Documentation
¶
Overview ¶
Package identitystore provides a PostgreSQL-backed principal, session, local password, and bearer store. Credential surfaces are published only when the consumer explicitly provisions that credential kind.
Stability: alpha. Consumers should pin an exact pre-v1 Modary version.
Index ¶
Constants ¶
const ( // ModuleID intentionally retains the durable v0.2 migration owner. Package // naming may evolve; a migration owner must not be renamed underneath an // already initialized database. ModuleID = "local-identity" DefaultSessionTTL = 12 * time.Hour MaximumSessionTTL = 30 * 24 * time.Hour StandardPasswordCheckConcurrency = 2 MaximumConcurrentPasswordChecks = 32 )
Adapter identity, session, and Argon2 concurrency limits.
Variables ¶
var ( ErrContextRequired = errors.New("PostgreSQL identity store context is required") ErrActorNotFound = identity.ErrActorNotFound ErrAuthenticationFailed = identity.ErrAuthenticationFailed ErrSessionInvalid = identity.ErrSessionInvalid ErrRandomSourcePanic = errors.New("PostgreSQL identity store random source panicked") )
Adapter errors mirror public identity classifications and add local failure modes for context and injected randomness.
Functions ¶
func GenerateBearerToken ¶
GenerateBearerToken returns a URL-safe bearer credential with 256 bits of entropy from crypto/rand. The caller is responsible for displaying or persisting the plaintext exactly once; identitystore stores only its digest.
func Module ¶
func Module(options Options) (module.Registration, error)
Module returns a pure Registration. Options are validated and defensively copied before any database, migration, random, or hashing work occurs. The returned consumer-owned Registration captures that copy, including plaintext provisioning credentials; callers should retain it only as long as their composition source requires. A started Application does not retain the startup callback after provisioning completes.
Types ¶
type BearerToken ¶
BearerToken is one explicitly provisioned bearer credential. TokenID is a non-secret stable identifier used for rotation and revocation. Token must be generated from at least 256 bits of cryptographically secure randomness; GenerateBearerToken provides the recommended representation.
type Options ¶
type Options struct {
Principals []Principal
PasswordCredentials []PasswordCredential
BearerTokens []BearerToken
RevokedActorIDs []string
RevokedTokenIDs []string
SessionTTL time.Duration
// MaxConcurrentPasswordChecks bounds Argon2 memory use. Zero selects the
// conservative limit; values above MaximumConcurrentPasswordChecks fail.
MaxConcurrentPasswordChecks int
// Random overrides crypto/rand for password salts and session material. A
// production override must be a concurrency-safe CSPRNG. Reads are serialized;
// deterministic readers are suitable only for tests.
Random io.Reader
}
Options is an explicit provisioning and revocation patch. Empty provisioning creates only schema; omitted durable principals and credentials are retained. A password or actor type change invalidates sessions. An actor type change also invalidates sessions and deactivates bearer credentials; a BearerTokens entry in the same patch explicitly reactivates or replaces that credential. Password verification concurrency is bounded in-process; network and account rate limiting remain deployment responsibilities.
type PasswordCredential ¶
PasswordCredential is one explicitly provisioned username/password login for an existing or concurrently provisioned principal.