Documentation
¶
Index ¶
- func GetCLIVersionFromHeader(ctx context.Context) string
- func GetOrganizationNameFromHeader(ctx context.Context) (string, error)
- func GetRawToken(ctx context.Context) (string, error)
- func WithCurrentAPIToken(ctx context.Context, token *APIToken) context.Context
- func WithCurrentOrg(ctx context.Context, org *Org) context.Context
- func WithCurrentUser(ctx context.Context, user *User) context.Context
- func WithMembership(ctx context.Context, m *Membership) context.Context
- type APIToken
- func (t *APIToken) IsInstanceScoped() bool
- func (t *APIToken) IsOrgScoped() bool
- func (t *APIToken) IsProductScoped() bool
- func (t *APIToken) ReachableProjects() []uuid.UUID
- func (t *APIToken) ReachesProject(id uuid.UUID) bool
- func (t *APIToken) ResourceScope() (kind authz.ResourceType, id uuid.UUID, ok bool)
- type Membership
- type Org
- type ResourceMembership
- type User
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func GetCLIVersionFromHeader ¶
GetCLIVersionFromHeader returns the CLI version advertised by the caller in the Chainloop-Cli-Version request header. The value format is "<version>-<edition>", e.g. "v1.94.2-oss". Returns an empty string when the header is absent or there is no transport in the context.
func GetRawToken ¶
GetRawToken takes whatever Bearer token is in the request
func WithCurrentAPIToken ¶
func WithMembership ¶
func WithMembership(ctx context.Context, m *Membership) context.Context
Types ¶
type APIToken ¶
type APIToken struct {
ID string
// Token Name
Name string
CreatedAt *time.Time
Token string
ProjectID *uuid.UUID
ProjectName *string
WorkflowID *uuid.UUID
WorkflowName *string
// ACL policies for this token. Used for authorization checks.
Policies []*authz.Policy
// Scope and ScopeID name what the token is scoped to. They are loaded from the row, never
// from a claim. Every row records them; a token recording none is confined to nothing.
Scope *authz.ResourceType
ScopeID *uuid.UUID
// ProjectIDs are the projects a product token reaches, loaded from the row.
ProjectIDs []uuid.UUID
// IsSystem marks tokens minted by internal code paths; these are hidden from the public API.
IsSystem bool
}
func CurrentAPIToken ¶
func (*APIToken) IsInstanceScoped ¶ added in v1.113.0
IsInstanceScoped reports whether the token acts for the whole instance, with no organization of its own. A token recording no scope is not.
func (*APIToken) IsOrgScoped ¶ added in v1.113.0
IsOrgScoped reports whether the token acts for its whole organization. A token recording no scope is not.
func (*APIToken) IsProductScoped ¶ added in v1.113.0
IsProductScoped reports whether the token is confined to a product: it reaches the projects in its ProjectIDs rather than a project of its own. It keys on the scope kind, never on scope_id.
func (*APIToken) ReachableProjects ¶ added in v1.113.0
ReachableProjects returns the projects a token is restricted to: its project, or its product's list, never nil. It returns nil for an organization or instance token, meaning no restriction: that token reaches every project of its organization. A token confined to nothing gets an empty list.
func (*APIToken) ReachesProject ¶ added in v1.113.0
ReachesProject reports whether the token reaches the project, without copying its project list. An organization or instance token reaches every project of its organization; no token, and a token confined to nothing, reach none.
func (*APIToken) ResourceScope ¶ added in v1.113.0
ResourceScope returns the resource the token is confined to, its project or its product, so callers can render and authorize it without naming its kind. ok is false for a token acting for its whole organization or instance, and for one recording no scope or no scope id. biz.APIToken classifies its scope through this one.
type Membership ¶
type Membership struct {
UserID uuid.UUID
Resources []*ResourceMembership
}
func CurrentMembership ¶
func CurrentMembership(ctx context.Context) *Membership