Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ( ErrNotFound = errors.New("secret not found") ErrAccessDenied = errors.New("access denied") // nuh, uh, uh! )
var ErrInvalidPattern = errors.New("invalid pattern")
Functions ¶
This section is empty.
Types ¶
type AuthorizeResponse ¶
type Authorizer ¶
type Authorizer interface {
Authorize(ctx context.Context, pattern ...Pattern) (AuthorizeResponse, error)
}
type Envelope ¶
type Envelope struct {
ID ID `json:"-"`
Value []byte `json:"-"`
Metadata map[string]string `json:"-"`
Provider string `json:"-"`
Version string `json:"-"`
CreatedAt time.Time `json:"-"`
ResolvedAt time.Time `json:"-"`
ExpiresAt time.Time `json:"-"`
}
func (Envelope) MarshalJSON ¶
type ErrInvalidID ¶
type ErrInvalidID struct {
ID string
}
func (ErrInvalidID) Error ¶
func (e ErrInvalidID) Error() string
type ID ¶
type ID interface {
// String formats the [ID] as a string
String() string
// Match the [ID] against a [Pattern]
// It checks if a given identifier matches the pattern.
// - "*" matches a single component
// - "**" matches zero or more components
// - "/" is the separator
Match(pattern Pattern) bool
}
ID contains a secret identifier. Valid secret identifiers must match the format ^[A-Za-z0-9._:-]+(?:/[A-Za-z0-9._:-]+)*$.
For storage, we don't really differentiate much about the ID format but by convention we do simple, slash-separated management, providing a groupable access control system for management across plugins.
func MustParseID ¶
MustParseID parses a string into a ID and behaves similar to ParseID, however, it panics when the id is invalid
type Pattern ¶
type Pattern interface {
// Match reports whether the pattern matches id.
// Complexity: O(n*m^k), where id has n components and the pattern has
// m components and k occurrences of '**'.
Match(id ID) bool
// Contains reports whether every ID that [other] matches can also be
// matched by the pattern: the set of IDs [other] matches is contained
// in the set the pattern matches, i.e., matches(other) ⊆ matches(p).
//
// Examples:
// - docker/** contains docker/*/mcp/*: '**' is more general than
// '*/mcp/*'.
// - docker/proj1/** does not contain docker/*/mcp/*: docker/*/mcp/*
// matches docker/proj2/mcp/x, but docker/proj1/** does not.
//
// Complexity: O(n*m)
Contains(other Pattern) bool
// Overlaps reports whether the pattern and [other] match at least one
// ID in common, i.e., matches(p) ∩ matches(other) ≠ ∅.
//
// Examples:
// - docker/*/mcp/* and docker/proj1/** overlap: both match e.g. docker/proj1/mcp/x.
// - bar/** and foo/** do not overlap: an ID cannot begin with both bar and foo.
//
// Complexity: O(n*m)
Overlaps(other Pattern) bool
// String returns the pattern text.
String() string
ExpandID(other ID) (ID, error)
ExpandPattern(other Pattern) (Pattern, error)
}
Pattern matches secret IDs. It follows the ID validation rules, except that '*' matches one component and '**' matches zero or more. Below, matches(p) denotes the set of IDs a pattern p matches.
func Minimize ¶
Minimize removes each pattern that another contains (see Pattern.Contains); when patterns match the same IDs, only the first stays. The result preserves input order.
Examples:
[** a/*] -> [**] [**/* */** **] -> [**/*] [a/** **/a] -> [a/** **/a]
Complexity: O(n²·L²) for n patterns of at most L components each.
func MustParsePattern ¶
MustParsePattern is like ParsePattern but panics on an invalid pattern.
func ParsePattern ¶
ParsePattern parses s into a Pattern: non-empty '/'-separated components of A-Z, a-z, 0-9, '.', '-', '_', ':', where a component may instead be '*' or '**'. It returns ErrInvalidPattern for anything else.