internal/

directory
v0.149.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: MIT

Directories

Path Synopsis
Package apikey is the API-key token format, shared by the engine (mint and resolve) and verify (routing a bearer token to the API-key path).
Package apikey is the API-key token format, shared by the engine (mint and resolve) and verify (routing a bearer token to the API-key path).
Package apitest holds black-box tests of the Client and its HTTP API, one file per feature.
Package apitest holds black-box tests of the Client and its HTTP API, one file per feature.
Package builtwith lets authtest read what a Client was built with, which the Client does not publish: a replica or a stale session of a Client the host built itself.
Package builtwith lets authtest read what a Client was built with, which the Client does not publish: a replica or a stale session of a Client the host built itself.
cmd
contract command
Command contract generates AuthKit's HTTP contract from the route catalog (httpapi.Catalog) and the error catalog: api/openapi.json, and auth-ui's generated wire types, route table and error codes and messages.
Command contract generates AuthKit's HTTP contract from the route catalog (httpapi.Catalog) and the error catalog: api/openapi.json, and auth-ui's generated wire types, route table and error codes and messages.
Package config is the one definition of AuthKit's host configuration: Config (plain data), Deps (everything that reaches outside the process), the Roles builder and MigrateOptions.
Package config is the one definition of AuthKit's host configuration: Config (plain data), Deps (everything that reaches outside the process), the Roles builder and MigrateOptions.
Package cursor is AuthKit's one page-cursor codec: a keyset position as opaque base64url JSON.
Package cursor is AuthKit's one page-cursor codec: a keyset position as opaque base64url JSON.
Package dpop verifies the ES256/P-256 profile of RFC 9449 sender proofs.
Package dpop verifies the ES256/P-256 profile of RFC 9449 sender proofs.
Package enrollment marks requests to AuthKit's 2FA-enrollment routes, the only ones a 2FA-enrollment-only token reaches and the only ones a user a Required 2FA policy has yet to enroll may use.
Package enrollment marks requests to AuthKit's 2FA-enrollment routes, the only ones a 2FA-enrollment-only token reaches and the only ones a user a Required 2FA policy has yet to enroll may use.
Package errmodel is AuthKit's one error model: the catalog fixing every wire code's HTTP status and message, the concrete error value, and its constructors.
Package errmodel is AuthKit's one error model: the catalog fixing every wire code's HTTP status and message, the concrete error value, and its constructors.
Package ident builds iam identifiers from strings AuthKit already trusts: stored rows, verified token claims, its compiled role schema and its own tests.
Package ident builds iam identifiers from strings AuthKit already trusts: stored rows, verified token claims, its compiled role schema and its own tests.
Package jose is AuthKit's JWT mechanics: signing with a keys.Signer, signature verification, the token types, claim readers, sender-binding (cnf) claims and JWKS serving.
Package jose is AuthKit's JWT mechanics: signing with a keys.Signer, signature verification, the token types, claim readers, sender-binding (cnf) claims and JWKS serving.
Package jwks is the issuer key cache behind every AuthKit verifier: it fetches an issuer's JWKS, serves it stale-while-revalidate up to a max staleness, refetches on key rotation, and reports health.
Package jwks is the issuer key cache behind every AuthKit verifier: it fetches an issuer's JWKS, serves it stale-while-revalidate up to a max staleness, refetches on key rotation, and reports health.
Package keypolicy is AuthKit's one public-key policy, applied to every signing and verification key: RSA of 2048-8192 bits with a sane exponent, P-256/384/521, or Ed25519.
Package keypolicy is AuthKit's one public-key policy, applied to every signing and verification key: RSA of 2048-8192 bits with a sane exponent, P-256/384/521, or Ed25519.
Package lang is AuthKit's one language normalizer and the request language the HTTP layer hands the engine.
Package lang is AuthKit's one language normalizer and the request language the HTTP layer hands the engine.
migrations
postgres
Package postgres embeds AuthKit's private PostgreSQL schema migrations.
Package postgres embeds AuthKit's private PostgreSQL schema migrations.
retired
Package retired converts databases built by the migration chain AuthKit v0.125.0–v0.148.x shipped (0001–0015, kept verbatim in v0.148/) to the v1 baseline in place.
Package retired converts databases built by the migration chain AuthKit v0.125.0–v0.148.x shipped (0001–0015, kept verbatim in v0.148/) to the v1 baseline in place.
Package naming applies the username rule of a normalized config.UsernameConfig: validation, derivation, renames and former names.
Package naming applies the username rule of a normalized config.UsernameConfig: validation, derivation, renames and former names.
Package netguard is the single outbound-network policy for AuthKit: the private/reserved address list, the resolve-then-dial SSRF guard, and the timeout-bounded HTTP client every package uses for fetches it does not fully control (JWKS, IdP endpoints).
Package netguard is the single outbound-network policy for AuthKit: the private/reserved address list, the resolve-then-dial SSRF guard, and the timeout-bounded HTTP client every package uses for fetches it does not fully control (JWKS, IdP endpoints).
Package oidcstate holds the browser-flow state shared by the HTTP layer and the engine: the pending-login record and PKCE generation.
Package oidcstate holds the browser-flow state shared by the HTTP layer and the engine: the pending-login record and PKCE generation.
Package ops declares AuthKit's operations once, with the signatures of the root Client's methods.
Package ops declares AuthKit's operations once, with the signatures of the root Client's methods.
Package passkeytest is a software WebAuthn authenticator for passkey integration tests: it answers real registration and assertion ceremonies with a P-256 key, so tests exercise the production ceremony code paths.
Package passkeytest is a software WebAuthn authenticator for passkey integration tests: it answers real registration and assertion ceremonies with a P-256 key, so tests exercise the production ceremony code paths.
internal/commongen command
Command commongen regenerates ../../common_passwords.txt.gz from pinned SecLists (MIT) lists: run `go generate ./password`.
Command commongen regenerates ../../common_passwords.txt.gz from pinned SecLists (MIT) lists: run `go generate ./password`.
memory
Package memorylimiter is the in-memory sliding-window rate limiter over ratelimit.Limit buckets.
Package memorylimiter is the in-memory sliding-window rate limiter over ratelimit.Limit buckets.
redis
Package redislimiter is the Redis-backed sliding-window rate limiter over ratelimit.Limit buckets.
Package redislimiter is the Redis-backed sliding-window rate limiter over ratelimit.Limit buckets.
Package rbac compiles the host's role configuration into the immutable schema the engine authorizes against: each persona's permission catalog, its roles, and the pure grant-resolution core.
Package rbac compiles the host's role configuration into the immutable schema the engine authorizes against: each persona's permission catalog, its roles, and the pure grant-resolution core.
Package secret mints and compares one-time secrets over crypto/rand: tokens, numeric and alphabet codes, their stored digests and constant-time comparison.
Package secret mints and compares one-time secrets over crypto/rand: tokens, numeric and alphabet codes, their stored digests and constant-time comparison.
Package siws implements Sign In With Solana (SIWS) authentication.
Package siws implements Sign In With Solana (SIWS) authentication.
Package testclock is a settable clock for tests that would otherwise sleep through a TTL, grace window or rate-limit window.
Package testclock is a settable clock for tests that would otherwise sleep through a TTL, grace window or rate-limit window.
Package testdb owns AuthKit's Postgres integration-test harness.
Package testdb owns AuthKit's Postgres integration-test harness.
Package testdpop creates genuine signed sender proofs for workflow tests.
Package testdpop creates genuine signed sender proofs for workflow tests.
Package testhttp is the adapters' preset over authtest.New.
Package testhttp is the adapters' preset over authtest.New.
Package testidp is a fake identity provider for tests of AuthKit's provider sign-in, link and recovery flows: an OpenID Provider (discovery, JWKS, ID tokens) and a plain OAuth2 server (token, userinfo) on one TLS server.
Package testidp is a fake identity provider for tests of AuthKit's provider sign-in, link and recovery flows: an OpenID Provider (discovery, JWKS, ID tokens) and a plain OAuth2 server (token, userinfo) on one TLS server.
Package testkeys generates signing keys for tests.
Package testkeys generates signing keys for tests.
Package testoutbox defines the capturing email and SMS senders that authtest publishes as authtest.Outbox.
Package testoutbox defines the capturing email and SMS senders that authtest publishes as authtest.Outbox.
Package wireform puts a value in AuthKit's wire form before it is marshaled: every time in UTC, every list [] and every map {} rather than null.
Package wireform puts a value in AuthKit's wire form before it is marshaled: every time in UTC, every list [] and every map {} rather than null.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL