateClient implements lookup.OAuthClientStore.

type OAuthGrants

type OAuthGrants struct {
	// contains filtered or unexported fields
}

OAuthGrants implements lookup.OAuthGrantStore with the resolvespec_oauth_* grant procedures. Every procedure takes one jsonb request and returns (p_success, p_error, p_data). A failure that maps to a lookup sentinel carries a stable code in p_error (see the grantErrors table).

func NewOAuthGrants

func NewOAuthGrants(run Runner, procs lookup.ProcNames) *OAuthGrants

NewOAuthGrants creates the procedure-backed OAuthGrantStore.

func (*OAuthGrants) ConsumePushedRequest

func (o *OAuthGrants) ConsumePushedRequest(ctx context.Context, requestURI string) (*lookup.PushedRequest, error)

ConsumePushedRequest implements lookup.OAuthGrantStore.

func (*OAuthGrants) CreateDevice

func (o *OAuthGrants) CreateDevice(ctx context.Context, d lookup.DeviceCode) error

CreateDevice implements lookup.OAuthGrantStore.

func (*OAuthGrants) DeviceByUserCode

func (o *OAuthGrants) DeviceByUserCode(ctx context.Context, userCode string) (*lookup.DeviceCode, error)

DeviceByUserCode implements lookup.OAuthGrantStore.

func (*OAuthGrants) DeviceDecide

func (o *OAuthGrants) DeviceDecide(ctx context.Context, userCode string, approve bool, userID int, sessionToken string) error

DeviceDecide implements lookup.OAuthGrantStore.

func (*OAuthGrants) DevicePoll

func (o *OAuthGrants) DevicePoll(ctx context.Context, deviceHash string) (*lookup.DeviceCode, error)

DevicePoll implements lookup.OAuthGrantStore.

func (*OAuthGrants) GetConsent

func (o *OAuthGrants) GetConsent(ctx context.Context, userID int, clientID string) (*lookup.Consent, error)

GetConsent implements lookup.OAuthGrantStore.

func (*OAuthGrants) PeekRefresh

func (o *OAuthGrants) PeekRefresh(ctx context.Context, hash string) (*lookup.RefreshToken, error)

PeekRefresh implements lookup.OAuthGrantStore.

func (*OAuthGrants) RevokeConsent

func (o *OAuthGrants) RevokeConsent(ctx context.Context, userID int, clientID string) error

RevokeConsent implements lookup.OAuthGrantStore.

func (*OAuthGrants) RevokeRefreshBySession

func (o *OAuthGrants) RevokeRefreshBySession(ctx context.Context, sessionToken string) error

RevokeRefreshBySession implements lookup.OAuthGrantStore.

func (*OAuthGrants) RevokeRefreshFamily

func (o *OAuthGrants) RevokeRefreshFamily(ctx context.Context, familyID string) error

RevokeRefreshFamily implements lookup.OAuthGrantStore.

func (*OAuthGrants) RotateRefresh

func (o *OAuthGrants) RotateRefresh(ctx context.Context, oldHash string, next lookup.RefreshToken) (*lookup.RefreshToken, error)

RotateRefresh implements lookup.OAuthGrantStore.

func (*OAuthGrants) SaveConsent

func (o *OAuthGrants) SaveConsent(ctx context.Context, c lookup.Consent) error

SaveConsent implements lookup.OAuthGrantStore.

func (*OAuthGrants) SavePushedRequest

func (o *OAuthGrants) SavePushedRequest(ctx context.Context, r lookup.PushedRequest) error

SavePushedRequest implements lookup.OAuthGrantStore.

func (*OAuthGrants) SaveRefresh

func (o *OAuthGrants) SaveRefresh(ctx context.Context, t lookup.RefreshToken) error

SaveRefresh implements lookup.OAuthGrantStore.

func (*OAuthGrants) SeenJTI

func (o *OAuthGrants) SeenJTI(ctx context.Context, key string, expires time.Time) (bool, error)

SeenJTI implements lookup.OAuthGrantStore.

type OAuthUsers

type OAuthUsers struct {
	// contains filtered or unexported fields
}

OAuthUsers implements lookup.OAuthUserStore with the resolvespec_oauth_* procedures.

func NewOAuthUsers

func NewOAuthUsers(run Runner, procs lookup.ProcNames) *OAuthUsers

NewOAuthUsers creates the procedure-backed OAuthUserStore.

func (*OAuthUsers) CreateSession

func (o *OAuthUsers) CreateSession(ctx context.Context, s lookup.OAuthSession) error

CreateSession implements lookup.OAuthUserStore.

func (*OAuthUsers) GetByRefreshToken

func (o *OAuthUsers) GetByRefreshToken(ctx context.Context, refreshToken string) (*lookup.OAuthRefreshSession, error)

GetByRefreshToken implements lookup.OAuthUserStore.

func (*OAuthUsers) GetOrCreateUser

func (o *OAuthUsers) GetOrCreateUser(ctx context.Context, user *sectypes.UserContext, provider string) (int, error)

GetOrCreateUser implements lookup.OAuthUserStore.

func (*OAuthUsers) GetUser

func (o *OAuthUsers) GetUser(ctx context.Context, userID int) (*sectypes.UserContext, error)

GetUser implements lookup.OAuthUserStore.

func (*OAuthUsers) UpdateRefreshToken

func (o *OAuthUsers) UpdateRefreshToken(ctx context.Context, userID int, oldRefreshToken, newSessionToken, newAccessToken, newRefreshToken string, expiresAt time.Time) error

UpdateRefreshToken implements lookup.OAuthUserStore.

type Passkey

type Passkey struct {
	// contains filtered or unexported fields
}

Passkey implements lookup.PasskeyStore with the resolvespec_passkey_* procedures. Credential ids cross the lookup interface as base64 text; the procedures that take a bytea credential id receive the decoded bytes.

func NewPasskey

func NewPasskey(run Runner, procs lookup.ProcNames) *Passkey

NewPasskey creates the procedure-backed PasskeyStore.

func (*Passkey) ByUsername

func (p *Passkey) ByUsername(ctx context.Context, username string) (int, []lookup.PasskeyCredentialRef, error)

ByUsername implements lookup.PasskeyStore.

func (*Passkey) Delete

func (p *Passkey) Delete(ctx context.Context, userID int, credentialID string) error

Delete implements lookup.PasskeyStore.

func (*Passkey) Get

func (p *Passkey) Get(ctx context.Context, credentialID string) (userID int, signCount uint32, err error)

Get implements lookup.PasskeyStore.

func (*Passkey) List

func (p *Passkey) List(ctx context.Context, userID int) ([]sectypes.PasskeyCredential, error)

List implements lookup.PasskeyStore.

func (*Passkey) Login

func (p *Passkey) Login(ctx context.Context, userID int, claims map[string]any) (*sectypes.LoginResponse, error)

Login implements lookup.PasskeyStore: it creates the session for a user whose passkey assertion was already verified.

func (*Passkey) Rename

func (p *Passkey) Rename(ctx context.Context, userID int, credentialID, name string) error

Rename implements lookup.PasskeyStore.

func (*Passkey) Store

Store implements lookup.PasskeyStore.

func (*Passkey) UpdateCounter

func (p *Passkey) UpdateCounter(ctx context.Context, credentialID string, newCounter uint32) (bool, error)

UpdateCounter implements lookup.PasskeyStore. Like the code it replaces, it only reports an error when the query itself fails; the procedure's success flag is not checked.

type Policy

type Policy struct {
	// contains filtered or unexported fields
}

Policy implements lookup.PolicyStore with the column and row security procedures.

func NewPolicy

func NewPolicy(run Runner, procs lookup.ProcNames) *Policy

NewPolicy creates the procedure-backed PolicyStore.

func (*Policy) ColumnSecurity

func (p *Policy) ColumnSecurity(ctx context.Context, userID int, schema, table string) ([]sectypes.ColumnSecurity, error)

ColumnSecurity implements lookup.PolicyStore.

func (*Policy) RowSecurity

func (p *Policy) RowSecurity(ctx context.Context, userRef any, schema, table string) (sectypes.RowSecurity, error)

RowSecurity implements lookup.PolicyStore. userRef is unwrapped to a scalar user id because the procedure's p_user_id is an integer.

type RunFunc

type RunFunc func(run func(*sql.DB) error) error

RunFunc adapts a function to Runner. The security package passes its own reconnecting helper this way.

func (RunFunc) Run

func (f RunFunc) Run(run func(*sql.DB) error) error

Run implements Runner.

type Runner

type Runner interface {
	Run(run func(*sql.DB) error) error
}

Runner runs a database operation, reconnecting once when the *sql.DB has been closed.

type TOTP

type TOTP struct {
	// contains filtered or unexported fields
}

TOTP implements lookup.TOTPStore with the resolvespec_totp_* procedures.

func NewTOTP

func NewTOTP(run Runner, procs lookup.ProcNames) *TOTP

NewTOTP creates the procedure-backed TOTPStore.

func (*TOTP) Disable

func (t *TOTP) Disable(ctx context.Context, userID int) error

Disable implements lookup.TOTPStore.

func (*TOTP) Enable

func (t *TOTP) Enable(ctx context.Context, userID int, secret string, hashedCodes []string) error

Enable implements lookup.TOTPStore.

func (*TOTP) RegenerateBackupCodes

func (t *TOTP) RegenerateBackupCodes(ctx context.Context, userID int, hashedCodes []string) error

RegenerateBackupCodes implements lookup.TOTPStore.

func (*TOTP) Secret

func (t *TOTP) Secret(ctx context.Context, userID int) (string, error)

Secret implements lookup.TOTPStore.

func (*TOTP) Status

func (t *TOTP) Status(ctx context.Context, userID int) (bool, error)

Status implements lookup.TOTPStore.

func (*TOTP) ValidateBackupCode

func (t *TOTP) ValidateBackupCode(ctx context.Context, userID int, codeHash string) (bool, error)

ValidateBackupCode implements lookup.TOTPStore. A failure without a message means "not valid", not an error.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL