Documentation
¶
Index ¶
- func MockConjurExchangeServer(t testing.TB, token string) (*httptest.Server, *http.Client)
- func MockConjurExchangeServerStatus(t testing.TB, status int) (*httptest.Server, *http.Client)
- func MockConjurExchangeServerStatusBody(t testing.TB, status int, body []byte) (*httptest.Server, *http.Client)
- type Client
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func MockConjurExchangeServer ¶
MockConjurExchangeServer returns a TLS server whose authn-jwt endpoint returns the given token.
func MockConjurExchangeServerStatusBody ¶
func MockConjurExchangeServerStatusBody(t testing.TB, status int, body []byte) (*httptest.Server, *http.Client)
MockConjurExchangeServerStatusBody is like MockConjurExchangeServerStatus but also writes body, for asserting the client surfaces Conjur's own error message rather than discarding it.
Types ¶
type Client ¶
type Client struct {
// contains filtered or unexported fields
}
Client exchanges a JWT for a Conjur access token and authenticates requests with it.
func (*Client) AuthenticateRequest ¶
AuthenticateRequest implements identity.RequestAuthenticator.
It exchanges the JWT for a Conjur access token, sets the Authorization header, and returns an identity string for audit tagging. The identity is the token's own `sub` claim when it can be extracted; otherwise it falls back to the configured service ID so a token in an unexpected shape never fails the request.
A cached token is re-exchanged refreshSkew before its real expiry, so a request is never authenticated with a token that expires while it is in flight.
The mutex is held across the exchange's network round-trip so concurrent callers share one exchange instead of a thundering herd; they're effectively serial at the current call sites. Whichever caller wins the race also controls the exchange's deadline via its own req.Context(), so an unrelated cancellation can fail a waiting caller — acceptable for now given the current call pattern.
func (*Client) Invalidate ¶
func (c *Client) Invalidate()
Invalidate clears the cached token, forcing the next AuthenticateRequest call to exchange a fresh one. Callers should call this after a 401 from the resource server the token was used against — the cache's own expiry tracking only catches a token aging out, not one rejected early (e.g. a Conjur restart or a toggled authenticator).