authkitfiber

package module
v0.117.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 22, 2026 License: MIT Imports: 12 Imported by: 0

Documentation

Overview

Package authkitfiber bridges AuthKit's net/http middleware to Fiber v3. Mount registers AuthKit's routes directly on the application. Verification policy stays in verify.

Index

Constants

View Source
const RouteNamePrefix = "authkit."

RouteNamePrefix identifies routes registered by Mount in app.GetRoutes().

Variables

This section is empty.

Functions

func Claims

func Claims(c fiber.Ctx) (verify.Claims, bool)

Claims returns the claims verified by authentication middleware.

func Fallback deprecated

func Fallback(h http.Handler) fiber.Handler

Fallback adapts authhttp.MountHandler to Fiber. Register it last with app.Use so host routes win and all AuthKit paths retain their full prefix.

Deprecated: use Mount to register AuthKit as ordinary, inspectable Fiber routes. Fallback remains available for hosts adapting a custom HTTP handler.

func Mount added in v0.3.0

func Mount(app *fiber.App, svc *authhttp.Service, options ...authhttp.MountOptions) error

Mount registers AuthKit's configured routes directly on app. Each route is visible through app.GetRoutes() and named "authkit.METHOD /path". Call Mount during application setup, before serving requests.

The optional MountOptions selects route groups, exclusions, the API prefix, wrappers, and refresh-cookie policy. JWKS, documents, and browser OIDC retain their standard root paths. Handlers use AuthKit's canonical HTTP pipeline, including authentication, JSON guards, and cookie protections. Unmatched requests continue through Fiber's normal routing; no fallback is installed. Existing routes with the same method and normalized path cause an error; normalization honors CaseSensitive and StrictRouting. This checks exact paths, not overlapping wildcard patterns. Exclude a replaced AuthKit route with MountOptions.ExcludeRoutes before mounting. Every mounted method must be enabled by the app's RequestMethods configuration.

func Optional

func Optional(v *verify.Verifier) fiber.Handler

Optional passes requests without Authorization through anonymously. A present but invalid credential is rejected, just as in verify.Optional.

func OptionalLive added in v0.111.0

func OptionalLive(v *verify.Verifier) (fiber.Handler, error)

OptionalLive admits anonymous requests and checks the liveness of presented native-user credentials. It returns verify.ErrLivenessUnconfigured at startup when no source is wired. Use on routes, groups, or as application middleware.

func Principal

func Principal(c fiber.Ctx) (authkit.Principal, bool)

Principal returns the typed user, API-key, or application principal.

func RequirePermission

func RequirePermission(checker verify.PermissionChecker, perm authkit.Perm, resolve func(fiber.Ctx) verify.PermissionScope) fiber.Handler

RequirePermission checks the canonical permission policy using a Fiber-native scope resolver. Mount after Required or RequiredLive.

func Required

func Required(v *verify.Verifier) fiber.Handler

Required validates a credential and stores verified claims in c.Context(). Like Gin's Required, it accepts every principal the verifier supports. A user-only handler must also check UserClaims.

func RequiredLive

func RequiredLive(v *verify.Verifier) (fiber.Handler, error)

RequiredLive adds an account-liveness check and fresh identity claims. It returns verify.ErrLivenessUnconfigured if no liveness source is wired.

func Use

func Use(mw ...func(http.Handler) http.Handler) fiber.Handler

Use runs synchronous net/http authentication middleware around Fiber's downstream handlers. Context values and cancellation flow in both directions; Fiber errors are returned to its error handler. Middleware must not retain the converted request after returning. Streaming and hijacking are not supported. This bridge is for authentication and context middleware, not request rewriting or wrappers that intercept downstream response bodies.

Types

type Bundle added in v0.115.0

type Bundle struct {
	// contains filtered or unexported fields
}

Bundle contains the runtime's already configured route inventory.

func Routes added in v0.115.0

func Routes(runtime *embedded.Runtime) (*Bundle, error)

Routes obtains the local runtime's HTTP surface without constructing a server, engine or additional HTTP state. ConfigureHTTP must precede this call.

func (*Bundle) Mount added in v0.115.0

func (b *Bundle) Mount(target *fiber.App) error

Mount registers every configured route natively. AuthKit's JWKS, OIDC and document endpoints retain their required root anchors.

type UserClaimsData

type UserClaimsData = verify.UserClaimsData

UserClaimsData is the shared local-user view. See verify.UserClaimsData for optional fields and the token-time versus live-profile freshness contract.

func UserClaims

func UserClaims(c fiber.Ctx) (UserClaimsData, bool)

UserClaims returns only a verified local user, never a machine principal or an external issuer's subject. It performs no database lookup; profile availability depends on Required/Optional versus RequiredLive.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL