apitoken

package
v1.118.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: Apache-2.0 Imports: 7 Imported by: 0

Documentation

Index

Constants

View Source
const Audience = "api-token-auth.chainloop"

Variables

View Source
var SigningMethod = jwt.SigningMethodHS256

Functions

This section is empty.

Types

type Builder

type Builder struct {
	// contains filtered or unexported fields
}

func NewBuilder

func NewBuilder(opts ...NewOpt) (*Builder, error)

NewBuilder creates a new APIToken JWT builder It supports expiration and revocation Currently we use a simple hmac encryption method meant to be continuously rotated TODO: additional/alternative encryption method, i.e DSE asymmetric, see CAS robot account for reference

func (*Builder) GenerateJWT

func (ra *Builder) GenerateJWT(opts *GenerateJWTOptions) (string, error)

GenerateJWT creates a new JWT token for the given organization and keyID

type CustomClaims

type CustomClaims struct {
	OrgID        string `json:"org_id"`
	OrgName      string `json:"org_name"`
	KeyName      string `json:"token_name"`
	ProjectID    string `json:"project_id,omitempty"`
	ProjectName  string `json:"project_name,omitempty"`
	WorkflowID   string `json:"workflow_id,omitempty"`
	WorkflowName string `json:"workflow_name,omitempty"`
	// Scope and ScopeID say what the token was granted. Scope is the kind: instance, organization,
	// project or product. ScopeID names the resource, and an instance scope names none.
	//
	// A token minted before the control plane signed its scope has no scope claim. An older
	// instance token has the value "INSTANCE_ADMIN" in it instead. GetScope derives the scope of
	// such a token from the claims that it does carry.
	Scope   string `json:"scope,omitempty"`
	ScopeID string `json:"scope_id,omitempty"`
	jwt.RegisteredClaims
}

func ClaimsFromMap added in v1.116.0

func ClaimsFromMap(m jwt.MapClaims) (*CustomClaims, error)

ClaimsFromMap reads API-token claims that were parsed generically, as the API entry point receives them. A claim of the wrong type is an error, not an absent claim.

func (*CustomClaims) GetScope added in v1.116.0

func (c *CustomClaims) GetScope() (authz.ResourceType, *uuid.UUID, error)

GetScope returns the scope that the claims bind the token to. For a token with the scope and scope_id claims, that scope is what they name. For an older token, it is the scope that its other claims imply (see legacyScope). GetScope returns an error for claims that do not fit the scope (see validateScope).

func (*CustomClaims) HasScopeClaims added in v1.116.0

func (c *CustomClaims) HasScopeClaims() bool

HasScopeClaims reports whether the token was signed with its scope kind in the scope claim. A token without it was minted before the control plane signed the scope.

type GenerateJWTOptions added in v1.12.0

type GenerateJWTOptions struct {
	OrgID        *uuid.UUID
	OrgName      *string
	KeyID        uuid.UUID
	KeyName      string
	ProjectID    *uuid.UUID
	ProjectName  *string
	WorkflowID   *uuid.UUID
	WorkflowName *string
	ExpiresAt    *time.Time
	// Scope and ScopeID name the token's scope, as its row records it. Scope is required.
	// ScopeID is unset only for an instance token.
	Scope   *authz.ResourceType
	ScopeID *uuid.UUID
}

type NewOpt

type NewOpt func(b *Builder)

func WithIssuer

func WithIssuer(issuer string) NewOpt

func WithKeySecret

func WithKeySecret(hmacSecret string) NewOpt

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL