Documentation
¶
Overview ¶
Package auth provides credential storage and resolution for jira-cli. Tokens are stored in the OS keyring when available, with automatic fallback to a plaintext JSON file with restrictive filesystem permissions when the keyring is unavailable. The fallback is not encrypted-at-rest.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ErrTokenNotFound = keyring.ErrNotFound
ErrTokenNotFound is returned when a token is not found in any store.
Functions ¶
func NormalizeInstanceURL ¶
NormalizeInstanceURL strips scheme, trailing slashes, and /rest/... suffix from an instance URL, yielding a clean hostname (e.g. "mysite.atlassian.net").
Types ¶
type Credentials ¶
type Credentials struct {
Instance string // e.g. "mysite.atlassian.net" (no scheme, no trailing slash)
User string // email for Basic auth
Token string // API token
}
Credentials holds resolved authentication data for the Jira API.
func Resolve ¶
func Resolve(flagInstance, flagUser, flagToken, profileName string, cfg ProfileConfig, tokenStore TokenStore) (*Credentials, error)
Resolve resolves credentials using the chain: flags > env > profile. flagInstance, flagUser, flagToken are the values from --instance, --user, --token flags. profileName is from --profile flag (empty means "use active profile"). cfg is used for profile lookup; tokenStore retrieves stored tokens.
type ProfileConfig ¶
type ProfileConfig interface {
ActiveProfile() string
GetProfile(name string) *ProfileData
}
ProfileConfig is the subset of config needed for auth resolution. This avoids importing the full config package.
type ProfileData ¶
ProfileData mirrors config.Profile without creating a dependency cycle.
type TokenStore ¶
type TokenStore interface {
StoreToken(profile, token string) error
RetrieveToken(profile string) (string, error)
DeleteToken(profile string) error
}
TokenStore abstracts credential storage for API tokens.
func NewTokenStore ¶
func NewTokenStore(tokensPath string, stderr io.Writer) TokenStore
NewTokenStore returns a TokenStore that tries the OS keyring first and falls back to tokens.json when the keyring is unavailable. The tokensPath argument is the path to the fallback tokens.json file. stderr is used to print warnings when keyring is unavailable.