Documentation
¶
Overview ¶
Package authkitfiber bridges AuthKit's net/http middleware to Fiber v3. Mount registers AuthKit's routes directly on the application. Verification policy stays in verify.
Index ¶
- Constants
- func Claims(c fiber.Ctx) (verify.Claims, bool)
- func Fallback(h http.Handler) fiber.Handlerdeprecated
- func Mount(app *fiber.App, svc *authhttp.Service, options ...authhttp.MountOptions) error
- func Optional(v *verify.Verifier) fiber.Handler
- func OptionalLive(v *verify.Verifier) (fiber.Handler, error)
- func Principal(c fiber.Ctx) (authkit.Principal, bool)
- func RequirePermission(checker verify.PermissionChecker, perm authkit.Perm, ...) fiber.Handler
- func Required(v *verify.Verifier) fiber.Handler
- func RequiredLive(v *verify.Verifier) (fiber.Handler, error)
- func Use(mw ...func(http.Handler) http.Handler) fiber.Handler
- type Bundle
- type UserClaimsData
Constants ¶
const RouteNamePrefix = "authkit."
RouteNamePrefix identifies routes registered by Mount in app.GetRoutes().
Variables ¶
This section is empty.
Functions ¶
func Fallback
deprecated
Fallback adapts authhttp.MountHandler to Fiber. Register it last with app.Use so host routes win and all AuthKit paths retain their full prefix.
Deprecated: use Mount to register AuthKit as ordinary, inspectable Fiber routes. Fallback remains available for hosts adapting a custom HTTP handler.
func Mount ¶ added in v0.3.0
Mount registers AuthKit's configured routes directly on app. Each route is visible through app.GetRoutes() and named "authkit.METHOD /path". Call Mount during application setup, before serving requests.
The optional MountOptions selects route groups, exclusions, the API prefix, wrappers, and refresh-cookie policy. JWKS, documents, and browser OIDC retain their standard root paths. Handlers use AuthKit's canonical HTTP pipeline, including authentication, JSON guards, and cookie protections. Unmatched requests continue through Fiber's normal routing; no fallback is installed. Existing routes with the same method and normalized path cause an error; normalization honors CaseSensitive and StrictRouting. This checks exact paths, not overlapping wildcard patterns. Exclude a replaced AuthKit route with MountOptions.ExcludeRoutes before mounting. Every mounted method must be enabled by the app's RequestMethods configuration.
func Optional ¶
Optional passes requests without Authorization through anonymously. A present but invalid credential is rejected, just as in verify.Optional.
func OptionalLive ¶ added in v0.111.0
OptionalLive admits anonymous requests and checks the liveness of presented native-user credentials. It returns verify.ErrLivenessUnconfigured at startup when no source is wired. Use on routes, groups, or as application middleware.
func RequirePermission ¶
func RequirePermission(checker verify.PermissionChecker, perm authkit.Perm, resolve func(fiber.Ctx) verify.PermissionScope) fiber.Handler
RequirePermission checks the canonical permission policy using a Fiber-native scope resolver. Mount after Required or RequiredLive.
func Required ¶
Required validates a credential and stores verified claims in c.Context(). Like Gin's Required, it accepts every principal the verifier supports. A user-only handler must also check UserClaims.
func RequiredLive ¶
RequiredLive adds an account-liveness check and fresh identity claims. It returns verify.ErrLivenessUnconfigured if no liveness source is wired.
func Use ¶
Use runs synchronous net/http authentication middleware around Fiber's downstream handlers. Context values and cancellation flow in both directions; Fiber errors are returned to its error handler. Middleware must not retain the converted request after returning. Streaming and hijacking are not supported. This bridge is for authentication and context middleware, not request rewriting or wrappers that intercept downstream response bodies.
Types ¶
type Bundle ¶ added in v0.115.0
type Bundle struct {
// contains filtered or unexported fields
}
Bundle contains the runtime's already configured route inventory.
type UserClaimsData ¶
type UserClaimsData = verify.UserClaimsData
UserClaimsData is the shared local-user view. See verify.UserClaimsData for optional fields and the token-time versus live-profile freshness contract.
func UserClaims ¶
func UserClaims(c fiber.Ctx) (UserClaimsData, bool)
UserClaims returns only a verified local user, never a machine principal or an external issuer's subject. It performs no database lookup; profile availability depends on Required/Optional versus RequiredLive.