Documentation
¶
Index ¶
- Constants
- func NormalizeAuthMethods(methods []string) []string
- func NormalizePreferredLanguage(language string) (string, error)
- func RecentSignIn(authTime time.Time, amr []string, mfa bool, now time.Time) bool
- func SessionRevokeReasonFrom(ctx context.Context) *string
- func StepUpMethods(hasPassword bool, settings *TwoFactorSettings, providerSlugs []string, ...) []string
- func ValidTwoFactorStepUpMethod(method string) bool
- func ValidationErrorCode(err error) errmodel.Code
- func WithSessionRevokeReason(ctx context.Context, reason SessionRevokeReason) context.Context
- type AccountRecoveryConfirmation
- type ActionAvailability
- type AuthSessionEvent
- type DeviceKeyAuthResult
- type DeviceKeyChallenge
- type DeviceKeySecondFactorRequired
- type ExternalIdentity
- type ExternalLinkAuthorization
- type ExternalLoginInput
- type FactorEnrollmentMode
- type InviteRedemption
- type IssuedSession
- type ListPage
- type LoginChallengeInput
- type LoginOutcome
- type LoginOutcomeKind
- type MFAContinuationRequiredError
- type MFAStatus
- type Passkey
- type PasswordLoginInput
- type PasswordlessLoginInput
- type PasswordlessStartRequest
- type PasswordlessStartResult
- type PendingRegistration
- type ProfileInput
- type RegisterInput
- type RegisterOutcome
- type RegisterOutcomeKind
- type RemovedMFARoleAssignment
- type Session
- type SessionFreshness
- type SessionRevokeReason
- type SolanaLinkedAccount
- type StepUpTwoFactorOption
- type StepUpTwoFactorOptions
- type TwoFactorChallenge
- type TwoFactorEnrollInput
- type TwoFactorEnrollKind
- type TwoFactorEnrollOutcome
- type TwoFactorEnrollmentScope
- type TwoFactorFactor
- type TwoFactorSettings
- type UserProfile
- type UserSecurity
- type VerificationInput
- type VerificationRequired
Constants ¶
const ( ActionUpdateUsername = "update_username" ActionRequestPasswordReset = "request_password_reset" ActionRequestVerification = "request_verification" )
ActionAvailability reports whether a cooldown-gated action is currently allowed; it rides on 429 error metadata. Action names carried by ActionAvailability.
const SensitiveActionFreshAuthWindow = 15 * time.Minute
Variables ¶
This section is empty.
Functions ¶
func NormalizeAuthMethods ¶
func NormalizePreferredLanguage ¶
NormalizePreferredLanguage is lang.Normalize for an account's stored preference: "" clears it, and a value naming no language is refused.
func RecentSignIn ¶
RecentSignIn reports whether a token's assurance clears the sensitive-action gate: signed in within SensitiveActionFreshAuthWindow and, for an account with a usable second factor (mfa), with that factor (amr otp or mfa). An account without one is never blocked for lacking it.
func SessionRevokeReasonFrom ¶
SessionRevokeReasonFrom reads the reason WithSessionRevokeReason attached, or nil.
func StepUpMethods ¶
func StepUpMethods(hasPassword bool, settings *TwoFactorSettings, providerSlugs []string, supportsStepUp func(string) bool) []string
StepUpMethods lists how the user can re-authenticate for a sensitive action: password, an enabled second factor, and every linked provider that supports step-up (de-duplicated, sorted). Pure over already-loaded inputs.
func ValidTwoFactorStepUpMethod ¶
ValidTwoFactorStepUpMethod reports whether method can satisfy a step-up.
func ValidationErrorCode ¶
ValidationErrorCode returns the identity-policy code err carries, or "" when err is not a validation failure.
func WithSessionRevokeReason ¶
func WithSessionRevokeReason(ctx context.Context, reason SessionRevokeReason) context.Context
WithSessionRevokeReason annotates ctx so revoke paths can record a structured reason in the session log.
Types ¶
type AccountRecoveryConfirmation ¶
type AccountRecoveryConfirmation struct {
Token string `json:"token"`
ExpiresAt time.Time `json:"expires_at"`
PurgeAt time.Time `json:"purge_at"`
}
AccountRecoveryConfirmation is an opaque proof, never an access token or session. Confirmation restores this deletion generation without signing in.
type ActionAvailability ¶
type ActionAvailability struct {
Action string `json:"action"`
Allowed bool `json:"allowed"`
Reason string `json:"reason,omitempty"`
RetryAfterSeconds int64 `json:"retry_after_seconds,omitempty"`
NextAllowedAt *time.Time `json:"next_allowed_at,omitempty"`
Limit *int `json:"limit,omitempty"`
Remaining *int `json:"remaining,omitempty"`
WindowSeconds *int64 `json:"window_seconds,omitempty"`
CooldownSeconds *int64 `json:"cooldown_seconds,omitempty"`
}
type AuthSessionEvent ¶
type AuthSessionEvent struct {
OccurredAt time.Time
Issuer string
UserID string
SessionID string
Event iam.SessionEventKind
Method *string
Reason *string
IPAddr *string
UserAgent *string
}
AuthSessionEvent is a best-effort, append-only session lifecycle record stored in Postgres (session_events, #245) and retained per Config.SessionEventRetention. issuer/user_id/session_id/event are required; method is typically set for SessionEventCreated and reason for SessionEventRevoked.
type DeviceKeyAuthResult ¶
type DeviceKeyChallenge ¶
DeviceKey is the public projection of one native-client credential.
type DeviceKeySecondFactorRequired ¶
type DeviceKeySecondFactorRequired struct{ Method string }
DeviceKeySecondFactorRequired is returned by FinishDeviceKeyEnrollment when the email code and key proof are valid but the account has a usable second factor that was not presented (#293). Method is a factor independent of the enrollment mailbox (totp, sms) or backup_code. The ceremony stays live for a retry carrying the code; for an SMS factor the code has just been sent.
func (*DeviceKeySecondFactorRequired) Error ¶
func (e *DeviceKeySecondFactorRequired) Error() string
type ExternalIdentity ¶
type ExternalIdentity struct {
Provider string // provider slug (the configured name)
Issuer string
Subject string
Email string
EmailVerified bool
PreferredUsername string
DisplayName string
}
ExternalIdentity is a provider-verified identity.
type ExternalLinkAuthorization ¶
ExternalLinkAuthorization records the fresh session that initiated linking. It is carried only in server-side browser state, never accepted from a callback.
type ExternalLoginInput ¶
type ExternalLoginInput struct {
Identity ExternalIdentity
// Link authorizes a provider mutation only; it never creates a session.
Link *ExternalLinkAuthorization
AccountInviteToken string
Event string // session-created audit event, e.g. "oidc_login"
UserAgent string
IP string
}
ExternalLoginInput is an external-identity login or link attempt.
type FactorEnrollmentMode ¶
type FactorEnrollmentMode string
FactorEnrollmentMode distinguishes restricted enrollment grants from authenticated factor management.
const ( // FirstFactorOnly permits a restricted grant to enroll only when no factor exists. FirstFactorOnly FactorEnrollmentMode = "first_factor_only" // AllowAdditionalFactors permits fresh authenticated users to add a new method. AllowAdditionalFactors FactorEnrollmentMode = "allow_additional_factors" )
type InviteRedemption ¶
InviteRedemption is the group and role a redeemed invite link granted.
type IssuedSession ¶
type IssuedSession struct {
SessionID string
RefreshToken string
AccessToken string
AccessExpiresAt time.Time
}
IssuedSession is a freshly established refresh session plus its paired access token.
func (IssuedSession) TokenSet ¶
func (s IssuedSession) TokenSet() iam.TokenSet
TokenSet is the wire shape of an IssuedSession.
type ListPage ¶
type ListPage[T any] struct { Object string `json:"object"` Data []T `json:"data"` NextCursor string `json:"next_cursor,omitempty"` }
ListPage is the one list envelope: {object:"list", data:[...], next_cursor?}. A present next_cursor means another page exists; pass it back as ?cursor=.
func NewListPage ¶
NewListPage wraps items (never null: an empty page marshals as []).
type LoginChallengeInput ¶
type LoginChallengeInput struct {
UserID string
Challenge string
FactorID string
Code string
BackupCode bool
UserAgent string
IP string
}
LoginChallengeInput supplies the second proof; clients never supply AMR or first-factor provenance. Backup codes are independently stored recovery keys.
type LoginOutcome ¶
type LoginOutcome struct {
Recovery *AccountRecoveryConfirmation
Enrollment *iam.TokenSet
AllowedMethods []string
ReturnTo string
Created bool
Kind LoginOutcomeKind
UserID string
Reason error
Session *IssuedSession
Verification *VerificationRequired
Challenge *TwoFactorChallenge
}
LoginOutcome is the result of a password login. Exactly one of Session, Verification and Challenge is set, per Kind; Reason is set for LoginRejected.
type LoginOutcomeKind ¶
type LoginOutcomeKind string
LoginOutcomeKind is the closed set of ways a login attempt ends.
const ( LoginProviderLinked LoginOutcomeKind = "provider_linked" LoginContactChanged LoginOutcomeKind = "contact_changed" // LoginSessionIssued: the caller is signed in; Session carries the tokens. LoginSessionIssued LoginOutcomeKind = "session_issued" // LoginVerificationRequired: the identifier still needs verifying; a fresh // code was just sent to Verification.Identifier over Verification.Channel. LoginVerificationRequired LoginOutcomeKind = "verification_required" // LoginTwoFactorRequired: the password verified; a second factor is now // pending (Challenge carries the issued challenge and the factor menu). LoginTwoFactorRequired LoginOutcomeKind = "2fa_required" // LoginTwoFAEnrollmentRequired: the password verified but the deployment // requires a second factor the user has not enrolled yet. LoginTwoFAEnrollmentRequired LoginOutcomeKind = "2fa_enrollment_required" // LoginRejected: no session; Reason says why (ErrInvalidCredentials, // ErrUserBanned, ErrPasswordResetRequired). LoginRejected LoginOutcomeKind = "rejected" )
const LoginRecoveryRequired LoginOutcomeKind = "account_recovery_required"
type MFAContinuationRequiredError ¶
MFAContinuationRequiredError identifies the already-validated refresh session that needs a first-factor continuation. It never authorizes an arbitrary user.
func (*MFAContinuationRequiredError) Error ¶
func (e *MFAContinuationRequiredError) Error() string
func (*MFAContinuationRequiredError) Unwrap ¶
func (e *MFAContinuationRequiredError) Unwrap() error
type Passkey ¶
type Passkey struct {
ID string `json:"id"`
UserID string `json:"user_id,omitempty"`
Label *string `json:"label,omitempty"`
Transports []string `json:"transports,omitempty"`
AuthenticatorAttachment string `json:"authenticator_attachment,omitempty"`
BackupEligible bool `json:"backup_eligible"`
BackupState bool `json:"backup_state"`
CreatedAt time.Time `json:"created_at"`
LastUsedAt *time.Time `json:"last_used_at,omitempty"`
}
type PasswordLoginInput ¶
PasswordLoginInput is a password login attempt. Identifier is an email (contains "@"), an E.164 phone ("+…") or a username.
type PasswordlessLoginInput ¶
type PasswordlessLoginInput struct {
Identifier string
Code string
Token string
UserAgent string
IP string
}
PasswordlessLoginInput selects either a typed code or a link token, never both, and supplies request metadata for the resulting authentication.
type PasswordlessStartResult ¶
type PendingRegistration ¶
type PendingRegistration struct {
Email string
Username string
PasswordHash string
PreferredLanguage string
}
PendingRegistration represents an unverified registration
type ProfileInput ¶
type ProfileInput struct {
UserID string
ClaimsUsername string // fallback when the row carries no username
AuthTime time.Time
StepUpSatisfied bool // the presented token is fresh enough for sensitive actions
// ProviderSupportsStepUp reports which linked providers can re-authenticate.
ProviderSupportsStepUp func(provider string) bool
}
ProfileInput is what the transport knows that the engine does not: the verified claims' username/auth-time/sensitivity and the deployment's provider registry.
type RegisterInput ¶
type RegisterInput struct {
Identifier string
Username string
Password string
PreferredLanguage string
AccountInviteToken string
UserAgent string
IP string
}
RegisterInput is a native-user registration attempt: Identifier is an email or an E.164 phone; the account is password-backed.
type RegisterOutcome ¶
type RegisterOutcome struct {
Login *LoginOutcome
Kind RegisterOutcomeKind
Username string
Email *string
Phone *string
Session *IssuedSession
}
RegisterOutcome reports who was registered and what happens next.
type RegisterOutcomeKind ¶
type RegisterOutcomeKind string
RegisterOutcomeKind is the closed set of ways a registration ends.
const ( RegisterLoginRequired RegisterOutcomeKind = "login_required" // RegisterSessionIssued: the account exists and is signed in (no // verification pending). RegisterSessionIssued RegisterOutcomeKind = "session_issued" // RegisterVerifyEmail / RegisterVerifyPhone: the registration is pending // until the code just sent to the identifier is confirmed. RegisterVerifyEmail RegisterOutcomeKind = "verify_email" RegisterVerifyPhone RegisterOutcomeKind = "verify_phone" )
type Session ¶
type Session struct {
ID string
FamilyID string
CreatedAt time.Time
LastAuthenticatedAt *time.Time
LastUsedAt time.Time
ExpiresAt *time.Time
RevokedAt *time.Time
UserAgent *string
IPAddr *string
}
Session is a sanitized session view (no tokens). Part of the wire contract.
type SessionFreshness ¶
type SessionFreshness struct {
LastAuthenticatedAt time.Time
TimeUntilStepUpRequired time.Duration
StepUpRequiredForSensitiveOps bool
AuthMethods []string
// MFAAuthenticatedAt is when the session last proved a second factor.
MFAAuthenticatedAt time.Time
}
func (SessionFreshness) AssuranceClaims ¶
func (f SessionFreshness) AssuranceClaims(secondFactor bool) (authTime int64, amr []string, acr string)
AssuranceClaims are the token's auth_time, amr and acr. A token claims otp/mfa only as of the session's last MFA proof. For an account with a second factor (secondFactor), auth_time is that proof, so a password re-auth never makes it fresh, and a session that never proved it claims no MFA. For an account without one (passkeys only), a later re-auth without MFA is fresh but no longer MFA (P5).
type SessionRevokeReason ¶
type SessionRevokeReason string
SessionRevokeReason identifies why a session (or set of sessions) was revoked.
const ( SessionRevokeReasonLogout SessionRevokeReason = "logout" SessionRevokeReasonUserRevoke SessionRevokeReason = "user_revoke" SessionRevokeReasonUserRevokeAll SessionRevokeReason = "user_revoke_all" SessionRevokeReasonAdminRevoke SessionRevokeReason = "admin_revoke" SessionRevokeReasonAdminRevokeAll SessionRevokeReason = "admin_revoke_all" SessionRevokeReasonPasswordChange SessionRevokeReason = "password_change" SessionRevokeReasonAdminSetPassword SessionRevokeReason = "admin_set_password" SessionRevokeReasonContactChange SessionRevokeReason = "contact_change" SessionRevokeReasonContactProven SessionRevokeReason = "contact_proven" SessionRevokeReasonMFAReset SessionRevokeReason = "mfa_reset" SessionRevokeReasonBanned SessionRevokeReason = "banned" SessionRevokeReasonSoftDeleted SessionRevokeReason = "soft_deleted" SessionRevokeReasonEvicted SessionRevokeReason = "evicted" SessionRevokeReasonRefreshReuseDetected SessionRevokeReason = "refresh_reuse_detected" )
type SolanaLinkedAccount ¶
type SolanaLinkedAccount struct {
Provider string `json:"provider"`
Issuer string `json:"issuer"`
Address string `json:"address"`
Verified bool `json:"verified"`
VerifiedAt *time.Time `json:"verified_at"`
PrimarySNSName *string `json:"primary_sns_name"`
SNSResolutionStatus string `json:"sns_resolution_status"`
SNSResolvedAt *time.Time `json:"sns_resolved_at"`
SNSStale bool `json:"sns_stale"`
SNSError *string `json:"sns_error"`
}
SolanaLinkedAccount is the AuthKit-owned normalized metadata for a SIWS-linked wallet.
type StepUpTwoFactorOption ¶
type StepUpTwoFactorOptions ¶
type StepUpTwoFactorOptions struct {
Methods []string `json:"methods,omitempty"`
DefaultMethod string `json:"default_method,omitempty"`
Options []StepUpTwoFactorOption `json:"options,omitempty"`
}
StepUpTwoFactorOptions lists the second factors a step-up can use.
func NewStepUpTwoFactorOptions ¶
func NewStepUpTwoFactorOptions(settings *TwoFactorSettings) *StepUpTwoFactorOptions
NewStepUpTwoFactorOptions lists the second factors a step-up can use, with the code destination masked. Nil when 2FA is not enabled.
type TwoFactorChallenge ¶
type TwoFactorChallenge struct {
Method string
Destination string // where the code went (email/phone), unmasked
Challenge string
Factor TwoFactorFactor
Factors []TwoFactorFactor
}
TwoFactorChallenge is the second-factor step a password login opened.
type TwoFactorEnrollInput ¶
type TwoFactorEnrollInput struct {
LoginChallenge string
// SessionID is the caller's session; a confirmed code marks it 2FA-verified.
SessionID string
UserAgent string
IP string
UserID string
Mode FactorEnrollmentMode
Method string // "email" | "sms" | "totp"; empty with FactorID+MakeDefault re-points the default
Code string // email/SMS setup code or TOTP code; empty starts the method's setup
PhoneNumber string
MakeDefault bool
FactorID string
}
TwoFactorEnrollInput is one enrollment request.
type TwoFactorEnrollKind ¶
type TwoFactorEnrollKind string
TwoFactorEnrollKind is the closed set of enrollment results.
const ( TwoFactorEnrollDefaultSet TwoFactorEnrollKind = "default_set" TwoFactorEnrollCodeSent TwoFactorEnrollKind = "code_sent" // email/SMS setup code delivered TwoFactorEnrollTOTPStarted TwoFactorEnrollKind = "totp_started" // secret + otpauth URI handed out TwoFactorEnrollEnabled TwoFactorEnrollKind = "enabled" )
type TwoFactorEnrollOutcome ¶
type TwoFactorEnrollOutcome struct {
Login *LoginOutcome
Kind TwoFactorEnrollKind
Method string
Secret string
OTPAuthURI string
BackupCodes []string
SessionVerified bool
}
TwoFactorEnrollOutcome carries the TOTP material for TwoFactorEnrollTOTPStarted and the plaintext backup codes (shown once) for TwoFactorEnrollEnabled. SessionVerified reports that the input session now holds 2FA assurance.
type TwoFactorEnrollmentScope ¶
type TwoFactorEnrollmentScope struct {
Mode FactorEnrollmentMode
HasFactors bool
}
TwoFactorEnrollmentScope is what an enrollment call may do: the factor slot policy and whether the account already holds a factor.
type TwoFactorFactor ¶
type TwoFactorFactor struct {
ID string
UserID string
Method string
PhoneNumber *string
// Email is the address an email factor was proven for; its codes go
// there, never to the account's current address.
Email *string
TOTPSecret []byte
LastTOTPStep *int64
IsDefault bool
Enabled bool
CreatedAt time.Time
UpdatedAt time.Time
}
type TwoFactorSettings ¶
type UserProfile ¶
type UserProfile struct {
ID string `json:"id"`
Username string `json:"username"`
Email *string `json:"email"`
PhoneNumber *string `json:"phone_number"`
EmailVerified bool `json:"email_verified"`
PhoneVerified bool `json:"phone_verified"`
HasPassword bool `json:"has_password"`
SolanaLinkedAccount *SolanaLinkedAccount `json:"solana_linked_account,omitempty"`
LinkedProviders []string `json:"linked_providers,omitempty"`
Roles []string `json:"roles"`
Entitlements []string `json:"entitlements"`
AvatarURL *string `json:"avatar_url,omitempty"`
PreferredLanguage *string `json:"preferred_language,omitempty"`
CreatedAt *string `json:"created_at,omitempty"`
Naming naming.State `json:"naming"`
Security UserSecurity `json:"security"`
}
UserProfile is the caller's own account as GET /me returns it: identity, contact state, linked providers, roles/entitlements, naming state and the security view.
type UserSecurity ¶
type UserSecurity struct {
LastAuthenticatedAt *string `json:"last_authenticated_at,omitempty"`
TimeUntilStepUpRequired *int64 `json:"time_until_step_up_required,omitempty"`
StepUpRequiredForSensitiveActions bool `json:"step_up_required_for_sensitive_actions"`
StepUpMethods []string `json:"step_up_methods,omitempty"`
StepUp2FA *StepUpTwoFactorOptions `json:"step_up_2fa,omitempty"`
MFAEnabled bool `json:"mfa_enabled"`
MFASatisfied bool `json:"mfa_satisfied"`
MFAAllowedMethods []string `json:"mfa_allowed_methods,omitempty"`
}
UserSecurity is the session/step-up/MFA view of the caller's own account, nested under UserProfile.Security.
type VerificationInput ¶
type VerificationInput struct {
Identifier string
Code string
Token string
UserID string
SessionID string
UserAgent string
IP string
}
VerificationInput completes a delivered code/link. UserID and SessionID are supplied only from an authenticated host principal for contact changes.
type VerificationRequired ¶
VerificationRequired names the contact channel a login is parked on.
Source Files
¶
- account_recovery_proof.go
- audit.go
- context.go
- contract.go
- flow_device_keys.go
- flow_external_login.go
- flow_login.go
- flow_passkeys.go
- flow_passwordless.go
- flow_register.go
- flow_twofactor.go
- flow_twofactor_enroll.go
- flow_verify_login.go
- identity_validation.go
- language.go
- login_continuation.go
- mandatory_2fa.go
- profile.go
- service.go
- service_sessions.go
- user.go
- wire.go