Documentation
¶
Index ¶
Constants ¶
const Audience = "api-token-auth.chainloop"
Variables ¶
var SigningMethod = jwt.SigningMethodHS256
Functions ¶
This section is empty.
Types ¶
type Builder ¶
type Builder struct {
// contains filtered or unexported fields
}
func NewBuilder ¶
NewBuilder creates a new APIToken JWT builder It supports expiration and revocation Currently we use a simple hmac encryption method meant to be continuously rotated TODO: additional/alternative encryption method, i.e DSE asymmetric, see CAS robot account for reference
func (*Builder) GenerateJWT ¶
func (ra *Builder) GenerateJWT(opts *GenerateJWTOptions) (string, error)
GenerateJWT creates a new JWT token for the given organization and keyID
type CustomClaims ¶
type CustomClaims struct {
OrgID string `json:"org_id"`
OrgName string `json:"org_name"`
KeyName string `json:"token_name"`
ProjectID string `json:"project_id,omitempty"`
ProjectName string `json:"project_name,omitempty"`
WorkflowID string `json:"workflow_id,omitempty"`
WorkflowName string `json:"workflow_name,omitempty"`
// Scope and ScopeID say what the token was granted. Scope is the kind: instance, organization,
// project or product. ScopeID names the resource, and an instance scope names none.
//
// A token minted before the control plane signed its scope has no scope claim. An older
// instance token has the value "INSTANCE_ADMIN" in it instead. GetScope derives the scope of
// such a token from the claims that it does carry.
Scope string `json:"scope,omitempty"`
ScopeID string `json:"scope_id,omitempty"`
jwt.RegisteredClaims
}
func ClaimsFromMap ¶ added in v1.116.0
func ClaimsFromMap(m jwt.MapClaims) (*CustomClaims, error)
ClaimsFromMap reads API-token claims that were parsed generically, as the API entry point receives them. A claim of the wrong type is an error, not an absent claim.
func (*CustomClaims) GetScope ¶ added in v1.116.0
func (c *CustomClaims) GetScope() (authz.ResourceType, *uuid.UUID, error)
GetScope returns the scope that the claims bind the token to. For a token with the scope and scope_id claims, that scope is what they name. For an older token, it is the scope that its other claims imply (see legacyScope). GetScope returns an error for claims that do not fit the scope (see validateScope).
func (*CustomClaims) HasScopeClaims ¶ added in v1.116.0
func (c *CustomClaims) HasScopeClaims() bool
HasScopeClaims reports whether the token was signed with its scope kind in the scope claim. A token without it was minted before the control plane signed the scope.
type GenerateJWTOptions ¶ added in v1.12.0
type GenerateJWTOptions struct {
OrgID *uuid.UUID
OrgName *string
KeyID uuid.UUID
KeyName string
ProjectID *uuid.UUID
ProjectName *string
WorkflowID *uuid.UUID
WorkflowName *string
ExpiresAt *time.Time
// Scope and ScopeID name the token's scope, as its row records it. Scope is required.
// ScopeID is unset only for an instance token.
Scope *authz.ResourceType
ScopeID *uuid.UUID
}