Documentation
¶
Overview ¶
Package httpsignature signs FH responses using the Ed25519 response profile implemented by pkg/httpsignature and the wire format defined by RFC 9421.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func CheckAndStore ¶
Types ¶
type Config ¶
type Config struct {
PrivateKey ed25519.PrivateKey
KeyID string
Label string
// Origin is the externally visible request origin, such as
// https://api.example.com. It is required so @target-uri is not derived from
// attacker-controlled forwarding headers.
Origin string
// AllowedOrigins adds exact alternative external origins. The request Host
// selects one of these validated origins; unlisted hosts fail closed.
AllowedOrigins []string
// AllowInsecureDevelopmentOrigins permits explicit HTTP origins outside
// loopback. Use only for development servers intentionally exposed to a LAN.
// The default is false, so production remains HTTPS-only.
AllowInsecureDevelopmentOrigins bool
Validity time.Duration
MaxBodySize int
NonceStore kv.Store
Now func() time.Time
Skip func(fh.Ctx) bool
}
Click to show internal directories.
Click to hide internal directories.