Documentation
¶
Index ¶
- Constants
- type AuthPasswordInterface
- type AuthPasswordlessInterface
- type AuthSharedInterface
- type AuthenticatedUserID
- type ConfigPasswordless
- type ConfigUsernameAndPassword
- type CookieConfig
- type CookieOption
- func WithCookieConfig(cfg CookieConfig) CookieOption
- func WithDomain(domain string) CookieOption
- func WithHttpOnly(httpOnly bool) CookieOption
- func WithMaxAge(maxAge int) CookieOption
- func WithPath(path string) CookieOption
- func WithSameSite(sameSite http.SameSite) CookieOption
- func WithSecure(secure bool) CookieOption
- type ImpersonatorUserID
- type IsImpersonating
- type NoopObservabilityHooks
- func (NoopObservabilityHooks) RecordImpersonationStart(string, string)
- func (NoopObservabilityHooks) RecordImpersonationStop(string, string)
- func (NoopObservabilityHooks) RecordLoginAttempt(string, bool, error)
- func (NoopObservabilityHooks) RecordPasswordReset(bool, error)
- func (NoopObservabilityHooks) RecordRateLimitHit(string, string)
- func (NoopObservabilityHooks) RecordRegistrationAttempt(bool, error)
- func (NoopObservabilityHooks) RecordSessionCreated(string)
- type ObservabilityHooks
- type PasswordStrengthConfig
- type UserAuthOptions
Constants ¶
const ( // Validation errors MsgEmailRequired = "Email is required field" MsgPasswordRequired = "Password is required field" MsgFirstNameRequired = "First name is required field" MsgLastNameRequired = "Last name is required field" MsgTokenRequired = "Token is required field" MsgUserIDRequired = "user_id is required field" MsgVerificationCodeRequired = "Verification code is required field" MsgPasswordsDoNotMatch = "Passwords do not match" MsgEmailInvalid = "Email is invalid" MsgVerificationCodeInvalidLength = "Verification code is invalid length" MsgVerificationCodeInvalidCharacters = "Verification code contains invalid characters" MsgVerificationCodeExpired = "Verification code has expired" MsgSerializedFormatMalformed = "Serialized format is malformed" // Auth errors MsgInvalidCredentials = "Invalid credentials" MsgUserNotFound = "User not found" // Operation errors MsgRegistrationFailed = "registration failed." MsgRegistrationFailedFn = "registration failed. FuncUserRegister function not defined" MsgRegistrationFailedEmailTpl = "registration failed. FuncEmailTemplateRegisterCode function not defined" MsgRegistrationFailedEmailSend = "registration failed. FuncEmailSend function not defined" MsgRegistrationFailedGeneric = "Registration failed. Please try again later" MsgPasswordResetFailed = "Password reset failed. Please try again later" MsgLogoutFailed = "Logout failed. Please try again later" MsgPasswordValidationFailed = "Password validation failed" // Generic internal errors MsgInternalServer = "Internal server error. Please try again later" MsgFailedToProcess = "Failed to process request. Please try again later" MsgFailedToGenerateCode = "Failed to generate verification code. Please try again later" MsgFailedToSendEmail = "Failed to send email. Please try again later" MsgLinkNotValidOrExpired = "Link not valid or expired" MsgTooManyRequests = "Too many requests. Please try again later." // Email subjects EmailSubjectRegistrationCode = "Registration Code" // Success messages MsgLoginSuccess = "login success" MsgRegistrationSuccess = "registration success" MsgRegistrationCodeSent = "Registration code was sent successfully" MsgLoginCodeSent = "Login code was sent successfully" MsgPasswordResetLinkSent = "Password reset link was sent to your e-mail" MsgPasswordResetSuccess = "Password has been reset successfully" // Impersonation messages MsgImpersonationStarted = "impersonation started" MsgImpersonationStopped = "impersonation stopped" MsgNotImpersonating = "not currently impersonating" MsgAlreadyImpersonating = "already impersonating — stop first" MsgImpersonationNotEnabled = "impersonation is not enabled" MsgImpersonationForbidden = "impersonation is not allowed" MsgImpersonationFailed = "impersonation failed. Please try again later" )
Error messages for validation and internal failures. These constants centralize all user-facing strings so applications can override or localize them without modifying core business logic.
const ( LoginMethodPassword = "password" LoginMethodPasswordless = "passwordless" )
Login method identifiers used by RecordLoginAttempt.
const CookieName = "authtoken"
const ImpersonationKeyPrefix = "imp:"
ImpersonationKeyPrefix is the prefix used for temporary keys that store the original admin auth token during an impersonation session.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type AuthPasswordInterface ¶ added in v0.30.0
type AuthPasswordInterface interface {
AuthSharedInterface
// Password reset URLs (web and API).
LinkPasswordRestore() string
LinkPasswordReset(token string) string
LinkApiPasswordRestore() string
LinkApiPasswordReset() string
}
AuthPasswordInterface represents username/password based authentication. It extends the shared interface with password-reset specific helpers.
type AuthPasswordlessInterface ¶ added in v0.30.0
type AuthPasswordlessInterface interface {
AuthSharedInterface
// Passwordless-only URL helpers.
LinkLoginCodeVerify() string
LinkApiLoginCodeVerify() string
}
AuthPasswordlessInterface represents passwordless authentication flows. It extends the shared interface with login/verification code helpers.
type AuthSharedInterface ¶ added in v0.30.0
type AuthSharedInterface interface {
Router() *http.ServeMux
WebAuthOrRedirectMiddleware(next http.Handler) http.Handler
WebAppendUserIdIfExistsMiddleware(next http.Handler) http.Handler
GetCurrentUserID(r *http.Request) string
// Web URL helpers
// API URL helpers
// Additional accessors used by internal API flows.
// Observability hooks for metrics and tracing (optional).
AuthenticateViaUsername(w http.ResponseWriter, r *http.Request, email, firstName, lastName string)
}
AuthSharedInterface defines the common behavior shared by all auth modes. It includes routing helpers, middleware, current user access, and the primary login/register URL helpers.
type AuthenticatedUserID ¶ added in v0.30.0
type AuthenticatedUserID struct{}
type ConfigPasswordless ¶ added in v0.30.0
type ConfigPasswordless struct {
// ===== START: shared by all implementations
EnableRegistration bool
Endpoint string
FuncLayout func(content string) string
FuncTemporaryKeyGet func(key string) (value string, err error)
FuncTemporaryKeySet func(key string, value string, expiresSeconds int) (err error)
FuncUserFindByAuthToken func(ctx context.Context, sessionID string, options UserAuthOptions) (userID string, err error)
FuncUserLogout func(ctx context.Context, userID string, options UserAuthOptions) (err error)
FuncUserStoreAuthToken func(ctx context.Context, sessionID string, userID string, options UserAuthOptions) error
UrlRedirectOnSuccess string
UseCookies bool
UseLocalStorage bool
CookieConfig *CookieConfig
// Rate limiting options
DisableRateLimit bool // Set to true to disable rate limiting (not recommended for production)
FuncCheckRateLimit func(ip string, endpoint string) (allowed bool, retryAfter time.Duration, err error) // Optional: override default rate limiter
MaxLoginAttempts int // Maximum attempts before lockout (default: 5)
LockoutDuration time.Duration // Duration to lock after max attempts (default: 15 minutes)
// CSRF Protection
EnableCSRFProtection bool
CSRFSecret string
Logger *slog.Logger
// Impersonation
EnableImpersonation bool
FuncCanImpersonate func(ctx context.Context, adminUserID string, targetUserID string) (bool, error)
FuncImpersonationStart func(ctx context.Context, adminUserID string, targetUserID string) error // optional
FuncImpersonationStop func(ctx context.Context, adminUserID string, targetUserID string) error // optional
// ===== START: passwordless options
FuncUserFindByEmail func(ctx context.Context, email string, options UserAuthOptions) (userID string, err error)
FuncEmailTemplateLoginCode func(ctx context.Context, email string, logingLink string, options UserAuthOptions) string // optional
FuncEmailTemplateRegisterCode func(ctx context.Context, email string, registerLink string, options UserAuthOptions) string // optional
FuncEmailSend func(ctx context.Context, email string, emailSubject string, emailBody string) (err error)
FuncUserRegister func(ctx context.Context, email string, firstName string, lastName string, options UserAuthOptions) (err error)
// Observability hooks for metrics and tracing (optional)
ObservabilityHooks ObservabilityHooks
}
type ConfigUsernameAndPassword ¶ added in v0.30.0
type ConfigUsernameAndPassword struct {
// ===== START: shared by all implementations
EnableRegistration bool
Endpoint string
FuncLayout func(content string) string
FuncTemporaryKeyGet func(key string) (value string, err error)
FuncTemporaryKeySet func(key string, value string, expiresSeconds int) (err error)
FuncUserStoreAuthToken func(ctx context.Context, sessionID string, userID string, options UserAuthOptions) error
FuncUserFindByAuthToken func(ctx context.Context, sessionID string, options UserAuthOptions) (userID string, err error)
UrlRedirectOnSuccess string
UseCookies bool
UseLocalStorage bool
CookieConfig *CookieConfig
// Rate limiting options
DisableRateLimit bool // Set to true to disable rate limiting (not recommended for production)
FuncCheckRateLimit func(ip string, endpoint string) (allowed bool, retryAfter time.Duration, err error) // Optional: override default rate limiter
MaxLoginAttempts int // Maximum attempts before lockout (default: 5)
LockoutDuration time.Duration // Duration to lock after max attempts (default: 15 minutes)
// CSRF Protection
EnableCSRFProtection bool
CSRFSecret string
Logger *slog.Logger
// Impersonation
EnableImpersonation bool
FuncCanImpersonate func(ctx context.Context, adminUserID string, targetUserID string) (bool, error)
FuncImpersonationStart func(ctx context.Context, adminUserID string, targetUserID string) error // optional
FuncImpersonationStop func(ctx context.Context, adminUserID string, targetUserID string) error // optional
// ===== START: username(email) and password options
EnableVerification bool
FuncEmailTemplatePasswordRestore func(ctx context.Context, userID string, passwordRestoreLink string, options UserAuthOptions) string // optional
FuncEmailTemplateRegisterCode func(ctx context.Context, userID string, passwordRestoreLink string, options UserAuthOptions) string // optional
FuncEmailSend func(ctx context.Context, userID string, emailSubject string, emailBody string) (err error)
FuncUserFindByUsername func(ctx context.Context, username string, firstName string, lastName string, options UserAuthOptions) (userID string, err error)
FuncUserLogin func(ctx context.Context, username string, password string, options UserAuthOptions) (userID string, err error)
FuncUserLogout func(ctx context.Context, userID string, options UserAuthOptions) (err error)
FuncUserPasswordChange func(ctx context.Context, username string, newPassword string, options UserAuthOptions) (err error)
FuncUserRegister func(ctx context.Context, username string, password string, first_name string, last_name string, options UserAuthOptions) (err error)
PasswordStrength *PasswordStrengthConfig
LabelUsername string
// Observability hooks for metrics and tracing (optional)
ObservabilityHooks ObservabilityHooks
}
Config defines the available configuration options for authentication
type CookieConfig ¶ added in v0.30.0
type CookieOption ¶ added in v0.33.0
type CookieOption func(*CookieConfig)
CookieOption customizes a CookieConfig by mutating it. Options are applied on top of the default config.
func WithCookieConfig ¶ added in v0.33.0
func WithCookieConfig(cfg CookieConfig) CookieOption
WithCookieConfig replaces the entire cookie config with the provided one. Use this when you already have a complete CookieConfig.
func WithDomain ¶ added in v0.33.0
func WithDomain(domain string) CookieOption
WithDomain sets the Domain.
func WithHttpOnly ¶ added in v0.33.0
func WithHttpOnly(httpOnly bool) CookieOption
WithHttpOnly sets the HttpOnly flag.
func WithMaxAge ¶ added in v0.33.0
func WithMaxAge(maxAge int) CookieOption
WithMaxAge sets the MaxAge in seconds.
func WithSameSite ¶ added in v0.33.0
func WithSameSite(sameSite http.SameSite) CookieOption
WithSameSite sets the SameSite attribute.
func WithSecure ¶ added in v0.33.0
func WithSecure(secure bool) CookieOption
WithSecure sets the Secure flag.
type ImpersonatorUserID ¶ added in v0.33.0
type ImpersonatorUserID struct{}
type IsImpersonating ¶ added in v0.33.0
type IsImpersonating struct{}
type NoopObservabilityHooks ¶ added in v0.31.0
type NoopObservabilityHooks struct{}
NoopObservabilityHooks is a no-op implementation of ObservabilityHooks. It is the default when no hooks are configured.
func (NoopObservabilityHooks) RecordImpersonationStart ¶ added in v0.33.0
func (NoopObservabilityHooks) RecordImpersonationStart(string, string)
func (NoopObservabilityHooks) RecordImpersonationStop ¶ added in v0.33.0
func (NoopObservabilityHooks) RecordImpersonationStop(string, string)
func (NoopObservabilityHooks) RecordLoginAttempt ¶ added in v0.31.0
func (NoopObservabilityHooks) RecordLoginAttempt(string, bool, error)
func (NoopObservabilityHooks) RecordPasswordReset ¶ added in v0.31.0
func (NoopObservabilityHooks) RecordPasswordReset(bool, error)
func (NoopObservabilityHooks) RecordRateLimitHit ¶ added in v0.31.0
func (NoopObservabilityHooks) RecordRateLimitHit(string, string)
func (NoopObservabilityHooks) RecordRegistrationAttempt ¶ added in v0.31.0
func (NoopObservabilityHooks) RecordRegistrationAttempt(bool, error)
func (NoopObservabilityHooks) RecordSessionCreated ¶ added in v0.31.0
func (NoopObservabilityHooks) RecordSessionCreated(string)
type ObservabilityHooks ¶ added in v0.31.0
type ObservabilityHooks interface {
// RecordLoginAttempt is called after every login attempt (success or
// failure). method is "password" or "passwordless". err is nil on
// success.
RecordLoginAttempt(method string, success bool, err error)
// RecordRegistrationAttempt is called after every registration attempt.
// err is nil on success.
RecordRegistrationAttempt(success bool, err error)
// RecordRateLimitHit is called when a request is denied due to rate
// limiting.
RecordRateLimitHit(endpoint string, ip string)
// RecordSessionCreated is called when a new session/token is issued
// for a user.
RecordSessionCreated(userID string)
// RecordPasswordReset is called after a password reset attempt.
// err is nil on success.
RecordPasswordReset(success bool, err error)
// RecordImpersonationStart is called when an admin begins impersonating
// another user.
RecordImpersonationStart(adminUserID string, targetUserID string)
// RecordImpersonationStop is called when an admin stops impersonating
// another user.
RecordImpersonationStop(adminUserID string, targetUserID string)
}
ObservabilityHooks allows applications to record metrics and tracing spans for authentication events using their preferred provider (Prometheus, Datadog, OpenTelemetry, etc.).
All methods must be safe to call from multiple goroutines. Implementations should be non-blocking; if a method needs to do expensive work it should do so asynchronously.
A nil ObservabilityHooks is valid and means no metrics are recorded.
type PasswordStrengthConfig ¶
type PasswordStrengthConfig struct {
MinLength int
RequireUppercase bool
RequireLowercase bool
RequireDigit bool
RequireSpecial bool
ForbidCommonWords bool
}
PasswordStrengthConfig defines configurable rules for password strength.