Documentation
¶
Overview ¶
Package ident builds iam identifiers from strings AuthKit already trusts: stored rows, verified token claims, its compiled role schema and its own tests. A string that fails the syntax check yields the zero value, which matches and grants nothing. Host input goes through the schema instead (Client.Persona, Client.Permission, Client.Role).
Index ¶
- Constants
- Variables
- func CredentialsManage(p iam.Persona) iam.Perm
- func CredentialsRead(p iam.Persona) iam.Perm
- func IntrinsicRootPermissions() []iam.Perm
- func MembersManage(p iam.Persona) iam.Perm
- func MembersRead(p iam.Persona) iam.Perm
- func Perm(s string) iam.Perm
- func Perms(ss []string) []iam.Perm
- func Persona(s string) iam.Persona
- func Role(persona iam.Persona, name string) iam.Role
- func RoleText(s string) iam.Role
- func Strings[T fmt.Stringer](vs []T) []string
- func ValidIssuer(iss string) bool
- func ValidSegment(s string) bool
- func ValidateGrantPattern(g string) error
- func ValidatePermission(p string) error
Constants ¶
const MaxIssuerLen = 512
MaxIssuerLen bounds a remote-application issuer.
Variables ¶
var ( RootUsersRead = Perm("root:users:read") // list and read accounts and their sign-ins RootUsersBan = Perm("root:users:ban") // ban / unban an account RootUsersDelete = Perm("root:users:delete") // soft-delete and restore an account RootUsersManage = Perm("root:users:manage") // edit another account, revoke its sessions RootUsersInvite = Perm("root:users:invite") // invite someone to create an account )
The intrinsic root permissions gating AuthKit's account administration.
Functions ¶
func CredentialsManage ¶
CredentialsManage gates creating, revoking and re-roling API keys and remote applications. Registered with CredentialsRead.
func CredentialsRead ¶
CredentialsRead gates listing API keys. Registered only for personas with API keys or remote applications.
func IntrinsicRootPermissions ¶
IntrinsicRootPermissions are the root permissions every deployment registers besides the members built-ins.
func MembersManage ¶
MembersManage gates adding, removing and re-roling members and invitations.
func MembersRead ¶
MembersRead gates listing a group's members and its role catalog.
func RoleText ¶
RoleText reads a role's text form `<persona>:<name>`, as rows store it; the zero Role when it is malformed.
func ValidIssuer ¶
ValidIssuer reports whether iss has the shape every registered remote-application issuer has: an absolute http(s) URL with a host, at most MaxIssuerLen bytes, no whitespace or control characters. Registration enforces it, and the verifier applies it to a token's self-asserted iss before any store lookup.
func ValidSegment ¶
ValidSegment reports whether s is one permission segment (a persona, resource, action or role name): [a-z][a-z0-9-]*.
func ValidateGrantPattern ¶
ValidateGrantPattern checks what a role holds: a concrete permission or a namespace-anchored glob, never a bare `*`:
<persona>:<resource>:<action> a concrete permission <persona>:<resource>:* every action on a resource <persona>:* the whole persona namespace (the owner)
It is stricter than iam.Perm.Matches: it refuses mid-glob forms such as `persona:*:action`.
func ValidatePermission ¶
ValidatePermission checks a concrete catalog permission: exactly three segments `<persona>:<resource>:<action>` (`merchant:catalog:update`).
Types ¶
This section is empty.