httpauth

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 6 Imported by: 0

Documentation

Overview

Package httpauth defines transport-layer authentication contracts for the standard HTTP distribution (design §13, R4). HTTP types, Provider, and AuthErrorRenderer live here; semantic auth DTOs remain in github.com/matdev83/go-llm-interactive-proxy/pkg/lipsdk/auth. Principal context is stored through github.com/matdev83/go-llm-interactive-proxy/pkg/lipsdk/execview (same context key as execview.WithPrincipal).

Errors: Provider.Authenticate errors may be logged by stdhttp integration. Implementations must return errors without secrets, bearer tokens, or other high-entropy credential material.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func CredentialMatcherFromContext

func CredentialMatcherFromContext(ctx context.Context) (secretguard.Matcher, bool)

CredentialMatcherFromContext delegates to secretguard.RequestMatcherFromContext.

func PrincipalFromContext

func PrincipalFromContext(ctx context.Context) (execview.PrincipalView, bool)

PrincipalFromContext is a transport-named alias for execview.PrincipalFromContext.

func ScopeFromContext

func ScopeFromContext(ctx context.Context) (scope.PrincipalScopeView, bool)

ScopeFromContext is a transport-named alias for scope.ScopeFromContext.

func WithCredentialMatcher

func WithCredentialMatcher(ctx context.Context, m secretguard.Matcher) context.Context

WithCredentialMatcher delegates to secretguard.WithRequestMatcher.

func WithIngressAttribution

func WithIngressAttribution(ctx context.Context, a IngressAttribution) context.Context

WithIngressAttribution delegates to secretguard.WithIngressAttribution.

func WithPrincipal

func WithPrincipal(ctx context.Context, p execview.PrincipalView) context.Context

WithPrincipal is a transport-named alias for execview.WithPrincipal so the auth middleware and the policy core share one context key without the core importing this package.

func WithScope

WithScope is a transport-named alias for scope.WithScope so transport auth and the core share one context key for the authoritative principal/scope snapshot.

Types

type AuthErrorRenderInput

type AuthErrorRenderInput = lipsdk.AuthErrorRenderInput

Transport-local aliases for auth error rendering contracts defined on github.com/matdev83/go-llm-interactive-proxy/pkg/lipsdk so stdhttp and plugins can refer to this subpackage without duplicating types, while internal/core avoids a transitive dependency on pkg/lipsdk/transport (see internal/archtest).

type AuthErrorRenderResult

type AuthErrorRenderResult = lipsdk.AuthErrorRenderResult

Transport-local aliases for auth error rendering contracts defined on github.com/matdev83/go-llm-interactive-proxy/pkg/lipsdk so stdhttp and plugins can refer to this subpackage without duplicating types, while internal/core avoids a transitive dependency on pkg/lipsdk/transport (see internal/archtest).

type AuthErrorRenderer

type AuthErrorRenderer = lipsdk.AuthErrorRenderer

Transport-local aliases for auth error rendering contracts defined on github.com/matdev83/go-llm-interactive-proxy/pkg/lipsdk so stdhttp and plugins can refer to this subpackage without duplicating types, while internal/core avoids a transitive dependency on pkg/lipsdk/transport (see internal/archtest).

type AuthenticationResult

type AuthenticationResult struct {
	Type AuthenticationType

	// Principal is used when Type is TypePrincipal.
	Principal execview.PrincipalView

	// Scope is an optional authoritative safe principal/scope snapshot carried from trusted
	// auth provider code into the middleware. It is nil for legacy principal-only results.
	// Raw secrets and transport headers must never be placed here (requirements 2.1, 2.6).
	Scope *scope.PrincipalScopeView

	// IngressAttribution is sanitized peer/frontend/device attribution (zero means absent).
	// Never place bearer tokens or raw headers here.
	IngressAttribution IngressAttribution

	// HTTPStatus is used for TypeReject and TypeChallenge (default 401 if zero).
	HTTPStatus int

	// Headers is copied for TypeChallenge (and optional metadata for TypeReject).
	Headers http.Header

	// Body is optional for TypeReject and TypeChallenge.
	Body []byte

	// ContentType is optional for TypeReject and TypeChallenge. When non-empty, stdhttp
	// sets the Content-Type response header. When empty with a non-empty Body, the default
	// is "text/plain; charset=utf-8" (pre-1.x compatible).
	ContentType string

	// ResponseHeaders are merged on the success path when Type is TypeAnnotate.
	// The stdhttp integration allow-lists safe response header names (cache, security
	// meta, Vary); disallowed names (e.g. Set-Cookie) are dropped with a warning log.
	ResponseHeaders http.Header
}

AuthenticationResult is the typed outcome from Provider.Authenticate.

func (AuthenticationResult) EffectiveStatus

func (r AuthenticationResult) EffectiveStatus() int

EffectiveStatus returns a non-zero HTTP status for reject/challenge results.

type AuthenticationType

type AuthenticationType uint8

AuthenticationType classifies the outcome of one provider invocation.

const (
	// TypeContinue means this provider did not terminate the chain; processing continues.
	TypeContinue AuthenticationType = iota
	// TypePrincipal attaches identity and continues the provider chain.
	TypePrincipal
	// TypeReject ends the request with HTTPStatus and optional Body.
	TypeReject
	// TypeChallenge ends the request with HTTPStatus and response Headers (e.g. WWW-Authenticate).
	TypeChallenge
	// TypeAnnotate merges ResponseHeaders onto the outbound response and continues the chain.
	TypeAnnotate
)

type IngressAttribution

type IngressAttribution = secretguard.IngressAttribution

IngressAttribution is a transport alias for secretguard.IngressAttribution so auth middleware and core share one type without core importing this package.

func IngressAttributionFromContext

func IngressAttributionFromContext(ctx context.Context) (IngressAttribution, bool)

IngressAttributionFromContext delegates to secretguard.IngressAttributionFromContext.

type Provider

type Provider interface {
	Authenticate(ctx context.Context, w http.ResponseWriter, r *http.Request) (AuthenticationResult, error)
}

Provider performs transport-native authentication before frontend decode (R4). Returning a non-nil error is fail-closed for that provider. Implementations must not write to w unless returning TypeReject or TypeChallenge (or annotate-only paths that only add headers via the result, applied by the stdhttp integration layer). For TypeReject/TypeChallenge, AuthenticationResult.ContentType is optional: when set, the stdhttp integration sets the Content-Type response header; otherwise a non-empty Body uses "text/plain; charset=utf-8".

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL