Documentation
¶
Overview ¶
Package app builds the identity service HTTP handler from injected dependencies. It is shared by the production binary (cmd/identity) and the integration test harness (tests/integration), so that both exercise the exact same wiring code: middleware chain, audit logger, service layer, and Connect-RPC handler registration.
Schema declaration listing.
EntDB's schema is client-side: the SDK reads (entdb.node) / (entdb.edge) options off the proto descriptor at every call site, and the wire format is keyed by proto field id. There is no server-side "register schema" step to wait for — the previous "schema_registration_pending_upstream_api" warning was wrong about the SDK contract.
This file therefore loads the embedded FileDescriptor for identity's schema and emits one structured log line per declared node type at startup, so operators can see the contract identity runs against. It does no I/O.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ErrSchemaMalformed = errors.New("identity schema descriptor is malformed")
ErrSchemaMalformed indicates the embedded identity schema descriptor is missing required (entdb.node) annotations on messages we declared as node types. We treat this as an internal invariant violation — identity binaries should never ship with a schema that fails this check.
Functions ¶
This section is empty.
Types ¶
type Built ¶ added in v0.9.0
type Built struct {
Handler http.Handler
ConnectHandler *identityconnect.IdentityHandler
// contains filtered or unexported fields
}
Built is the result of New: the assembled identity service, ready to mount and run. It separates construction (no goroutines) from the background-worker lifecycle so the embedding consumer — the container binary or a host server — controls when workers run via Start/Stop.
- Handler is the full middleware chain wrapping the Connect-RPC handler; mount it on any HTTP/2 (or h2c) server.
- ConnectHandler is the Connect service implementation. The native gRPC bridge registers against this so both mount surfaces share one service-layer wiring.
- Start launches the background workers (audit flusher, sweeper); it is idempotent. Stop drains them; safe to call multiple times.
func New ¶
New assembles the identity service from injected dependencies. It builds the middleware chain, the Connect-RPC service handler, and the background workers — but does NOT start the workers; the caller starts them with (*Built).Start once it is ready to serve, and drains them with (*Built).Stop on shutdown. Configuration errors (e.g. invalid CORS origins) are returned before any worker is constructed.
type Deps ¶
type Deps struct {
Config *config.Config
Logger *zap.Logger
Signer jwt.Signer
Repo service.Repository
DB service.DB
Passkeys *passkeys.WebAuthnService
TOTPKey []byte
// TenantAdmin is the cross-tenant admin handle backing the
// `mode=multi` OrganizationSignup RPC. Required when
// Config.IdentityMode == "multi"; ignored in single mode. The
// production binary wires repo.NewTenantAdmin(entdbClient);
// integration tests pass a fake.
TenantAdmin service.TenantAdmin
// RepositoryForTenant is the factory OrganizationSignup uses to
// obtain a Repository scoped to the freshly-created tenant. When
// nil, the handler treats `mode=multi` as not yet wired and
// returns CodeUnimplemented. The production binary wires a closure
// over the entdb client; tests pass a closure returning an
// in-memory Repo keyed on tenant id.
RepositoryForTenant service.RepositoryForTenant
// ProjectResolver resolves a request's control-plane project from its
// credential key or Host header (see middleware.NewProjectResolver).
// Non-nil only for the postgres driver; when nil the project-resolution
// middleware pins every request to the configured default project. The
// production binary wires the postgres control-plane store; tests pass
// a fake or nil.
ProjectResolver service.ProjectResolver
// TOTPRecoveryPepper is the HMAC-SHA-256 key used to hash and
// verify recovery codes. Must be >= totp.MinRecoveryPepperBytes
// bytes long; the binary refuses to start otherwise.
TOTPRecoveryPepper []byte
// EmailTransport delivers outbound mail. If nil, New constructs a
// transport from cfg via buildEmailTransport (so production code
// only needs to populate this when a test wants a custom recorder).
EmailTransport email.Transport
// SMSSender delivers outbound SMS for phone verification. If nil, New
// constructs a sender from cfg via buildSMSSender — a log-only sender
// when GATEWAY_SMS_ENABLED is false, otherwise the configured
// provider (Twilio / SNS / Azure).
SMSSender sms.Sender
// OAuthRegistry holds the per-provider Exchangers used for OAuth
// login. May be nil — in that case OAuthLogin returns
// ErrOAuthDisabled. When nil, New builds a registry from the
// config's GATEWAY_*_CLIENT_ID/SECRET env vars (only providers
// with both credentials set are registered).
OAuthRegistry *oauth.Registry
// IDVProvider drives identity-verification (document + selfie).
// May be nil — in that case BeginIdentityVerification returns
// CodeUnimplemented. Production deployments wire an Azure or
// other real provider; tests typically pass an idv.StubProvider.
IDVProvider idv.Provider
// CaptchaVerifier gates the unauthenticated auth endpoints. May be
// nil — in that case New builds one from Config (the no-op verifier
// when CAPTCHA is disabled). Tests inject a fake to drive pass/fail
// without network calls.
CaptchaVerifier captcha.Verifier
// MetricsRegistry is the Prometheus registry the server records
// RED metrics into. May be nil — in that case the default
// registry is used (which is what production wants). Tests pass an
// isolated registry so they can read counters without colliding
// with other tests in the same process.
MetricsRegistry prometheus.Registerer
}
Deps groups the injectable dependencies required to build the identity HTTP handler. It lets the production main.go pass real adapters and the integration test harness pass in-memory fakes, without duplicating the wiring code.