auth

package
v0.10.5 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 3, 2026 License: MIT Imports: 27 Imported by: 0

Documentation

Index

Constants

View Source
const EnvTokenVar = "ENTIRE_TOKEN"

EnvTokenVar is the environment variable that, when set, bypasses contexts.json and the keyring entirely: its value is used verbatim as the bearer for control-plane and git data-plane requests. This is the CI / workload-identity path — a runner injects a short-lived login or sa-session JWT and clones without an interactive `entire login`. The explicit `entire auth token --jurisdiction` command remains a separate path and uses the value as the subject of its requested jurisdiction-token exchange.

View Source
const (

	// JurisdictionIdentityScope is the scope jurisdiction identity tokens
	// are minted with (also used by git-remote-entire's jurisdiction git
	// auth). The receiving surface authorizes live per request, so the
	// scope carries identity semantics only, not a permission grant.
	JurisdictionIdentityScope = "openid"
)

Variables

View Source
var ErrCredentialStoreWrite = errors.New("credential store write failed")

ErrCredentialStoreWrite marks a failure writing tokens to the configured credential backend (OS keyring or file store), as opposed to claim validation or contexts.json failures. Login UX branches on it via errors.Is to decide whether pointing the user at the file token store would actually help.

View Source
var ErrNoCellForJurisdiction = errors.New("no entire-api cell configured for jurisdiction")

ErrNoCellForJurisdiction signals that the caller's home jurisdiction has no entire-api cell in the cluster catalog (or its row carries no apiUrl). It is not fatal: callers that also have a data-API path (e.g. activity/recap) treat it as "entire-api isn't serving this region yet" and fall back rather than failing the command. errors.Is unwraps it from the contextual message.

View Source
var ErrNotLoggedIn = tokenmanager.ErrNotLoggedIn

ErrNotLoggedIn re-exports tokenmanager.ErrNotLoggedIn so callers in the cli package can errors.Is against it without an extra import.

Functions

func Contexts added in v0.7.0

func Contexts() ([]*contexts.Context, string, error)

Contexts returns all stored login contexts and the name of the one currently acting, for listing/switching and for the status/logout targets. Order matches on-disk order.

The second return is the EFFECTIVE active name, so a `--context`/ $ENTIRE_CONTEXT selection is what `auth status` reports, what `auth contexts` marks, and what `logout` revokes — the alternative is status describing one identity while every other command uses another.

func CoreURLFromEnvToken added in v0.7.4

func CoreURLFromEnvToken(rawToken string) (string, error)

CoreURLFromEnvToken derives the home-region core URL from an ENTIRE_TOKEN JWT's audience claim. Login and sa-session JWTs carry aud=<home-region URL>, so we read aud, not iss (iss may be a different regional core).

SECURITY: ParseClaims does NOT verify the signature, so the audience is attacker-controlled if a forged token is injected. This function only enforces the *shape* of a safe core origin (https, bare origin). The git helper uses the result only after checking it against the target cluster's advertised CoreURLs, then sends the env token directly to the data plane. Control-plane clients use the result as their bearer target, while the explicit `entire auth token --jurisdiction` path uses it as the STS host for that command's requested exchange.

Structural rules, all required:

  • the aud is a well-formed absolute URL,
  • scheme is https (no cleartext token transmission),
  • it carries a host and no userinfo, path, query, or fragment — entire cores are bare origins (https://core.example.com), so anything richer is either a misconfigured token or an attempt to smuggle a path/redirect.

The aud claim may be a single string or an array (RFC 7519 §4.1.3); ParseClaims normalises both to a slice. Non-URL audiences (e.g. an OAuth client_id like "entire-cli") are skipped; the first URL-shaped audience is validated strictly. A token with no URL-shaped aud is rejected with a clear error rather than silently falling back to context resolution.

func EnableInsecureHTTP added in v0.6.3

func EnableInsecureHTTP()

EnableInsecureHTTP relaxes the token managers' HTTPS guard so non-loopback http:// resources (and the login server's STS endpoint) are permitted during token resolution. The CLI calls this when the user passes --insecure-http-auth to a command that hits the data API on a private network (e.g. a split-host local-dev box where both hosts are plain HTTP).

func HomeJurisdictionFromLoginJWT added in v0.8.0

func HomeJurisdictionFromLoginJWT(loginJWT string) (string, error)

HomeJurisdictionFromLoginJWT reads the home_jurisdiction claim without verifying the signature — callers only route with it; the server re-verifies. The claim is normalized (NormalizeJurisdiction), so a malformed label is an error here and every reader sees one spelling. Returns "" (no error) when the claim is absent so each caller can phrase its own missing-claim error. Shared with git-remote-entire's jurisdiction git auth.

func JurisdictionToken added in v0.8.0

func JurisdictionToken(ctx context.Context, insecureHTTP bool, jurisdiction string) (string, error)

JurisdictionToken mints and returns a jurisdictional identity token (scope=openid, aud=jurisdiction host) for `jurisdiction`, for authenticating against that jurisdiction's entire-api cells (e.g. https://aws-us-east-2.api.entire.io/api/v1). Unlike NewEntireAPICellClient it returns the raw token string (it skips the cell-base-URL resolution, which is only needed to build a client) and it honours ENTIRE_TOKEN.

Subject credential precedence:

  • ENTIRE_TOKEN set: the env token is the exchange subject_token, and its own aud core drives the environment family (so this works with only ENTIRE_TOKEN set, no ENTIRE_API_BASE_URL, in prod/staging/loopback). Presence is exclusive and fail-closed — a malformed/blank value errors rather than falling back to a stored login. The env token must be a login JWT (subject-capable); a rejected exchange surfaces the server error.
  • otherwise: the active stored context's refreshed login JWT.

An empty `jurisdiction` falls back to the subject token's home_jurisdiction claim.

func LocalIdentityCacheKey added in v0.7.8

func LocalIdentityCacheKey() (string, error)

LocalIdentityCacheKey returns a non-secret local auth identity key.

func LoginTokenForContext added in v0.7.0

func LoginTokenForContext(c *contexts.Context) (string, error)

LoginTokenForContext returns the login JWT stored for c, read from the OS keyring slot the context points at. The encoded expiry is stripped; the server is the authority on validity and the device-flow login holds no refresh token, so an expired token surfaces as a 401 the caller can translate into a re-login hint.

func NewEntireAPICellClient added in v0.8.0

func NewEntireAPICellClient(ctx context.Context, insecureHTTP bool, target *CellTarget) (*api.Client, error)

NewEntireAPICellClient returns an authenticated client aimed at an entire-api cell, carrying the caller's login JWT directly.

Cell selection, in precedence order:

  • target != nil: dial target.BaseURL. This is the repo-scoped path — the caller (cli) resolved the repo's own cell and jurisdiction.
  • the configured data host already targets a cell (host contains ".api."): keep that origin.
  • a loopback data host (local dev): keep that origin.
  • otherwise the data host is a BFF/apex: resolve the caller's home-cell apiUrl from the cluster catalog (home-jurisdiction fallback).

func NewRefreshingLoginProvider added in v0.7.4

func NewRefreshingLoginProvider(c *contexts.Context, transport http.RoundTripper, allowInsecureHTTP bool) (func(context.Context) (string, error), error)

NewRefreshingLoginProvider returns a login-JWT provider (the shape repocreds wants) for context c that transparently re-mints an expired login JWT from the stored refresh token. Call NewRefreshingLoginCredential when a reactive 401 path also needs to force-refresh a rejected token.

It is backed by auth-go's tokenmanager, which is what makes this safe against the server's single-use refresh-token rotation: refreshes are serialised across processes (an advisory file lock) and goroutines, the store is re-read after locking so a late waiter reuses a peer's freshly minted token, and the rotated refresh token is persisted. Without that, two concurrent git-remote-entire processes (e.g. a recursive submodule fetch) could replay the same single-use token and trip the server's reuse detection, revoking the whole family.

A still-valid token is returned with no network call. A context with no stored refresh token degrades gracefully: valid token used, expired token surfaces a re-login error.

transport carries the caller's TLS configuration; allowInsecureHTTP permits an http:// core for loopback/dev.

func NormalizeJurisdiction added in v0.10.4

func NormalizeJurisdiction(value string) (string, error)

NormalizeJurisdiction is the one rule for a user- or claim-supplied jurisdiction: trimmed, lowercased, and constrained to a single DNS label (`--jurisdiction US`, `" us "` and `us` all yield `us`). Empty is returned as "" without error so callers can apply their own default (home).

func ParseEnvToken added in v0.7.8

func ParseEnvToken(raw string) (coreURL, token string, err error)

ParseEnvToken is the single owner of the ENTIRE_TOKEN validation sequence shared by coreapi.New's bypass and `entire auth status`: it trims the raw value, enforces fail-closed that it is non-blank, and derives the control- plane core origin from its aud via CoreURLFromEnvToken. Callers pass the raw env value (presence is the caller's LookupEnv decision) and send the returned token verbatim as the bearer to coreURL. A blank or aud-less value is an error, never a silent fall-back to context resolution.

func RecordLoginContext added in v0.7.0

func RecordLoginContext(rawToken, refreshToken string, activate bool) (string, error)

RecordLoginContext records a freshly obtained login token in the shared contexts.json credential model: it derives the issuer (core URL), handle, and expiry from the token's own claims, stores the token in the OS keyring under the entire-core:<issuer> service scheme entiredb uses, and writes (or updates) the matching context.

Contexts are keyed by identity (core URL + handle): re-logging into the same identity updates its context in place, while a second identity on the same core gets its own context (named handle@host) instead of clobbering the first.

activate controls current_context: true makes the just-completed login active (kubectl use-context style); false records it without switching the user's active account, though it still sets current_context when none exists yet.

This is the CLI's only credential write: a login recorded here is what every consumer resolves against — the control plane, the data API, the in-CLI git remote helper, and entiredb's CLIs, which share this file and keychain layout.

Returns the context name on success.

func RefreshedLoginToken added in v0.7.6

func RefreshedLoginToken(ctx context.Context, c *contexts.Context) (string, error)

RefreshedLoginToken returns context c's login JWT, transparently re-minting an expired one from the stored refresh token. It is the convenience form of NewRefreshingLoginProvider for callers that want a single token now (e.g. `auth status` / `logout`, which must report a refreshable session as alive rather than telling the user to re-login). The insecure-HTTP decision mirrors the control-plane resolver: loopback cores and the --insecure-http-auth opt-in are permitted, everything else requires https.

Errors preserve the tokenmanager sentinels (ErrReauthRequired when the session is genuinely dead, ErrNotLoggedIn when no credential is usable) so callers can branch on errors.Is.

func RememberJurisdictionAudience added in v0.10.0

func RememberJurisdictionAudience(name, audience string) error

RememberJurisdictionAudience adds audience to context `name`'s JurisdictionAudiences, so logout can find the matching keyring slot. Idempotent: an already-recorded audience rewrites nothing.

Callers MUST record before writing the token to the credential store — a persisted-but-unrecorded token is a bearer logout can't find, whereas a failed record that aborts the write costs only one token exchange.

func RemoveContext added in v0.7.4

func RemoveContext(name string) error

RemoveContext deletes the named context's keyring tokens, then its contexts.json entry. A missing context is a no-op. Used by logout and `logout --all-contexts`. File.Delete clears current_context when name was the active one, so removing the current context this way also logs it out.

func RemoveCurrentContext added in v0.7.0

func RemoveCurrentContext() error

RemoveCurrentContext deletes the acting context's keyring tokens and its contexts.json entry, clearing current_context when it pointed there. It is a no-op (returns nil) when there is no acting context. Used by logout.

It resolves through File.Active, so `entire logout --context staging` removes the login it just revoked. Resolving the removal target differently from the revocation target (which comes from resolveStatusTarget, also via Active) would end one session server-side while deleting a different login's credentials locally.

func ResolveDataAPIToken added in v0.7.6

func ResolveDataAPIToken(ctx context.Context, dataBaseURL string) (string, error)

ResolveDataAPIToken returns the bearer for the data plane at dataBaseURL: the active context's refreshed login JWT — the account access token (scope entire:session) that the entire.io gateway and the entire-api cells accept directly, and that the gateway uses to mint per-jurisdiction cell tokens itself (COR-1095).

It used to return an RFC 8693 exchange of that JWT for the data host's audience (a narrower entire:api-access token). Cell-backed gateway routes can no longer serve that shape: the gateway had to re-exchange it at entire-core to reach a cell, and core refuses a non-session subject — which is how every released CLI's `entire dispatch` 502'd from 2026-08-20.

Discovery is unchanged and remains the only path: the host's /.well-known/entire-api.json names the login servers it trusts, and the ACTIVE auth context must be issued by one of them. Pointing the CLI at another environment therefore still takes two steps, because the acting identity is never inferred from the target host:

entire auth use staging
ENTIRE_API_BASE_URL=https://partial.to entire activity

A host that doesn't advertise discovery (unreachable / 404 / 503 / malformed) is an error — without it we can't know which login servers the host trusts, and guessing risks presenting a token to a host that doesn't accept that core (see clusterdiscovery.selectLoginContext).

Callers that honour --insecure-http-auth must call EnableInsecureHTTP before invoking this (as they already do); the per-context refresh reads that global opt-in.

func SetCellExchangeTransportForTest added in v0.8.0

func SetCellExchangeTransportForTest(t interface{ Helper() }, rt http.RoundTripper) func()

SetCellExchangeTransportForTest overrides the transport used for jurisdiction token exchange and cluster listing, returning a restore closure — the same set/restore convention the rest of the package uses for test seams.

func SetCurrentContext added in v0.7.0

func SetCurrentContext(name string) error

SetCurrentContext makes name the active context. Returns an error when no context with that name exists (a stale current pointer is a foot-gun).

func SetResolveContextForAPIForTest added in v0.7.6

func SetResolveContextForAPIForTest(t interface{ Helper() }, fn resolveContextFunc) func()

SetResolveContextForAPIForTest overrides the /.well-known/entire-api.json discovery seam and returns a cleanup func. Tests in other packages that exercise a data-API command (activity/search/dispatch/recap) MUST install this — otherwise ResolveDataAPIToken makes a real network call to the configured data host. Test-only.

func SetResolveContextForCellAPIForTest added in v0.8.0

func SetResolveContextForCellAPIForTest(t interface{ Helper() }, fn resolveContextFunc) func()

SetResolveContextForCellAPIForTest overrides the cell-API discovery seam.

func StoredContexts added in v0.10.1

func StoredContexts() ([]*contexts.Context, string, error)

StoredContexts returns all stored login contexts and the STORED current_context, ignoring any `--context`/$ENTIRE_CONTEXT override.

Use this for questions about what is *persisted* — does a default exist, what should become the new default — as opposed to which identity is *acting*, which is Contexts. Resolving the acting identity here would answer the wrong question: after `logout --context staging` the override names a context that no longer exists, so Active fails and a caller asking "is a default still set?" would silently get an error instead of "no".

Types

type BrowserAuthFlow added in v0.7.6

type BrowserAuthFlow struct {
	// contains filtered or unexported fields
}

BrowserAuthFlow is one in-progress loopback authorization-code login. It wraps an authcode.Flow, flattening the TokenSet to the (access, refresh) pair login.go persists — mirroring how PollDeviceAuth flattens the device-flow result. login.go depends on a small local interface that this concrete type satisfies, so it can fake the flow in tests.

func (*BrowserAuthFlow) AuthorizationURL added in v0.7.6

func (f *BrowserAuthFlow) AuthorizationURL() string

AuthorizationURL is the URL to open in the user's browser.

func (*BrowserAuthFlow) Close added in v0.7.6

func (f *BrowserAuthFlow) Close() error

Close tears down the loopback listener. Safe to call after Wait.

func (*BrowserAuthFlow) Exchange added in v0.7.6

func (f *BrowserAuthFlow) Exchange(ctx context.Context, code string) (accessToken, refreshToken string, err error)

Exchange redeems code for access + refresh tokens.

func (*BrowserAuthFlow) Issuer added in v0.10.1

func (f *BrowserAuthFlow) Issuer() string

Issuer is the RFC 9207 `iss` parameter the login server attached to the loopback callback, or "" when it sent none. Only populated after Wait.

It is reported verbatim and is NOT validated here — a dispatching login server legitimately names a different host than the one dialled, so the caller has to apply the trust rule (see issMatches in login.go) before handing the value to UseTokenIssuer.

func (*BrowserAuthFlow) UseTokenIssuer added in v0.10.1

func (f *BrowserAuthFlow) UseTokenIssuer(origin string) error

UseTokenIssuer redeems the authorization code at origin instead of the dialled login server, for an apex that dispatches the browser to a regional login server and serves no token endpoint of its own. The authorization code and the resulting tokens travel to origin, so callers must vet it first.

func (*BrowserAuthFlow) Wait added in v0.7.6

func (f *BrowserAuthFlow) Wait(ctx context.Context) (string, error)

Wait blocks until the browser is redirected to the loopback listener, returning the authorization code.

type CellClientFactory added in v0.8.1

type CellClientFactory struct {
	// contains filtered or unexported fields
}

CellClientFactory builds entire-api cell clients from a single resolved login subject. A caller dialing several cells in one operation (multi-cell fan-out over the caller's repos) should build one factory and reuse it for every cell, instead of paying discovery + login refresh once per cell via NewEntireAPICellClient.

A factory is safe for concurrent use, and holds credentials resolved at construction time — build it per operation, don't store it long-term. Like NewEntireAPICellClient it deliberately does NOT consult ENTIRE_TOKEN.

func NewEntireAPICellClientFactory added in v0.8.1

func NewEntireAPICellClientFactory(ctx context.Context, insecureHTTP bool) (*CellClientFactory, error)

NewEntireAPICellClientFactory resolves the active stored login credential once, for building clients aimed at several cells. See NewEntireAPICellClient for the single-cell convenience wrapper.

func (*CellClientFactory) ClientFor added in v0.8.1

func (f *CellClientFactory) ClientFor(ctx context.Context, target *CellTarget) (*api.Client, error)

ClientFor returns an authenticated client for the given cell target (nil falls back to home-jurisdiction routing), using the resolved login JWT as its bearer.

type CellTarget added in v0.8.0

type CellTarget struct {
	// BaseURL is the cell's apiUrl to dial (e.g. https://aws-eu-west-1.api.entire.io).
	BaseURL string
	// Jurisdiction is the repo's cluster jurisdiction; it drives cell routing.
	Jurisdiction string
}

CellTarget pins the entire-api cell a repo-scoped call must reach and its jurisdiction. The cli layer resolves it from the repo's own cluster (via coreapi mirrors/clusters), so a repo-scoped route reaches the cell that HOSTS the repo — not the caller's home cell. A nil target falls back to home-jurisdiction routing (derived from the login JWT), which is correct for the common same-region case and for local dev.

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client wraps a deviceflow.Client and an authcode.Client preconfigured for the entire-cli public client (see provider.go for the endpoint wiring).

func NewClient

func NewClient(server string, httpClient *http.Client, allowInsecureHTTP bool) *Client

NewClient constructs a Client for the device-flow login against server (the login-server origin, validated by the caller — `entire login --server`). httpClient.Transport is reused when non-nil (its TLS / proxy config flows through); a nil httpClient or nil Transport falls back to the deviceflow default (http.DefaultTransport).

HTTPS is required by default. Loopback http:// (localhost, 127.0.0.1, ::1) is always permitted — see isLoopbackHTTP. allowInsecureHTTP=true additionally permits non-loopback http:// for cases like local-dev auth hosts on a private network (e.g. http://devbox.internal); the CLI plumbs this from the --insecure-http-auth flag.

func (*Client) BaseURL

func (c *Client) BaseURL() string

BaseURL returns the login-server origin this client dialled.

func (*Client) PollDeviceAuth

func (c *Client) PollDeviceAuth(ctx context.Context, deviceCode string) (*DeviceAuthPoll, error)

PollDeviceAuth polls the token endpoint. On any OAuth-protocol error (recognised RFC 8628 §3.5 sentinel or unknown but spec-shaped code like invalid_request / invalid_client / server_error), the wire-side code is returned in DeviceAuthPoll.Error so the existing polling loop in login.go can branch on it — known codes hit the dedicated switch arms, unknown codes fall through to the default arm and fail fast. Non-protocol errors (network, decode) are returned as a real error and treated as transient by the polling loop.

func (*Client) StartBrowserAuth added in v0.7.6

func (c *Client) StartBrowserAuth(ctx context.Context) (*BrowserAuthFlow, error)

StartBrowserAuth begins the loopback authorization-code flow: it binds a local listener and returns a flow carrying the browser URL to open.

func (*Client) StartDeviceAuth

func (c *Client) StartDeviceAuth(ctx context.Context) (*DeviceAuthStart, error)

StartDeviceAuth requests a fresh device code.

func (*Client) UseTokenIssuer added in v0.10.1

func (c *Client) UseTokenIssuer(origin string) error

UseTokenIssuer points subsequent device-flow token polls at origin instead of BaseURL, for an apex login server that redirected /device_authorization to a regional one and serves no token endpoint of its own (DeviceAuthStart.ResponseOrigin reports where the request landed). The device code and the resulting tokens travel to origin, so callers must vet it first. An empty origin clears the override.

type ControlPlaneTarget added in v0.7.6

type ControlPlaneTarget struct {
	CoreURL     string
	TokenSource func(context.Context) (string, error)
}

ControlPlaneTarget is the resolved login server a control-plane request (org/repo/project/grant) should dial, plus the bearer source for it.

CoreURL is an origin (no /api/v1 suffix); the caller appends the API base path. TokenSource returns a bearer valid for CoreURL, re-minting silently from the stored refresh token when the active context drives resolution.

func ResolveControlPlaneTarget added in v0.7.6

func ResolveControlPlaneTarget() (ControlPlaneTarget, error)

ResolveControlPlaneTarget chooses which core the control-plane commands talk to and how their bearer is obtained. The control-plane host *is* a core, so there is no /.well-known discovery here — the active context names the core, which is what makes `entire auth use <ctx>` retarget the control plane onto that login server. The bearer is a per-context refreshing provider (silent JWT re-mint from the stored refresh token).

No active context means not logged in: the error wraps ErrNotLoggedIn so callers render the `entire login` hint. There is no fallback host — a control-plane command without a login has no identity to act as.

func ResolveControlPlaneTargetForCluster added in v0.7.8

func ResolveControlPlaneTargetForCluster(ctx context.Context, clusterHost string) (ControlPlaneTarget, error)

ResolveControlPlaneTargetForCluster chooses which core a *resource-provider* control-plane command should dial — one whose subject is a mirror on a specific cluster (mirror create/remove, mirror collaborators list) rather than the caller's own account.

Unlike ResolveControlPlaneTarget, the core is NOT taken from the active context: a cluster's mirror lives in the federation that fronts that cluster, which may differ from the active login (e.g. a partial.to context acting on a prod entire.io cluster). We discover the cluster's trusted cores from its /.well-known/entire-cluster.json and require the ACTIVE context to be issued by one of them — exactly as git and data-API resolution do (see ResolveDataAPIToken). The bearer is that context's refreshing login provider (silent JWT re-mint from its stored refresh token).

When the active context isn't trusted by the cluster the discovery resolver says so and names the saved logins that are (or, when none is, the cluster's cores), so the user switches with `entire auth use` or logs in to the right federation rather than seeing an opaque "unknown cluster_host" 400.

type DeviceAuthPoll

type DeviceAuthPoll struct {
	AccessToken      string
	RefreshToken     string
	TokenType        string
	ExpiresIn        int
	Scope            string
	Error            string
	ErrorDescription string
}

DeviceAuthPoll is the historical token-poll response shape. The shim flattens deviceflow's typed errors back into the Error field so existing login.go logic that switches on result.Error keeps working.

ErrorDescription carries the optional `error_description` from the server's RFC 8628 §3.5 error response, when present. Used to give callers a more actionable message than the bare error code.

type DeviceAuthStart

type DeviceAuthStart = deviceflow.DeviceCode

DeviceAuthStart preserves the historical type name; the shape now matches deviceflow.DeviceCode field-for-field.

type RefreshingLoginCredential added in v0.10.0

type RefreshingLoginCredential struct {
	// contains filtered or unexported fields
}

RefreshingLoginCredential resolves a context's login JWT and can force a refresh after a server rejects a still-locally-valid token.

func NewRefreshingLoginCredential added in v0.10.0

func NewRefreshingLoginCredential(c *contexts.Context, transport http.RoundTripper, allowInsecureHTTP bool) (*RefreshingLoginCredential, error)

NewRefreshingLoginCredential returns a refreshable login credential for context c.

func (*RefreshingLoginCredential) ForceRefresh added in v0.10.0

func (c *RefreshingLoginCredential) ForceRefresh(ctx context.Context, staleToken string) (string, error)

ForceRefresh re-mints the login JWT after staleToken was rejected by the server despite still appearing locally valid.

func (*RefreshingLoginCredential) Token added in v0.10.0

Token returns a locally fresh login JWT, refreshing it when needed.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL