Documentation
¶
Overview ¶
Package jwt provides an easy to use capability to work with JWT auth mechanism.
This package internally uses github.com/golang-jwt/jwt/v5 as raw implementation of the jwt specifications.
Index ¶
- Constants
- Variables
- func GetClaim(token *jwt.Token, key string) (interface{}, bool)
- func NewToken(feed JwtFeed, signingMethod jwt.SigningMethod) *jwt.Token
- func ParseUnverifiedToken(tokenString string) (*jwt.Token, error)
- func SignECDSA(feed JwtFeed, privateKey string, kid string, ...) (string, error)
- func SignHMAC(feed JwtFeed, secret string, kid string, signingMethod *jwt.SigningMethodHMAC) (string, error)
- func Verify(tokenString string, cfg VerifyConfig) (bool, *jwt.Token, error)
- func VerifyECDSA(tokenString string, cfg VerifyConfig) (bool, *jwt.Token, error)
- func VerifyHMAC(tokenString string, cfg VerifyConfig) (bool, *jwt.Token, error)
- type JwtFeed
- type Verifier
- type VerifyConfig
Constants ¶
const ( JwtClaimAudience string = "aud" JwtClaimIssuer string = "iss" JwtClaimSubject string = "sub" JwtClaimIssuedAt string = "iat" JwtClaimExpiration string = "exp" JwtClaimNotBefore string = "nbf" JwtClaimData string = "data" )
Standard JWT claims
Variables ¶
var ( SigningMethodES256 *jwt.SigningMethodECDSA = jwt.SigningMethodES256 SigningMethodES384 *jwt.SigningMethodECDSA = jwt.SigningMethodES384 SigningMethodES512 *jwt.SigningMethodECDSA = jwt.SigningMethodES512 SigningMethodHS256 *jwt.SigningMethodHMAC = jwt.SigningMethodHS256 SigningMethodHS384 *jwt.SigningMethodHMAC = jwt.SigningMethodHS384 SigningMethodHS512 *jwt.SigningMethodHMAC = jwt.SigningMethodHS512 )
SIGNING METHODS
Functions ¶
func NewToken ¶
func NewToken(feed JwtFeed, signingMethod jwt.SigningMethod) *jwt.Token
Creates new JWT token with claims and returns an instance of `jwt.Token`. Feed JwtFeed : Struct of all standard and custom claims for jwt token.
func SignECDSA ¶
func SignECDSA(feed JwtFeed, privateKey string, kid string, signingMethod *jwt.SigningMethodECDSA) (string, error)
SignECDSA signs the token with an ECDSA private key. privateKey should be a base64-encoded PEM key.
func SignHMAC ¶
func SignHMAC(feed JwtFeed, secret string, kid string, signingMethod *jwt.SigningMethodHMAC) (string, error)
SignHMAC signs the token with an HMAC shared secret.
func Verify ¶
Verifies the provided JWT token string and returns token validity status, parsed token, and error.
func VerifyECDSA ¶
VerifyECDSA verifies tokens signed with ECDSA algorithms.
func VerifyHMAC ¶
VerifyHMAC verifies tokens signed with HMAC algorithms.
Types ¶
type JwtFeed ¶
type JwtFeed struct {
Subject string
Audience string
Issuer string
IssuedAt int64
Expiration int64
NotBefore int64
CustomClaims map[string]interface{}
}
JwtFeed represents the payload of a JWT (JSON Web Token) used for authentication and information exchange in applications. It encapsulates standard JWT claims as well as custom claims that can be provided by the application for specific use cases.
Fields:
- Subject: Identifies the principal that is the subject of the JWT.
- Audience: Intended recipients for which the JWT is intended.
- Issuer: Identifies the principal that issued the JWT.
- IssuedAt: Timestamp indicating when the JWT was issued. It is represented as seconds since Unix epoch.
- Expiration: Timestamp indicating the time after which the JWT is no longer valid. It is represented as seconds since Unix epoch.
- NotBefore: Timestamp indicating the time before which the JWT should not be accepted for processing. It is represented as seconds since Unix epoch.
- CustomClaims: A map containing custom claims provided by the application. These can be used to convey additional information or attributes about the subject or other aspects related to the token's use.
type Verifier ¶
type Verifier struct {
Config VerifyConfig
}
Verifier adapts VerifyConfig to the core/auth Verifier interface.
type VerifyConfig ¶
type VerifyConfig struct {
ECDSAPublicKeys map[string]string // Base64-encoded PEM ECDSA public keys by kid.
HMACSecrets map[string]string // Raw HMAC shared secrets by kid.
ExpectedIssuer string
ExpectedAudience string
}
VerifyConfig defines verifier behavior and accepted key material.