Documentation
¶
Overview ¶
Package httpauth defines transport-layer authentication contracts for the standard HTTP distribution (design §13, R4). HTTP types, Provider, and AuthErrorRenderer live here; semantic auth DTOs remain in github.com/matdev83/go-llm-interactive-proxy/pkg/lipsdk/auth. Principal context is stored through github.com/matdev83/go-llm-interactive-proxy/pkg/lipsdk/execview (same context key as execview.WithPrincipal).
Errors: Provider.Authenticate errors may be logged by stdhttp integration. Implementations must return errors without secrets, bearer tokens, or other high-entropy credential material.
Index ¶
- func CredentialMatcherFromContext(ctx context.Context) (secretguard.Matcher, bool)
- func PrincipalFromContext(ctx context.Context) (execview.PrincipalView, bool)
- func ScopeFromContext(ctx context.Context) (scope.PrincipalScopeView, bool)
- func WithCredentialMatcher(ctx context.Context, m secretguard.Matcher) context.Context
- func WithIngressAttribution(ctx context.Context, a IngressAttribution) context.Context
- func WithPrincipal(ctx context.Context, p execview.PrincipalView) context.Context
- func WithScope(ctx context.Context, v scope.PrincipalScopeView) context.Context
- type AuthErrorRenderInput
- type AuthErrorRenderResult
- type AuthErrorRenderer
- type AuthenticationResult
- type AuthenticationType
- type IngressAttribution
- type Provider
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func CredentialMatcherFromContext ¶
func CredentialMatcherFromContext(ctx context.Context) (secretguard.Matcher, bool)
CredentialMatcherFromContext delegates to secretguard.RequestMatcherFromContext.
func PrincipalFromContext ¶
func PrincipalFromContext(ctx context.Context) (execview.PrincipalView, bool)
PrincipalFromContext is a transport-named alias for execview.PrincipalFromContext.
func ScopeFromContext ¶
func ScopeFromContext(ctx context.Context) (scope.PrincipalScopeView, bool)
ScopeFromContext is a transport-named alias for scope.ScopeFromContext.
func WithCredentialMatcher ¶
WithCredentialMatcher delegates to secretguard.WithRequestMatcher.
func WithIngressAttribution ¶
func WithIngressAttribution(ctx context.Context, a IngressAttribution) context.Context
WithIngressAttribution delegates to secretguard.WithIngressAttribution.
func WithPrincipal ¶
WithPrincipal is a transport-named alias for execview.WithPrincipal so the auth middleware and the policy core share one context key without the core importing this package.
func WithScope ¶
WithScope is a transport-named alias for scope.WithScope so transport auth and the core share one context key for the authoritative principal/scope snapshot.
Types ¶
type AuthErrorRenderInput ¶
type AuthErrorRenderInput = lipsdk.AuthErrorRenderInput
Transport-local aliases for auth error rendering contracts defined on github.com/matdev83/go-llm-interactive-proxy/pkg/lipsdk so stdhttp and plugins can refer to this subpackage without duplicating types, while internal/core avoids a transitive dependency on pkg/lipsdk/transport (see internal/archtest).
type AuthErrorRenderResult ¶
type AuthErrorRenderResult = lipsdk.AuthErrorRenderResult
Transport-local aliases for auth error rendering contracts defined on github.com/matdev83/go-llm-interactive-proxy/pkg/lipsdk so stdhttp and plugins can refer to this subpackage without duplicating types, while internal/core avoids a transitive dependency on pkg/lipsdk/transport (see internal/archtest).
type AuthErrorRenderer ¶
type AuthErrorRenderer = lipsdk.AuthErrorRenderer
Transport-local aliases for auth error rendering contracts defined on github.com/matdev83/go-llm-interactive-proxy/pkg/lipsdk so stdhttp and plugins can refer to this subpackage without duplicating types, while internal/core avoids a transitive dependency on pkg/lipsdk/transport (see internal/archtest).
type AuthenticationResult ¶
type AuthenticationResult struct {
Type AuthenticationType
// Principal is used when Type is TypePrincipal.
Principal execview.PrincipalView
// Scope is an optional authoritative safe principal/scope snapshot carried from trusted
// auth provider code into the middleware. It is nil for legacy principal-only results.
// Raw secrets and transport headers must never be placed here (requirements 2.1, 2.6).
Scope *scope.PrincipalScopeView
// IngressAttribution is sanitized peer/frontend/device attribution (zero means absent).
// Never place bearer tokens or raw headers here.
IngressAttribution IngressAttribution
// HTTPStatus is used for TypeReject and TypeChallenge (default 401 if zero).
HTTPStatus int
// Headers is copied for TypeChallenge (and optional metadata for TypeReject).
Headers http.Header
// Body is optional for TypeReject and TypeChallenge.
Body []byte
// ContentType is optional for TypeReject and TypeChallenge. When non-empty, stdhttp
// sets the Content-Type response header. When empty with a non-empty Body, the default
// is "text/plain; charset=utf-8" (pre-1.x compatible).
ContentType string
// ResponseHeaders are merged on the success path when Type is TypeAnnotate.
// The stdhttp integration allow-lists safe response header names (cache, security
// meta, Vary); disallowed names (e.g. Set-Cookie) are dropped with a warning log.
ResponseHeaders http.Header
}
AuthenticationResult is the typed outcome from Provider.Authenticate.
func (AuthenticationResult) EffectiveStatus ¶
func (r AuthenticationResult) EffectiveStatus() int
EffectiveStatus returns a non-zero HTTP status for reject/challenge results.
type AuthenticationType ¶
type AuthenticationType uint8
AuthenticationType classifies the outcome of one provider invocation.
const ( // TypeContinue means this provider did not terminate the chain; processing continues. TypeContinue AuthenticationType = iota // TypePrincipal attaches identity and continues the provider chain. TypePrincipal // TypeReject ends the request with HTTPStatus and optional Body. TypeReject // TypeChallenge ends the request with HTTPStatus and response Headers (e.g. WWW-Authenticate). TypeChallenge // TypeAnnotate merges ResponseHeaders onto the outbound response and continues the chain. TypeAnnotate )
type IngressAttribution ¶
type IngressAttribution = secretguard.IngressAttribution
IngressAttribution is a transport alias for secretguard.IngressAttribution so auth middleware and core share one type without core importing this package.
func IngressAttributionFromContext ¶
func IngressAttributionFromContext(ctx context.Context) (IngressAttribution, bool)
IngressAttributionFromContext delegates to secretguard.IngressAttributionFromContext.
type Provider ¶
type Provider interface {
Authenticate(ctx context.Context, w http.ResponseWriter, r *http.Request) (AuthenticationResult, error)
}
Provider performs transport-native authentication before frontend decode (R4). Returning a non-nil error is fail-closed for that provider. Implementations must not write to w unless returning TypeReject or TypeChallenge (or annotate-only paths that only add headers via the result, applied by the stdhttp integration layer). For TypeReject/TypeChallenge, AuthenticationResult.ContentType is optional: when set, the stdhttp integration sets the Content-Type response header; otherwise a non-empty Body uses "text/plain; charset=utf-8".