Documentation
¶
Index ¶
Constants ¶
const ( MockSuccessUser = successUser MockSuccessPassword = successPassword )
Exported credentials that MockIdentityServer accepts as a successful username/password login. Used by other packages' tests that exercise the legacy UP auth path against the mock server.
const ( // MechanismUsernamePassword is the string which identifies the username/password mechanism for completing // a login attempt MechanismUsernamePassword = "UP" // ActionAnswer is the string which is sent to an AdvanceAuthentication request to indicate we're providing // the credentials in band in text format (i.e., we're sending a password) ActionAnswer = "Answer" // SummaryLoginSuccess is returned by a StartAuthentication to indicate that login does not need // to proceed to the AdvanceAuthentication step. // We don't handle this because we don't expect it to happen. SummaryLoginSuccess = "LoginSuccess" // SummaryNewPackage is returned by a StartAuthentication call when the user must complete a challenge // to complete the log in. This is expected on a first login. SummaryNewPackage = "NewPackage" )
Variables ¶
This section is empty.
Functions ¶
Types ¶
type Client ¶
type Client struct {
// contains filtered or unexported fields
}
Client is a client for interacting with the CyberArk Identity API. It caches an authentication token and exposes it for use by AuthenticateRequest.
func (*Client) AuthenticateRequest ¶
AuthenticateRequest is a helper function that adds the Authorization header to an HTTP request using a cached token, refreshing it first if it's aged past tokenTTL. It sets the Header directly, and if successful returns the username corresponding to the token.
Refresh needs LoginUsernamePassword to have been called at least once — that's where the username/password this re-login uses gets captured. If a refresh attempt fails, this falls back to whatever's cached rather than failing the request outright: the failure is likely transient, and the next call will retry.
func (*Client) LoginUsernamePassword ¶
LoginUsernamePassword performs a blocking call to fetch an auth token from CyberArk Identity using the given username and password. It keeps its own internal copy of both so AuthenticateRequest can re-login on its own once the token ages out, without the password being passed in again — it does NOT zero the caller's slice: a caller (e.g. NewCyberArk's ClientConfig, reused across every upload) may need to pass the same slice into a future call, and wiping it here would silently break that on the second call. Tokens are cached internally and are not directly accessible to code; use Client.AuthenticateRequest to add credentials to an *http.Request.