mtls

package
v0.0.26 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: MIT Imports: 4 Imported by: 0

README

mtls middleware

Validates verified client certificate chains for admin APIs, internal routes, and high-trust control plane calls. Use Required to reject requests without a certificate, and use subject/issuer allowlists for tighter service identity controls.

Impact: this blocks unauthenticated clients before business handlers run. Do not trust client-certificate headers unless they come from a trusted TLS-terminating proxy.

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func New

func New(cfg Config) fh.HandlerFunc

func WithPeerCertificates

func WithPeerCertificates(ctx context.Context, certs []*x509.Certificate) context.Context

Types

type Config

type Config struct {
	Required bool
	// AllowUnverified permits PeerCertificates when the TLS stack did not build
	// a verified chain. Leave false for secure deployments. It exists for
	// private-PKI applications that perform all verification in Verify.
	AllowUnverified bool
	AllowedSubjects []string
	AllowedIssuers  []string
	Verify          func(fh.Ctx, []*x509.Certificate) bool
	Error           ErrorHandler
	Next            func(fh.Ctx) bool
}

type ErrorHandler

type ErrorHandler func(fh.Ctx, string) error

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL