entities

package
v1.113.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 9 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func GetCLIVersionFromHeader

func GetCLIVersionFromHeader(ctx context.Context) string

GetCLIVersionFromHeader returns the CLI version advertised by the caller in the Chainloop-Cli-Version request header. The value format is "<version>-<edition>", e.g. "v1.94.2-oss". Returns an empty string when the header is absent or there is no transport in the context.

func GetOrganizationNameFromHeader

func GetOrganizationNameFromHeader(ctx context.Context) (string, error)

func GetRawToken

func GetRawToken(ctx context.Context) (string, error)

GetRawToken takes whatever Bearer token is in the request

func WithCurrentAPIToken

func WithCurrentAPIToken(ctx context.Context, token *APIToken) context.Context

func WithCurrentOrg

func WithCurrentOrg(ctx context.Context, org *Org) context.Context

func WithCurrentUser

func WithCurrentUser(ctx context.Context, user *User) context.Context

func WithMembership

func WithMembership(ctx context.Context, m *Membership) context.Context

Types

type APIToken

type APIToken struct {
	ID string
	// Token Name
	Name         string
	CreatedAt    *time.Time
	Token        string
	ProjectID    *uuid.UUID
	ProjectName  *string
	WorkflowID   *uuid.UUID
	WorkflowName *string
	// ACL policies for this token. Used for authorization checks.
	Policies []*authz.Policy
	// Scope and ScopeID name what the token is scoped to. They are loaded from the row, never
	// from a claim. Every row records them; a token recording none is confined to nothing.
	Scope   *authz.ResourceType
	ScopeID *uuid.UUID
	// ProjectIDs are the projects a product token reaches, loaded from the row.
	ProjectIDs []uuid.UUID
	// IsSystem marks tokens minted by internal code paths; these are hidden from the public API.
	IsSystem bool
}

func CurrentAPIToken

func CurrentAPIToken(ctx context.Context) *APIToken

func (*APIToken) IsInstanceScoped added in v1.113.0

func (t *APIToken) IsInstanceScoped() bool

IsInstanceScoped reports whether the token acts for the whole instance, with no organization of its own. A token recording no scope is not.

func (*APIToken) IsOrgScoped added in v1.113.0

func (t *APIToken) IsOrgScoped() bool

IsOrgScoped reports whether the token acts for its whole organization. A token recording no scope is not.

func (*APIToken) IsProductScoped added in v1.113.0

func (t *APIToken) IsProductScoped() bool

IsProductScoped reports whether the token is confined to a product: it reaches the projects in its ProjectIDs rather than a project of its own. It keys on the scope kind, never on scope_id.

func (*APIToken) ReachableProjects added in v1.113.0

func (t *APIToken) ReachableProjects() []uuid.UUID

ReachableProjects returns the projects a token is restricted to: its project, or its product's list, never nil. It returns nil for an organization or instance token, meaning no restriction: that token reaches every project of its organization. A token confined to nothing gets an empty list.

func (*APIToken) ReachesProject added in v1.113.0

func (t *APIToken) ReachesProject(id uuid.UUID) bool

ReachesProject reports whether the token reaches the project, without copying its project list. An organization or instance token reaches every project of its organization; no token, and a token confined to nothing, reach none.

func (*APIToken) ResourceScope added in v1.113.0

func (t *APIToken) ResourceScope() (kind authz.ResourceType, id uuid.UUID, ok bool)

ResourceScope returns the resource the token is confined to, its project or its product, so callers can render and authorize it without naming its kind. ok is false for a token acting for its whole organization or instance, and for one recording no scope or no scope id. biz.APIToken classifies its scope through this one.

type Membership

type Membership struct {
	UserID    uuid.UUID
	Resources []*ResourceMembership
}

func CurrentMembership

func CurrentMembership(ctx context.Context) *Membership

type Org

type Org struct {
	ID, Name  string
	CreatedAt *time.Time
	Suspended bool
}

func CurrentOrg

func CurrentOrg(ctx context.Context) *Org

type ResourceMembership

type ResourceMembership struct {
	MembershipID uuid.UUID
	Role         authz.Role
	ResourceType authz.ResourceType
	ResourceID   uuid.UUID
}

type User

type User struct {
	Email, ID, FirstName, LastName string
	CreatedAt                      *time.Time
}

Utils to get and set information from context

func CurrentUser

func CurrentUser(ctx context.Context) *User

CurrentUser retrieves the user from the context

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL