Documentation
¶
Overview ¶
Package basic provides HTTP Basic authentication middleware and utilities.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func AddCredentials ¶
AddCredentials fills in the user's credentials for req, if any. The return value reports whether any matching credentials were found. This function uses the default package-level NetrcProvider for backward compatibility.
func AddCredentialsWithProvider ¶
func AddCredentialsWithProvider(req *http.Request, provider *NetrcProvider) (added bool)
AddCredentialsWithProvider fills in the user's credentials for req using the specified provider. The return value reports whether any matching credentials were found.
Types ¶
type AuthMap ¶
type AuthMap map[string]BasicAuthPair
AuthMap is a user and password pair.
func LoadBasicAuthFromFile ¶
LoadBasicAuthFromFile reads an htpasswd-style file at filePath into an AuthMap. The file must be readable only by its owner (mode 0600 or 0400).
func LoadBasicAuthFromFileOrEmpty ¶ added in v0.9.0
LoadBasicAuthFromFileOrEmpty behaves like LoadBasicAuthFromFile, except a missing file returns an empty AuthMap and a nil error instead of the underlying os.Open error. Other errors (bad permissions, unreadable file) are returned unchanged. Useful for callers that treat "no credentials file yet" as a valid, empty starting state rather than a failure.
func LoadBasicAuthFromReader ¶
LoadBasicAuthFromReader reads htpasswd-style "user:hash" lines from reader into an AuthMap.
func LoadBasicAuthFromScanner ¶
LoadBasicAuthFromScanner reads htpasswd-style "user:hash" lines from scanner into an AuthMap.
func (AuthMap) AddUserWithHashedPassword ¶
AddUserWithHashedPassword if user already exists it will over ride it.
func (AuthMap) AddUserWithPlainPassword ¶
AddUserWithPlainPassword if user already exists it will over ride it.
func (AuthMap) Authenticate ¶
Authenticate returns true if the user exists and the password is correct.
func (AuthMap) UserExists ¶
UserExists returns true if the user exists.
type BasicAuthPair ¶
BasicAuthPair holds a username and its bcrypt-hashed password.
func NewBasicAuthPairWithPlainPassword ¶
func NewBasicAuthPairWithPlainPassword(user, password string) (BasicAuthPair, error)
NewBasicAuthPairWithPlainPassword hashes password and returns a BasicAuthPair for user.
func (BasicAuthPair) VerifyPassword ¶
func (p BasicAuthPair) VerifyPassword(password string) (bool, error)
VerifyPassword reports whether password matches p's stored hash.
type ClientAuth ¶
type ClientAuth struct {
Config ClientConfig
// contains filtered or unexported fields
}
ClientAuth adds HTTP Basic credentials to outgoing requests, resolving them from Config or, failing that, a netrc file.
func (*ClientAuth) AddAuth ¶
func (a *ClientAuth) AddAuth(req *http.Request) error
AddAuth sets the Basic auth header on req, resolving credentials from a.Config.User/Password or, if unset, the matching netrc entry for req's host.
func (*ClientAuth) HTTPClient ¶
func (a *ClientAuth) HTTPClient() *http.Client
HTTPClient returns an *http.Client that authenticates every request with a's credentials.
type ClientConfig ¶
type ClientConfig struct {
// https://everything.curl.dev/usingcurl/netrc
//
// machine connect.lab.dioad.net
// login blah
// password blah
NetRCFile string `mapstructure:"netrc-file"`
User string `mapstructure:"user"`
Password string `mapstructure:"password"`
}
ClientConfig configures HTTP Basic credentials for an outgoing client, either directly (User/Password) or via a netrc file.
type Handler ¶
type Handler struct {
// contains filtered or unexported fields
}
Handler implements basic authentication for HTTP servers. The credential map can be replaced at any time via SetAuthMap, safely concurrent with in-flight AuthRequest calls - Handler does not need to be rebuilt to pick up new or changed credentials.
func NewHandler ¶
func NewHandler(cfg ServerConfig) (*Handler, error)
NewHandler creates a new Basic authentication handler from the provided configuration.
func NewHandlerWithMap ¶
func NewHandlerWithMap(cfg ServerConfig, authMap AuthMap) (*Handler, error)
NewHandlerWithMap creates a new Basic authentication handler using the provided AuthMap and configuration (for Realm, used in the WWW-Authenticate challenge header). Call h.SetAuthMap later to replace the credentials the returned Handler authenticates against, e.g. after a credentials file changes on disk.
func (*Handler) AuthMap ¶ added in v0.9.0
AuthMap returns the credentials Handler currently authenticates against. Safe to call concurrently with SetAuthMap and AuthRequest.
func (*Handler) AuthRequest ¶
AuthRequest authenticates an HTTP request using Basic authentication.
func (*Handler) SetAuthMap ¶ added in v0.9.0
SetAuthMap atomically replaces the credentials Handler authenticates against. Safe to call concurrently with in-flight AuthRequest calls.
type NetrcProvider ¶
type NetrcProvider struct {
// contains filtered or unexported fields
}
NetrcProvider manages netrc credentials and their loading. It encapsulates the state for loading and parsing netrc files, allowing for multiple independent instances with different configurations. This resolves the global state issue that made testing difficult.
func NewNetrcProviderFromContent ¶
func NewNetrcProviderFromContent(content string) *NetrcProvider
NewNetrcProviderFromContent creates a NetrcProvider initialized with the given netrc content. This is useful for testing or when netrc data comes from a non-standard source.
type RoundTripper ¶
type RoundTripper struct {
Username string
Password string
Base http.RoundTripper
}
RoundTripper adds HTTP Basic credentials to every request before delegating to Base (or http.DefaultTransport if Base is nil).