auth

package module
v0.0.8 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jan 12, 2021 License: Apache-2.0 Imports: 17 Imported by: 0

README

auth

Authentication Package

Documentation

Overview

Package auth is a authentication helper that supports multiple types of applications.

Index

Constants

View Source
const (
	// BcryptDefaultCost is the Bcrypt Default Cost where the performace is optimal
	BcryptDefaultCost = bcrypt.DefaultCost
	// BcryptMaxCost is the Bcrypt Maximum Cost with Longest Time
	BcryptMaxCost = bcrypt.MaxCost
	// BcryptMinCost is the Bcrypt Minimum Cost with Shortest time
	BcryptMinCost = bcrypt.MinCost
	// MethodMD5 describes the MD5 Hashing Algorithm
	MethodMD5 = "MD5"
	// MethodSHA1 describes the SHA1 Hashing Algorithm
	MethodSHA1 = "SHA1"
	// MethodSHA224 describes the SHA224 Hashing Algorithm
	MethodSHA224 = "SHA224"
	// MethodSHA256 describes the SHA256 Hashing Algorithm
	MethodSHA256 = "SHA256"
	// MethodSHA384 describes the SHA384 Hashing Algorithm
	MethodSHA384 = "SHA384"
	// MethodSHA512 describes the SHA512 Hashing Algorithm
	MethodSHA512 = "SHA512"
	// MethodBcrypt describes the bcrypt Hashing Algorithm
	MethodBcrypt = "bcrypt"
)
View Source
const (
	// Pbkdf2MinSize defines the minimum size of the Salt and Output
	Pbkdf2MinSize = 8
	// Pbkdf2MinRounds defines the minimum number of iterations for the
	// PBKDF2 key derivation process
	Pbkdf2MinRounds = 8
)
View Source
const JWTDefaultDuration = 1 * time.Minute

JWTDefaultDuration defines the default duration for a Token

View Source
const JWTDefaultIDSize int = 32

JWTDefaultIDSize defines the default size for the JWT ID

View Source
const Pbkdf2RoundsSize int = 8

Pbkdf2RoundsSize is the Size of the Encoded number of rounds in a byte array

View Source
const Pbkdf2SaltSize int = 8

Pbkdf2SaltSize is the minimum recommended size of the Salt used for PBKDF2

Variables

View Source
var (
	Md5    *hashFn
	Sha1   *hashFn
	Sha224 *hashFn
	Sha256 *hashFn
	Sha384 *hashFn
	Sha512 *hashFn
	Bcrypt *bcryptFn
)

List of Hash Functions

View Source
var ErrNotImplemented = fmt.Errorf("error functionality not implemented yet")

ErrNotImplemented occurs when an Un-implemented feature is called on

View Source
var ErrNotInitialized = fmt.Errorf("error this construct is not initialized")

ErrNotInitialized occurs when an Authentication process or function tries to access an un-initialized data parameter or construct.

View Source
var ErrNotSupported = fmt.Errorf("error the option or operation is not supported")

ErrNotSupported occurs when a particular feature is not implemented or

logically not supported in the current context
View Source
var ErrParameter = fmt.Errorf("error in supplied parameters")

ErrParameter occurs when there are issues with the supplied parameter in any function.

Functions

func CheckPbkdf2HS1 added in v0.0.5

func CheckPbkdf2HS1(key []byte, derivedKey []byte, salt []byte, rounds int) error

CheckPbkdf2HS1 check the PBKDF2 HMAC-SHA1 Key with an derived key

func CheckPbkdf2HS256 added in v0.0.5

func CheckPbkdf2HS256(key []byte, derivedKey []byte, salt []byte, rounds int) error

CheckPbkdf2HS256 check the PBKDF2 HMAC-SHA256 Key with an derived key

func CheckPbkdf2HS512 added in v0.0.5

func CheckPbkdf2HS512(key []byte, derivedKey []byte, salt []byte, rounds int) error

CheckPbkdf2HS512 check the PBKDF2 HMAC-SHA512 Key with an derived key

func Decode added in v0.0.6

func Decode(f *EncodeIt, value string) ([]byte, error)

Decode is the Generic DecodeFromString function for all encoded values supported

func Digest added in v0.0.6

func Digest(d DigestIt, data []byte, opts ...DigestOptions) ([]byte, error)

Digest is the generic function for obtaining various type of HASH function operations on the data

func Encode added in v0.0.6

func Encode(f *EncodeIt, data []byte) string

Encode is Generic EncodeToString function for All byte Arrays

func GetRandom added in v0.0.5

func GetRandom(size int) ([]byte, error)

GetRandom returns a cryptographically safe randome numbers byte array with the size specified

func PasswordCheck added in v0.0.8

func PasswordCheck(d DigestIt, pass string, dig []byte, opts ...DigestOptions) error

PasswordCheck function is used to verify the password against the precalculated digest.

func PasswordHash added in v0.0.2

func PasswordHash(d DigestIt, pass string, opts ...DigestOptions) ([]byte, error)

PasswordHash is used to generated cryptographically secure digest from the supplied password and also verify the digest.

func Pbkdf2 added in v0.0.8

func Pbkdf2(password []byte, d DigestIt, opt ...Pbkdf2Options) (
	result []byte,
	salt []byte,
	err error,
)

Pbkdf2 function performs the PBKDF2 operation with given optional functions

func Pbkdf2HS1 added in v0.0.5

func Pbkdf2HS1(key []byte, rounds int) (derivedKey []byte, salt []byte, err error)

Pbkdf2HS1 perform PBKDF2 Key Derivation using HMAC-SHA1

func Pbkdf2HS256 added in v0.0.5

func Pbkdf2HS256(key []byte, rounds int) (derivedKey []byte, salt []byte, err error)

Pbkdf2HS256 perform PBKDF2 Key Derivation using HMAC-SHA256

func Pbkdf2HS512 added in v0.0.5

func Pbkdf2HS512(key []byte, rounds int) (derivedKey []byte, salt []byte, err error)

Pbkdf2HS512 perform PBKDF2 Key Derivation using HMAC-SHA512

func RegisterDigestFunction added in v0.0.6

func RegisterDigestFunction(name string, f DigestIt)

RegisterDigestFunction adds the specific Hash generation functions in the global list. It is typically run during init() stage.

func RegisterEncoder added in v0.0.6

func RegisterEncoder(f *EncodeIt)

RegisterEncoder updates the list of Encoders available. This is typically called during init() stage.

func RegisterJwtMethod added in v0.0.6

func RegisterJwtMethod(name string, f func() JwtMethod)

RegisterJwtMethod registers a given Method name and a factory function for registering into the list JWT processing methods. This is only called during init.

func UUIDv4 added in v0.0.6

func UUIDv4() (string, error)

UUIDv4 function helps to generate UUID using V4 algorithm

Types

type Auth

type Auth interface {

	// Create function generates the Authentication Entity by processing
	// incoming data and the specific 'bias'.
	Create(data []byte, bias interface{}) (output []byte, err error)

	// Verify function checks the Authentication Entity by processing
	// it with the optional incoming 'bias'. It also recovers the original
	// 'data' and 'bias' used to create the Authentication Entity.
	Verify(value []byte, bias interface{}) (data []byte, iBias interface{}, err error)

	// Set function configures the Authentication Entity creation and
	// verification process. It also accepts the static "Key" that needs
	// to be employed while processing the Authentication Entity.
	Set(method string, key interface{}) error
}

Auth is the generic interface that would be implemented by the various authentication algorithms and classifications.

The term "Authentication Entity" refers to a token, pass, or a Unique piece of information that provides Identity, and Authorization status of the bearer.

type DigestIt added in v0.0.6

type DigestIt interface {

	// Name Returns the Name in String for the given Hash Function
	Name() string

	// Get function takes in the byte array of arbitrary Size and
	// process it into a digest of fix size
	Get([]byte) ([]byte, error)

	// Auth Interface is Implemented here
	Auth
}

DigestIt interface defines the way by which Hash function coverts byte array of arbitrary size to a byte array of a fixed size called the "hash value", "hash", or "message digest"

func GetDigestFunction added in v0.0.6

func GetDigestFunction(name string) (f DigestIt)

GetDigestFunction fetches the respective Hash generation function using its pre registed name.

type DigestOptions added in v0.0.6

type DigestOptions func(DigestIt) DigestIt

DigestOptions provides a functional Option for attribute modification functions

func WithBcryptCost added in v0.0.6

func WithBcryptCost(cost int) DigestOptions

WithBcryptCost helps to implement Alternative Bcrypt operation

func WithDigest added in v0.0.8

func WithDigest(digest []byte) DigestOptions

WithDigest helps to implement Verification as part of Digest operations

func WithHMACKey added in v0.0.6

func WithHMACKey(key []byte) DigestOptions

WithHMACKey helps to implement HMAC operation

type EncodeIt added in v0.0.6

type EncodeIt struct {
	Name string
	// To(EncodeToString) converts the Supplied byte array to the specific
	// encode Format string
	To func(src []byte) string

	// From(DecodeString) converts the Supplied string back to its byte array form
	From func(s string) ([]byte, error)
}

EncodeIt is the String format encode function for byte Array encoders

var (
	Hex       *EncodeIt
	Base64    *EncodeIt
	Base64URL *EncodeIt
)

List of Encoders Supported

func GetEncoder added in v0.0.6

func GetEncoder(name string) (f *EncodeIt)

GetEncoder fetches the specific encoder from the List of Encoders

func (*EncodeIt) Create added in v0.0.7

func (e *EncodeIt) Create(data []byte, encode interface{}) (output []byte, err error)

Create method from the Auth Interface

func (*EncodeIt) Set added in v0.0.7

func (e *EncodeIt) Set(method string, key interface{}) error

Set Method from the Auth Interface

func (*EncodeIt) Verify added in v0.0.7

func (e *EncodeIt) Verify(value []byte, bias interface{}) (data []byte, iBias interface{}, err error)

Verify method from the Auth Interface

type JwtAlgorithm added in v0.0.6

type JwtAlgorithm interface {

	// CreateToken helps to Create a token using supplied data in the from of map of string
	// and supplied options.
	CreateToken(string, ...func(JwtAlgorithm) JwtAlgorithm) (string, error)
	VerifyToken(string, ...func(JwtAlgorithm) JwtAlgorithm) (string, error)
}

JwtAlgorithm defines the way in which the JWT is calculated and verified

type JwtAlgorithmOptions added in v0.0.6

type JwtAlgorithmOptions func(JwtAlgorithm) JwtAlgorithm

JwtAlgorithmOptions is used to implement the JWT Option for Functional parameters of each Algorithm

type JwtMethod added in v0.0.6

type JwtMethod Auth

JwtMethod defines the way in which the JWT is Calculated

func GetJwtMethod added in v0.0.6

func GetJwtMethod(name string) (method JwtMethod)

GetJwtMethod helps to fetch the JWT Method via its name

type Pbkdf2Options added in v0.0.8

type Pbkdf2Options func(*pbkdf2Fn) *pbkdf2Fn

Pbkdf2Options type provides a way to create functional options for PBKDF2

func Pbkdf2Salt added in v0.0.8

func Pbkdf2Salt(buf []byte) Pbkdf2Options

Pbkdf2Salt sets a fixed salt for PBKDF2 Key derivation

func Pbkdf2With added in v0.0.8

func Pbkdf2With(rounds, size int) Pbkdf2Options

Pbkdf2With sets the number of rounds and output size of the PBKDF2

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL