identity

package
v1.12.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 19 Imported by: 0

Documentation

Index

Constants

View Source
const (
	MockSuccessUser     = successUser
	MockSuccessPassword = successPassword
)

Exported credentials that MockIdentityServer accepts as a successful username/password login. Used by other packages' tests that exercise the legacy UP auth path against the mock server.

View Source
const (
	// MechanismUsernamePassword is the string which identifies the username/password mechanism for completing
	// a login attempt
	MechanismUsernamePassword = "UP"

	// ActionAnswer is the string which is sent to an AdvanceAuthentication request to indicate we're providing
	// the credentials in band in text format (i.e., we're sending a password)
	ActionAnswer = "Answer"

	// SummaryLoginSuccess is returned by a StartAuthentication to indicate that login does not need
	// to proceed to the AdvanceAuthentication step.
	// We don't handle this because we don't expect it to happen.
	SummaryLoginSuccess = "LoginSuccess"

	// SummaryNewPackage is returned by a StartAuthentication call when the user must complete a challenge
	// to complete the log in. This is expected on a first login.
	SummaryNewPackage = "NewPackage"
)

Variables

This section is empty.

Functions

func MockIdentityServer

func MockIdentityServer(t testing.TB) (string, *http.Client)

MockIdentityServer returns a URL of a mocked CyberArk identity server and an HTTP client with the CA certs needed to connect to it..

Types

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client is a client for interacting with the CyberArk Identity API. It caches an authentication token and exposes it for use by AuthenticateRequest.

func New

func New(httpClient *http.Client, baseURL string, subdomain string) *Client

New returns an initialized CyberArk Identity client.

func (*Client) AuthenticateRequest

func (c *Client) AuthenticateRequest(req *http.Request) (string, error)

AuthenticateRequest is a helper function that adds the Authorization header to an HTTP request using a cached token, refreshing it first if it's aged past tokenTTL. It sets the Header directly, and if successful returns the username corresponding to the token.

Refresh needs LoginUsernamePassword to have been called at least once — that's where the username/password this re-login uses gets captured. If a refresh attempt fails, this falls back to whatever's cached rather than failing the request outright: the failure is likely transient, and the next call will retry.

func (*Client) LoginUsernamePassword

func (c *Client) LoginUsernamePassword(ctx context.Context, username string, password []byte) error

LoginUsernamePassword performs a blocking call to fetch an auth token from CyberArk Identity using the given username and password. It keeps its own internal copy of both so AuthenticateRequest can re-login on its own once the token ages out, without the password being passed in again — it does NOT zero the caller's slice: a caller (e.g. NewCyberArk's ClientConfig, reused across every upload) may need to pass the same slice into a future call, and wiping it here would silently break that on the second call. Tokens are cached internally and are not directly accessible to code; use Client.AuthenticateRequest to add credentials to an *http.Request.

type RequestAuthenticator added in v1.9.0

type RequestAuthenticator func(req *http.Request) (string, error)

Directories

Path Synopsis
cmd
testidentity command

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL