identity

package
v0.1.0-alpha.5 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 11, 2026 License: Apache-2.0 Imports: 14 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func MintBiscuitToken

func MintBiscuitToken(signingKey ed25519.PrivateKey, claims jwt.MapClaims, token *oidc.IDToken, remotePeer peer.ID, biscuitExpiry time.Time, roles []string, policyRoles []*api.PolicyRole, region string) ([]byte, []string, error)

MintBiscuitToken generates a signed Biscuit token for a peer with policy rules based on JWT claims. region is the control-plane-attested region claim (canonical, pre-validated); empty means no claim.

func MintBootstrapBiscuitToken

func MintBootstrapBiscuitToken(signingKey ed25519.PrivateKey, remotePeer peer.ID, role string, expiration time.Time, policyRoles []*api.PolicyRole, region string) ([]byte, error)

MintBootstrapBiscuitToken generates a signed Biscuit token for a peer using a bootstrap role. region is the control-plane-attested region claim (canonical, pre-validated); empty means no claim.

func VerifyAndExtractPeerID

func VerifyAndExtractPeerID(trustedPublicKeys []ed25519.PublicKey, biscuitData []byte, timeout time.Duration) (peer.ID, error)

VerifyAndExtractPeerID checks that the biscuit is signed by one of the trusted keys and returns the peer ID. This function does NOT perform time checks, making it suitable for token refresh flows.

func VerifyBiscuit

func VerifyBiscuit(biscuitData []byte, expectedPeer peer.ID, trustedPublicKeys []ed25519.PublicKey, timeout time.Duration) (*biscuit.Biscuit, error)

VerifyBiscuit verifies the validity of a Biscuit token. It ensures that: 1. The token is cryptographically signed by one of the trustedPublicKeys. 2. The token is not expired. 3. The token is securely bound to the expected remotePeer.

func VerifyBiscuitAndGetKey

func VerifyBiscuitAndGetKey(biscuitData []byte, expectedPeer peer.ID, trustedPublicKeys []ed25519.PublicKey, timeout time.Duration) (*biscuit.Biscuit, ed25519.PublicKey, error)

func VerifyBiscuitRole

func VerifyBiscuitRole(biscuitData []byte, controlPlanePubKey ed25519.PublicKey, expectedRole string) error

VerifyBiscuitRole checks that the biscuit is signed by the control plane's public key and contains the specified role fact.

func VerifyJWT

func VerifyJWT(ctx context.Context, jwtStr string, allowedAudiences []string, providers map[string]*oidc.Provider) (jwt.MapClaims, *oidc.IDToken, error)

VerifyJWT parses and cryptographically validates a JWT token against a list of allowed audiences and resolved OIDC providers.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL