Documentation
¶
Overview ¶
Package dockerhub reads Docker Hub access tokens and account profiles from the secrets engine. Obtain a ClientAuth from the client's HubAuth method, or from any secrets.Resolver via New.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ( // ErrNoSession means no Docker Hub credential is stored for the account. ErrNoSession = errors.New("user is not authenticated for this application") // ErrNoDefaultProfile means no account is set as the default. It wraps // [ErrNoSession]. ErrNoDefaultProfile = fmt.Errorf("no default account profile set: %w", ErrNoSession) )
Functions ¶
This section is empty.
Types ¶
type Audience ¶
type Audience []string
Audience is the "aud" claim: a single string or an array of strings.
func (*Audience) UnmarshalJSON ¶
type Claims ¶
type Claims struct {
Issuer string `json:"iss,omitempty"`
Subject string `json:"sub,omitempty"`
Audience Audience `json:"aud,omitempty"`
ExpiresAt *NumericDate `json:"exp,omitempty"`
NotBefore *NumericDate `json:"nbf,omitempty"`
IssuedAt *NumericDate `json:"iat,omitempty"`
ID string `json:"jti,omitempty"`
// Scope is a space-delimited list of granted scopes.
Scope string `json:"scope,omitempty"`
// AppName is the Docker client application the token was issued to.
AppName string `json:"app_name"`
UUID string `json:"uuid"`
// Source is formatted as `docker_{type}|{id}`.
Source string `json:"source"`
SessionID string `json:"session_id"`
ClientID string `json:"client_id,omitempty"`
ClientName string `json:"client_name,omitempty"`
Email string `json:"email"`
Username string `json:"username"`
}
Claims are the claims of a Docker Hub access token.
type ClientAuth ¶
type ClientAuth interface {
// ListProfiles returns the profiles of all signed-in accounts.
ListProfiles(ctx context.Context) ([]Profile, error)
// GetDefaultProfile returns the default account's profile, or
// [ErrNoDefaultProfile] when no default is set.
GetDefaultProfile(ctx context.Context) (Profile, error)
// GetDefaultSession returns the default account's session:
// [ErrNoDefaultProfile] when no default is set, [ErrNoSession] when its
// credential is missing.
GetDefaultSession(ctx context.Context) (UserSession, error)
// GetSession returns the session for username, or [ErrNoSession].
GetSession(ctx context.Context, username string) (UserSession, error)
}
ClientAuth reads Docker Hub authentication state from the secrets engine.
func New ¶
func New(engine secrets.Resolver, opts ...Option) ClientAuth
New returns a ClientAuth backed by engine. It panics on a nil engine.
type NumericDate ¶
NumericDate is an RFC 7519 numeric date: UNIX epoch seconds. It marshals truncated to whole seconds.
func (NumericDate) MarshalJSON ¶
func (d NumericDate) MarshalJSON() ([]byte, error)
func (*NumericDate) UnmarshalJSON ¶
func (d *NumericDate) UnmarshalJSON(data []byte) error
type Profile ¶
type Profile struct {
// UserID is the secret ID where the account's credential is stored.
UserID string `json:"user_id"`
// OriginalSignInApp is the Docker client application the user signed in from.
OriginalSignInApp string `json:"original_sign_in_app"`
Username string `json:"username"`
Email string `json:"email"`
SignInDate time.Time `json:"sign_in_date"`
}
Profile describes a signed-in Docker Hub account.
type UserSession ¶
type UserSession struct {
// AccessToken is a Docker Hub issued JWT.
AccessToken string `json:"access_token"`
// Claims are zero when the payload carries none.
Claims Claims `json:"claims"`
}
UserSession is a stored Docker Hub credential.