Documentation
¶
Overview ¶
Package accessmode implements deployment access posture: access mode normalization, listen-address classification, and cross-field posture validation used by core config.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ( ErrUnknownAccessMode = errors.New("access.mode: unknown value") ErrSingleUserBroadBind = errors.New("access.mode: single_user must not bind to all interfaces") ErrSingleUserNonLoopback = errors.New("access.mode: single_user allows only loopback listener addresses") ErrSingleUserMalformedAddress = errors.New("access.mode: single_user requires a valid loopback server.address") ErrSingleUserUnknownListenClass = errors.New("access.mode: single_user: unknown listen classification") ErrMultiUserIncompatibleNoAuth = errors.New("access.mode: multi_user is incompatible with server.auth_mode no_auth") ErrMultiUserHandlerRequired = errors.New("access.mode: multi_user requires auth.handler") ErrMultiUserLocalNoopDisallowed = errors.New("access.mode: multi_user requires authentication stronger than local_noop") ErrMultiUserRequiredLevelTooWeak = errors.New("access.mode: multi_user requires auth.required_level beyond none") ErrMultiUserUnknownHandler = errors.New("access.mode: multi_user unknown auth.handler") ErrMultiUserUnknownRequiredLevel = errors.New("access.mode: multi_user unknown auth.required_level") ErrMultiUserInternalUnknownMode = errors.New("access.mode: internal error, unknown mode") ErrMultiUserFlagRequired = errors.New("access.mode: multi_user requires the --multi-user flag on serve") ErrMultiUserFlagInconsistent = errors.New("access.mode: --multi-user flag is inconsistent with non-multi_user config") )
Sentinel errors for ValidatePosture and NormalizeMode. Use errors.Is in tests and callers.
var ErrMalformedListenAddress = errors.New("accessmode: malformed listen address")
ErrMalformedListenAddress is returned by ClassifyListenAddress when the address is not a usable host:port bind string (e.g. empty, missing port, or unparseable).
Functions ¶
func ValidatePosture ¶
func ValidatePosture(in PostureInput) error
ValidatePosture enforces access-mode and authentication posture rules (tasks 2.3, design AccessMode). It does not validate backend credential eligibility (separate task 7.x).
func ValidateServeModeGate ¶
ValidateServeModeGate enforces the CLI opt-in contract for multi-user serve:
- access.mode multi_user requires an explicit `--multi-user` flag on serve.
- `--multi-user` with a non-multi_user config is inconsistent and must fail rather than silently doing nothing.
multiUserFlag is nil when the operator did not pass `--multi-user`; a non-nil pointer reflects the parsed bool value (including an explicit `--multi-user=false`).
mode is the typed, already-normalized access mode produced by [config.Config.EffectiveAccessMode]. Invalid raw mode strings are rejected at the config parsing layer by NormalizeMode (returning ErrUnknownAccessMode); an empty mode is treated as single_user for parity with that layer. The gate trusts the typed mode and therefore does not re-normalize.
Types ¶
type ListenClassification ¶
ListenClassification is the parsed listen address plus a conservative surface kind. Hostname binds (other than localhost) are always SurfaceNonLoopback because loopback cannot be proven without resolution.
func ClassifyListenAddress ¶
func ClassifyListenAddress(raw string) (ListenClassification, error)
ClassifyListenAddress parses host/port and classifies bind posture.
type Mode ¶
type Mode string
Mode is deployment access posture (immutable after startup).
func NormalizeMode ¶
NormalizeMode maps YAML access.mode to a typed mode. Empty string defaults to single_user.
type PostureInput ¶
type PostureInput struct {
Mode Mode
Listen ListenClassification
Handler string
RequiredLevel string
LegacyAuthMode string
}
PostureInput carries effective access, listener, and auth policy for startup validation. LegacyAuthMode is the raw server.auth_mode value ("", "no_auth", "external").