Directories
¶
| Path | Synopsis |
|---|---|
|
Package apikey is the API-key token format, shared by the engine (mint and resolve) and verify (routing a bearer token to the API-key path).
|
Package apikey is the API-key token format, shared by the engine (mint and resolve) and verify (routing a bearer token to the API-key path). |
|
Package apitest holds black-box tests of the Client and its HTTP API, one file per feature.
|
Package apitest holds black-box tests of the Client and its HTTP API, one file per feature. |
|
cmd
|
|
|
contract
command
Command contract writes AuthKit's wire error codes, with their catalog statuses, to auth-ui's src/client/generated/error-codes.ts.
|
Command contract writes AuthKit's wire error codes, with their catalog statuses, to auth-ui's src/client/generated/error-codes.ts. |
|
Package config is the one definition of AuthKit's host configuration: Config (plain data), Deps (everything that reaches outside the process), the Roles builder and MigrateOptions.
|
Package config is the one definition of AuthKit's host configuration: Config (plain data), Deps (everything that reaches outside the process), the Roles builder and MigrateOptions. |
|
Package dpop verifies the ES256/P-256 profile of RFC 9449 sender proofs.
|
Package dpop verifies the ES256/P-256 profile of RFC 9449 sender proofs. |
|
Package enrollment marks requests to AuthKit's 2FA-enrollment routes, the only ones a 2FA-enrollment-only token reaches and the only ones a user a Required 2FA policy has yet to enroll may use.
|
Package enrollment marks requests to AuthKit's 2FA-enrollment routes, the only ones a 2FA-enrollment-only token reaches and the only ones a user a Required 2FA policy has yet to enroll may use. |
|
Package errmodel is AuthKit's one error model: the catalog fixing every wire code's HTTP status and message, the concrete error value, and its constructors.
|
Package errmodel is AuthKit's one error model: the catalog fixing every wire code's HTTP status and message, the concrete error value, and its constructors. |
|
Package ident builds iam identifiers from strings AuthKit already trusts: stored rows, verified token claims, its compiled role schema and its own tests.
|
Package ident builds iam identifiers from strings AuthKit already trusts: stored rows, verified token claims, its compiled role schema and its own tests. |
|
Package jose is AuthKit's JWT mechanics: signing with a keys.Signer, signature verification, the token types, claim readers, sender-binding (cnf) claims and JWKS serving.
|
Package jose is AuthKit's JWT mechanics: signing with a keys.Signer, signature verification, the token types, claim readers, sender-binding (cnf) claims and JWKS serving. |
|
Package jwks is the issuer key cache behind every AuthKit verifier: it fetches an issuer's JWKS, serves it stale-while-revalidate up to a max staleness, refetches on key rotation, and reports health.
|
Package jwks is the issuer key cache behind every AuthKit verifier: it fetches an issuer's JWKS, serves it stale-while-revalidate up to a max staleness, refetches on key rotation, and reports health. |
|
Package keypolicy is AuthKit's one public-key policy, applied to every signing and verification key: RSA of 2048-8192 bits with a sane exponent, P-256/384/521, or Ed25519.
|
Package keypolicy is AuthKit's one public-key policy, applied to every signing and verification key: RSA of 2048-8192 bits with a sane exponent, P-256/384/521, or Ed25519. |
|
Package lang is AuthKit's one language normalizer and the request language the HTTP layer hands the engine.
|
Package lang is AuthKit's one language normalizer and the request language the HTTP layer hands the engine. |
|
migrations
|
|
|
postgres
Package postgres embeds AuthKit's private PostgreSQL schema migrations.
|
Package postgres embeds AuthKit's private PostgreSQL schema migrations. |
|
Package naming applies the username rule of a normalized config.UsernameConfig: validation, derivation, renames and former names.
|
Package naming applies the username rule of a normalized config.UsernameConfig: validation, derivation, renames and former names. |
|
Package netguard is the single outbound-network policy for AuthKit: the private/reserved address list, the resolve-then-dial SSRF guard, and the timeout-bounded HTTP client every package uses for fetches it does not fully control (JWKS, IdP endpoints).
|
Package netguard is the single outbound-network policy for AuthKit: the private/reserved address list, the resolve-then-dial SSRF guard, and the timeout-bounded HTTP client every package uses for fetches it does not fully control (JWKS, IdP endpoints). |
|
Package oidcstate holds the browser-flow state shared by the HTTP layer and the engine: the pending-login record and PKCE generation.
|
Package oidcstate holds the browser-flow state shared by the HTTP layer and the engine: the pending-login record and PKCE generation. |
|
Package ops declares AuthKit's operations once, with the signatures of the root Client's methods.
|
Package ops declares AuthKit's operations once, with the signatures of the root Client's methods. |
|
Package passkeytest is a software WebAuthn authenticator for passkey integration tests: it answers real registration and assertion ceremonies with a P-256 key, so tests exercise the production ceremony code paths.
|
Package passkeytest is a software WebAuthn authenticator for passkey integration tests: it answers real registration and assertion ceremonies with a P-256 key, so tests exercise the production ceremony code paths. |
|
internal/commongen
command
Command commongen regenerates ../../common_passwords.txt.gz from pinned SecLists (MIT) lists: run `go generate ./password`.
|
Command commongen regenerates ../../common_passwords.txt.gz from pinned SecLists (MIT) lists: run `go generate ./password`. |
|
memory
Package memorylimiter is the in-memory sliding-window rate limiter over ratelimit.Limit buckets.
|
Package memorylimiter is the in-memory sliding-window rate limiter over ratelimit.Limit buckets. |
|
redis
Package redislimiter is the Redis-backed sliding-window rate limiter over ratelimit.Limit buckets.
|
Package redislimiter is the Redis-backed sliding-window rate limiter over ratelimit.Limit buckets. |
|
Package rbac compiles the host's role configuration into the immutable schema the engine authorizes against: each persona's permission catalog, its roles, and the pure grant-resolution core.
|
Package rbac compiles the host's role configuration into the immutable schema the engine authorizes against: each persona's permission catalog, its roles, and the pure grant-resolution core. |
|
Package secret mints and compares one-time secrets over crypto/rand: tokens, numeric and alphabet codes, their stored digests and constant-time comparison.
|
Package secret mints and compares one-time secrets over crypto/rand: tokens, numeric and alphabet codes, their stored digests and constant-time comparison. |
|
Package siws implements Sign In With Solana (SIWS) authentication.
|
Package siws implements Sign In With Solana (SIWS) authentication. |
|
Package testclock is a settable clock for tests that would otherwise sleep through a TTL, grace window or rate-limit window.
|
Package testclock is a settable clock for tests that would otherwise sleep through a TTL, grace window or rate-limit window. |
|
Package testdb owns AuthKit's Postgres integration-test harness.
|
Package testdb owns AuthKit's Postgres integration-test harness. |
|
Package testdpop creates genuine signed sender proofs for workflow tests.
|
Package testdpop creates genuine signed sender proofs for workflow tests. |
|
Package testhttp is the adapters' preset over authtest.New.
|
Package testhttp is the adapters' preset over authtest.New. |
|
Package testidp is a fake identity provider for tests of AuthKit's provider sign-in, link and recovery flows: an OpenID Provider (discovery, JWKS, ID tokens) and a plain OAuth2 server (token, userinfo) on one TLS server.
|
Package testidp is a fake identity provider for tests of AuthKit's provider sign-in, link and recovery flows: an OpenID Provider (discovery, JWKS, ID tokens) and a plain OAuth2 server (token, userinfo) on one TLS server. |
|
Package testkeys generates signing keys for tests.
|
Package testkeys generates signing keys for tests. |
|
Package testoutbox defines the capturing email and SMS senders that authtest publishes as authtest.Outbox.
|
Package testoutbox defines the capturing email and SMS senders that authtest publishes as authtest.Outbox. |
Click to show internal directories.
Click to hide internal directories.