secrets

package
v0.8.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 23, 2026 License: Apache-2.0 Imports: 6 Imported by: 6

Documentation

Index

Constants

This section is empty.

Variables

View Source
var (
	ErrNotFound     = errors.New("secret not found")
	ErrAccessDenied = errors.New("access denied") // nuh, uh, uh!
)
View Source
var ErrInvalidPattern = errors.New("invalid pattern")

Functions

This section is empty.

Types

type AuthorizeResponse

type AuthorizeResponse struct {
	// Expiry is when the decision stops holding. A zero Expiry means the
	// decision never expires, and the wire message then carries no timestamp.
	Expiry time.Time
	Allow  bool
}

type Authorizer

type Authorizer interface {
	Authorize(ctx context.Context, pattern ...Pattern) (AuthorizeResponse, error)
}

type Envelope

type Envelope struct {
	ID         ID                `json:"-"`
	Value      []byte            `json:"-"`
	Metadata   map[string]string `json:"-"`
	Provider   string            `json:"-"`
	Version    string            `json:"-"`
	CreatedAt  time.Time         `json:"-"`
	ResolvedAt time.Time         `json:"-"`
	ExpiresAt  time.Time         `json:"-"`
}

func (Envelope) MarshalJSON

func (e Envelope) MarshalJSON() ([]byte, error)

type ErrInvalidID

type ErrInvalidID struct {
	ID string
}

func (ErrInvalidID) Error

func (e ErrInvalidID) Error() string

type ID

type ID interface {
	// String formats the [ID] as a string
	String() string
	// Match the [ID] against a [Pattern]
	// It checks if a given identifier matches the pattern.
	// - "*" matches a single component
	// - "**" matches zero or more components
	// - "/" is the separator
	Match(pattern Pattern) bool
}

ID contains a secret identifier. Valid secret identifiers must match the format ^[A-Za-z0-9._:-]+(?:/[A-Za-z0-9._:-]+)*$.

For storage, we don't really differentiate much about the ID format but by convention we do simple, slash-separated management, providing a groupable access control system for management across plugins.

func MustParseID

func MustParseID(s string) ID

MustParseID parses a string into a ID and behaves similar to ParseID, however, it panics when the id is invalid

func ParseID

func ParseID(s string) (ID, error)

ParseID creates a new ID from a string If a validation error occurs, it returns nil and the error. Rules: - Components separated by '/' - Each component is non-empty - Only characters A-Z, a-z, 0-9, '.', '_', '-' or ':' - No leading, trailing, or double slashes

type Pattern

type Pattern interface {
	// Match reports whether the pattern matches id.
	// Complexity: O(n*m^k), where id has n components and the pattern has
	// m components and k occurrences of '**'.
	Match(id ID) bool
	// Contains reports whether every ID that [other] matches can also be
	// matched by the pattern: the set of IDs [other] matches is contained
	// in the set the pattern matches, i.e., matches(other) ⊆ matches(p).
	//
	// Examples:
	//   - docker/** contains docker/*/mcp/*: '**' is more general than
	//     '*/mcp/*'.
	//   - docker/proj1/** does not contain docker/*/mcp/*: docker/*/mcp/*
	//     matches docker/proj2/mcp/x, but docker/proj1/** does not.
	//
	// Complexity: O(n*m)
	Contains(other Pattern) bool
	// Overlaps reports whether the pattern and [other] match at least one
	// ID in common, i.e., matches(p) ∩ matches(other) ≠ ∅.
	//
	// Examples:
	//   - docker/*/mcp/* and docker/proj1/** overlap: both match e.g. docker/proj1/mcp/x.
	//   - bar/** and foo/** do not overlap: an ID cannot begin with both bar and foo.
	//
	// Complexity: O(n*m)
	Overlaps(other Pattern) bool
	// String returns the pattern text.
	String() string

	ExpandID(other ID) (ID, error)
	ExpandPattern(other Pattern) (Pattern, error)
}

Pattern matches secret IDs. It follows the ID validation rules, except that '*' matches one component and '**' matches zero or more. Below, matches(p) denotes the set of IDs a pattern p matches.

func Minimize

func Minimize(patterns []Pattern) []Pattern

Minimize removes each pattern that another contains (see Pattern.Contains); when patterns match the same IDs, only the first stays. The result preserves input order.

Examples:

[** a/*]        ->  [**]
[**/* */** **]  ->  [**/*]
[a/** **/a]     ->  [a/** **/a]

Complexity: O(n²·L²) for n patterns of at most L components each.

func MustParsePattern

func MustParsePattern(s string) Pattern

MustParsePattern is like ParsePattern but panics on an invalid pattern.

func ParsePattern

func ParsePattern(s string) (Pattern, error)

ParsePattern parses s into a Pattern: non-empty '/'-separated components of A-Z, a-z, 0-9, '.', '-', '_', ':', where a component may instead be '*' or '**'. It returns ErrInvalidPattern for anything else.

type Resolver

type Resolver interface {
	GetSecrets(ctx context.Context, pattern Pattern) ([]Envelope, error)
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL