conjur

package
v1.12.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 14 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func MockConjurExchangeServer

func MockConjurExchangeServer(t testing.TB, token string) (*httptest.Server, *http.Client)

MockConjurExchangeServer returns a TLS server whose authn-jwt endpoint returns the given token.

func MockConjurExchangeServerStatus

func MockConjurExchangeServerStatus(t testing.TB, status int) (*httptest.Server, *http.Client)

func MockConjurExchangeServerStatusBody

func MockConjurExchangeServerStatusBody(t testing.TB, status int, body []byte) (*httptest.Server, *http.Client)

MockConjurExchangeServerStatusBody is like MockConjurExchangeServerStatus but also writes body, for asserting the client surfaces Conjur's own error message rather than discarding it.

Types

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client exchanges a JWT for a Conjur access token and authenticates requests with it.

func New

func New(httpClient *http.Client, baseURL, serviceID, account string, src jwtsource.Source) *Client

func (*Client) AuthenticateRequest

func (c *Client) AuthenticateRequest(req *http.Request) (string, error)

AuthenticateRequest implements identity.RequestAuthenticator.

It exchanges the JWT for a Conjur access token, sets the Authorization header, and returns an identity string for audit tagging. The identity is the token's own `sub` claim when it can be extracted; otherwise it falls back to the configured service ID so a token in an unexpected shape never fails the request.

A cached token is re-exchanged refreshSkew before its real expiry, so a request is never authenticated with a token that expires while it is in flight.

The mutex is held across the exchange's network round-trip so concurrent callers share one exchange instead of a thundering herd; they're effectively serial at the current call sites. Whichever caller wins the race also controls the exchange's deadline via its own req.Context(), so an unrelated cancellation can fail a waiting caller — acceptable for now given the current call pattern.

func (*Client) Invalidate

func (c *Client) Invalidate()

Invalidate clears the cached token, forcing the next AuthenticateRequest call to exchange a fresh one. Callers should call this after a 401 from the resource server the token was used against — the cache's own expiry tracking only catches a token aging out, not one rejected early (e.g. a Conjur restart or a toggled authenticator).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL