Documentation
¶
Index ¶
- Constants
- Variables
- func Conform(t reflect.Type, v any) []string
- func DefaultRateLimits() map[string]ratelimit.Limit
- func IsPage(t reflect.Type) bool
- func PageItem(t reflect.Type) reflect.Type
- func SanitizeReturnTo(value string) string
- type APIKeyCreateRequest
- type Availability
- type AvailabilityField
- type AvailabilityQuery
- type Backend
- type BackupCodes
- type BanRequest
- type Capabilities
- type ChannelCapabilities
- type ClientIPFunc
- type CodeOrLinkRequest
- type CookieVariant
- type DelegatedTokenRequest
- type DeviceKeyEnrollBeginRequest
- type DeviceKeyEnrollFinishRequest
- type DeviceKeyEnrollment
- type DeviceKeyLoginBeginRequest
- type DeviceKeyLoginChallenge
- type DeviceKeyLoginFinishRequest
- type DeviceKeySession
- type ExternalLoginProvider
- type Feature
- type FreshAuth
- type GroupOp
- type GroupQuery
- type IdentifierPasswordRequest
- type IdentifierRequest
- type InvitationCreateRequest
- type InviteRedeemRequest
- type LabelRequest
- type MemberAddRequest
- type MemberListQuery
- type Mount
- type MountPaths
- type OIDCCallbackQuery
- type OIDCLoginQuery
- type OIDCLoginRequest
- type OIDCLoginResult
- type OIDCStart
- type OIDCStepUpResult
- type OIDCUser
- type PageQuery
- type PasskeyCapabilities
- type PasswordCapabilities
- type PasswordChangeRequest
- type PasswordLoginRequest
- type PasswordRequest
- type PasswordResetConfirmRequest
- type PasswordlessCapabilities
- type PasswordlessResult
- type PasswordlessStartRequest
- type PermissionSet
- type PreferredLanguage
- type PreferredLanguageRequest
- type RateLimitResult
- type RateLimiter
- type RateLimiterWithResult
- type RegisterRequest
- type RegistrationCapabilities
- type RegistrationResult
- type RegistrationUser
- type RemovedRole
- type RemovedRoles
- type Reply
- type ReturnToRequest
- type RoleInfo
- type RouteSpec
- type Service
- func (s *Service) APIRoutes(groups ...iam.RouteGroup) []RouteSpec
- func (s *Service) Backend() Backend
- func (s *Service) Capabilities() Capabilities
- func (s *Service) Close()
- func (s *Service) GroupHandler(op GroupOp) http.HandlerFunc
- func (s *Service) JWKSHandler() http.Handler
- func (s *Service) OIDCBrowserRoutes(groups ...iam.RouteGroup) []RouteSpec
- func (s *Service) SMSAvailable() bool
- type SolanaAccount
- type SolanaCapabilities
- type SolanaChallenge
- type SolanaChallengeRequest
- type SolanaLink
- type SolanaLoginResult
- type SolanaSignInOutput
- type SolanaSignInRequest
- type SolanaUser
- type StepUpResult
- type Surface
- type TokenRefreshRequest
- type TokenRequest
- type TwoFactorCapabilities
- type TwoFactorChallengeRequest
- type TwoFactorEnrollRequest
- type TwoFactorEnrollResult
- type TwoFactorFactor
- type TwoFactorFactorQuery
- type TwoFactorStatus
- type TwoFactorStepUpRequest
- type TwoFactorVerifyRequest
- type UserListQuery
- type UserProfile
- type UsernameCapabilities
- type UsernameChange
- type UsernameRequest
- type VerificationCapabilities
- type WebAuthnCredential
- type WireField
- type WireKind
Constants ¶
const ( // 2FA-specific rate limit buckets RL2FAStartPhone = "auth_2fa_start_phone" RL2FAStartTOTP = "auth_2fa_start_totp" RL2FAStartEmail = "auth_2fa_start_email" RL2FAEnable = "auth_2fa_enable" RL2FADisable = "auth_2fa_disable" RL2FARegenerateCodes = "auth_2fa_regenerate_codes" RL2FAVerify = "auth_2fa_verify" RLAuthToken = "auth_token" RLAuthRegister = "auth_register" RLAuthRegisterAvailability = "auth_register_availability" RLAuthRegisterAbandon = "auth_register_abandon" RLInviteCreate = "auth_invite_create" RLInviteRedeem = "auth_invite_redeem" RLAPIKeyMint = "auth_api_key_mint" RLPasswordLogin = "auth_password_login" RLPasswordStepUp = "auth_password_step_up" RLPasswordlessStart = "auth_passwordless_start" RLPasswordlessConfirm = "auth_passwordless_confirm" RLPasskeyRegister = "auth_passkey_register" RLPasskeyLogin = "auth_passkey_login" RLDeviceKeyEnrollBegin = "auth_device_key_enroll_begin" RLDeviceKeyEnrollFinish = "auth_device_key_enroll_finish" RLDeviceKeyLoginBegin = "auth_device_key_login_begin" RLDeviceKeyLoginFinish = "auth_device_key_login_finish" RLDeviceKeysManage = "auth_device_keys_manage" RLAuthLogout = "auth_logout" RLAuthSessionsList = "auth_sessions_list" RLAuthSessionsRevoke = "auth_sessions_revoke" RLAuthSessionsRevokeAll = "auth_sessions_revoke_all" // #261 delegated-token mint (authenticated; bounds signing cost per IP). RLDelegatedTokenMint = "delegated_token_mint" RLPasswordResetRequest = "auth_pwd_reset_request" RLPasswordResetConfirm = "auth_pwd_reset_confirm" // #312: one bucket per contact flow, whichever channel the identifier names. RLVerifyRequest = "auth_verify_request" RLVerifyConfirm = "auth_verify_confirm" RLContactChangeRequest = "auth_contact_change_request" RLOIDCStart = "auth_oidc_start" RLOIDCCallback = "auth_oidc_callback" RLUserPasswordChange = "auth_user_password_change" RLUserMe = "auth_user_me" RLUserUpdateUsername = "auth_user_update_username" RLUserPreferredLanguage = "auth_user_preferred_language" RLUserDelete = "auth_user_delete" RLUserUnlinkProvider = "auth_user_unlink_provider" RLAdminUserSessionsList = "auth_admin_user_sessions_list" // The admin session route revokes ALL of a user's sessions; there is no // single-session admin revoke, so no RLAdminUserSessionsRevoke bucket. RLAdminUserSessionsRevokeAll = "auth_admin_user_sessions_revoke_all" // Solana SIWS authentication RLSolanaChallenge = "auth_solana_challenge" RLSolanaLogin = "auth_solana_login" RLSolanaLink = "auth_solana_link" )
Bucket names used by authkit endpoints; they key HTTPConfig.RateLimits.
const ( CookieRefresh cookieKind = "refresh" CookieOIDCState cookieKind = "oidc_state" OIDCStatePrefix = "authkit_oauth_state_" )
const OIDCPath = "/oidc"
Mount layout. The whole surface lives beneath one base path: the path of the issuer, so verifiers find JWKS at the issuer plus iam.JWKSPath. Beneath it, browser OIDC sits at OIDCPath and the JSON API at APIPath. The surface is ONE handler.
Variables ¶
var CookieRegistry = []CookieVariant{ {Kind: CookieRefresh, Name: "authkit_rt", Path: "/", Current: true}, {Kind: CookieRefresh, Name: "__Host-authkit_rt", Path: "/", Secure: true, Current: true}, {Kind: CookieOIDCState, Name: OIDCStatePrefix, Path: "/", Current: true}, {Kind: CookieOIDCState, Name: "__Host-" + OIDCStatePrefix, Path: "/", Secure: true, Current: true}, }
CookieRegistry is append-only.
var Features = []Feature{FeaturePasskeys, FeaturePasswordless, FeatureRegistration, FeatureTwoFactor, FeatureSolana, FeatureOIDC, FeatureDelegated, FeatureDeviceKeys, FeatureGroups, FeatureAPIKeys}
Features lists every Feature a route can be mounted under.
Functions ¶
func Conform ¶ added in v0.148.0
Conform checks decoded JSON v against t's wire form and lists every difference: a missing or unknown member, a null where none is allowed, a wrong JSON type, a time not in UTC.
func DefaultRateLimits ¶
DefaultRateLimits returns AuthKit's built-in per-endpoint rate limits, per client IP; "default" applies to any bucket not listed. Hosts overlay them with HTTPConfig.RateLimits or replace the limiter.
func SanitizeReturnTo ¶
sanitizeReturnTo admits only a same-origin absolute path: a leading "/" but not "//" or "/\" (browsers read both as scheme-relative), no control characters, no scheme or host. Anything else becomes "/".
Types ¶
type APIKeyCreateRequest ¶ added in v0.148.0
type Availability ¶ added in v0.148.0
type Availability struct {
Username *AvailabilityField `json:"username"`
Email *AvailabilityField `json:"email"`
PhoneNumber *AvailabilityField `json:"phone_number"`
}
Availability answers each field asked for; null for a field not asked.
type AvailabilityField ¶ added in v0.148.0
AvailabilityField is one answer; Error is the wire code that makes the value unavailable.
type AvailabilityQuery ¶ added in v0.148.0
type Backend ¶
type Backend interface {
ops.Operations
// contains filtered or unexported methods
}
Backend is the engine capability the HTTP layer drives: the operations the Client exposes (ops.Operations) plus the flows only the HTTP layer runs. The engine implements it; hosts never see it. Each domain's flow methods live in its own backend_<domain>.go.
type BackupCodes ¶ added in v0.148.0
type BackupCodes struct {
BackupCodes []string `json:"backup_codes"`
}
type BanRequest ¶ added in v0.148.0
type Capabilities ¶ added in v0.148.0
type Capabilities struct {
Registration RegistrationCapabilities `json:"registration"`
ExternalLoginProviders []ExternalLoginProvider `json:"external_login_providers"`
Username UsernameCapabilities `json:"username"`
Password PasswordCapabilities `json:"password"`
Passwordless PasswordlessCapabilities `json:"passwordless"`
Passkeys PasskeyCapabilities `json:"passkeys"`
Solana SolanaCapabilities `json:"solana"`
Verification VerificationCapabilities `json:"verification"`
Channels ChannelCapabilities `json:"channels"`
TwoFactor TwoFactorCapabilities `json:"two_factor"`
Languages []string `json:"languages"`
Paths MountPaths `json:"paths"`
}
Capabilities is the public, static feature discovery.
type ChannelCapabilities ¶ added in v0.148.0
ChannelCapabilities says which contact channels can deliver now: a sender is configured and, for SMS, its latest health check passed.
type ClientIPFunc ¶
ClientIPFunc determines the client IP used for rate limiting and auditing.
Returning an empty string means "unknown" and causes rate limiting to fail open.
func ClientIPFromForwardedHeaders ¶
func ClientIPFromForwardedHeaders(trusted, cloudflare []netip.Prefix) ClientIPFunc
ClientIPFromForwardedHeaders derives the client IP behind proxies the host declared. A peer inside trusted or cloudflare enables the right-to-left X-Forwarded-For walk (hops in either set are skipped as our own). Only a peer inside cloudflare may additionally be trusted for CF-Connecting-IP, and only as a fallback when X-Forwarded-For yields nothing: a generic reverse proxy forwards CF-Connecting-IP verbatim, so honouring it from any trusted peer let a client pick its own rate-limit key (ak#298). Any other peer resolves to itself.
Hosts that pass a cloudflare set must also lock the origin down to Cloudflare ingress; otherwise a client that reaches the origin directly is its own peer and both headers are ignored, which is the safe outcome.
func DefaultClientIP ¶
func DefaultClientIP() ClientIPFunc
DefaultClientIP returns the immediate peer IP from RemoteAddr.
This intentionally includes private and loopback peers so embedded/local deployments still get default rate-limit protection. Hosts behind reverse proxies should use ClientIPFromForwardedHeaders with trusted proxy CIDRs when they need the original public client IP instead of the proxy peer.
type CodeOrLinkRequest ¶ added in v0.148.0
type CookieVariant ¶
type CookieVariant struct {
Kind cookieKind
Name string
Path string
Domain string // AuthKit never sets Domain: every variant is host-only
Secure bool // issued on HTTPS deployments (always true for __Host-)
// Current marks the variant AuthKit issues now, per Secure mode.
Current bool
}
CookieVariant is one cookie shape AuthKit issues. An OIDC state name is a prefix completed by stateCookieName.
func CurrentCookie ¶
func CurrentCookie(kind cookieKind, secure bool) CookieVariant
func (CookieVariant) Identity ¶
func (v CookieVariant) Identity() string
Identity names a variant in testdata/cookie-registry.golden.
type DelegatedTokenRequest ¶ added in v0.148.0
type DelegatedTokenRequest struct {
// TTLSeconds is an optional override, clamped into the configured
// floor/ceiling; absent or <= 0 mints the configured default.
TTLSeconds int `json:"ttl_seconds"`
// Audiences is an optional narrowing; every requested audience must be in
// the configured allowlist. Absent mints the full configured list.
Audiences []string `json:"audiences"`
// DelegateCertificateDERB64URL is the delegate's public X.509 leaf as
// unpadded base64url DER; the token is bound to exactly this certificate.
// Omitted when a DPoP proof binds the token instead.
DelegateCertificateDERB64URL string `json:"delegate_certificate_der_b64url"`
// RequestedGrant is one host-schema JSON object passed to the authorizer
// verbatim and never copied into the token.
RequestedGrant json.RawMessage `json:"requested_grant"`
}
type DeviceKeyEnrollBeginRequest ¶ added in v0.148.0
type DeviceKeyEnrollFinishRequest ¶ added in v0.148.0
type DeviceKeyEnrollment ¶ added in v0.148.0
type DeviceKeyEnrollment struct {
EnrollmentID string `json:"enrollment_id"`
Challenge string `json:"challenge"`
ExpiresAt time.Time `json:"expires_at"`
}
DeviceKeyEnrollment is an enrollment ceremony in progress: the challenge to sign, beside the code emailed to the address.
type DeviceKeyLoginBeginRequest ¶ added in v0.148.0
type DeviceKeyLoginBeginRequest struct {
DeviceKeyID string `json:"device_key_id"`
}
type DeviceKeyLoginChallenge ¶ added in v0.148.0
type DeviceKeyLoginChallenge struct {
ChallengeID string `json:"challenge_id"`
Challenge string `json:"challenge"`
ExpiresAt time.Time `json:"expires_at"`
}
DeviceKeyLoginChallenge is the challenge a device key signs to sign in.
type DeviceKeyLoginFinishRequest ¶ added in v0.148.0
type DeviceKeySession ¶ added in v0.148.0
type DeviceKeySession struct {
TokenSet iam.TokenSet `json:"token_set"`
DeviceKey iam.DeviceKey `json:"device_key"`
}
DeviceKeySession is a device key's sign-in; the key is the token's own.
type ExternalLoginProvider ¶ added in v0.148.0
type Feature ¶ added in v0.148.0
type Feature string
Feature is the configuration a route needs to be mounted.
const ( Always Feature = "" FeaturePasskeys Feature = "passkeys" // Passkeys.RPID set FeaturePasswordless Feature = "passwordless" // passwordless login on FeatureRegistration Feature = "registration" // registration not closed FeatureTwoFactor Feature = "two_factor" // two-factor authentication not disabled FeatureSolana Feature = "solana" // a Solana network set FeatureOIDC Feature = "oidc" // an identity provider configured FeatureDelegated Feature = "delegated" // delegated-token audiences declared FeatureDeviceKeys Feature = "device_keys" // device keys on FeatureGroups Feature = "groups" // a persona besides root FeatureAPIKeys Feature = "api_keys" // a persona whose groups hold API keys )
type FreshAuth ¶ added in v0.148.0
type FreshAuth struct {
StepUpRequiredForSensitiveActions bool `json:"step_up_required_for_sensitive_actions"`
TimeUntilStepUpRequired int64 `json:"time_until_step_up_required"`
LastAuthenticatedAt *time.Time `json:"last_authenticated_at"`
AuthMethods []string `json:"auth_methods"`
}
FreshAuth is the session's step-up state after a re-authentication.
type GroupOp ¶
type GroupOp int
GroupOp is the operation a group route performs.
type GroupQuery ¶ added in v0.148.0
type GroupQuery struct {
GroupID string `query:"group_id"`
}
type IdentifierPasswordRequest ¶ added in v0.148.0
type IdentifierRequest ¶ added in v0.148.0
type IdentifierRequest struct {
Identifier string `json:"identifier"`
}
type InvitationCreateRequest ¶ added in v0.148.0
type InviteRedeemRequest ¶ added in v0.148.0
type InviteRedeemRequest struct {
Code string `json:"code"`
}
type LabelRequest ¶ added in v0.148.0
type LabelRequest struct {
Label string `json:"label"`
}
type MemberAddRequest ¶ added in v0.148.0
type MemberListQuery ¶ added in v0.148.0
type Mount ¶
type Mount struct {
// contains filtered or unexported fields
}
Mount is the canonical HTTP handler and its route catalog. Framework adapters use the catalog to register native routes, delegating requests to ServeHTTP so AuthKit still owns path values, authentication, JSON and cookie guards.
func NewMount ¶
NewMount builds the full AuthKit surface — JSON API, browser OIDC and JWKS — as ONE net/http handler plus its route catalog, as Config.HTTP declares it. Every route keeps the gate its RouteSpec carries; the mount adds no auth and removes none. Excluding a route does not alter the MFA-enrollment exempt set, so a shadowed enroll route stays reachable through the host's replacement.
type MountPaths ¶ added in v0.148.0
type MountPaths struct {
API string `json:"api"`
OIDC *string `json:"oidc"`
JWKS *string `json:"jwks"`
}
MountPaths are the serving mount's anchors as full paths, so a client that knows one AuthKit URL finds the rest; null when not mounted.
type OIDCCallbackQuery ¶ added in v0.148.0
type OIDCLoginQuery ¶ added in v0.148.0
type OIDCLoginRequest ¶ added in v0.148.0
type OIDCLoginResult ¶ added in v0.148.0
type OIDCLoginResult struct {
TokenSet iam.TokenSet `json:"token_set"`
User OIDCUser `json:"user"`
}
OIDCLoginResult is a provider sign-in's session, for a callback asked for JSON.
type OIDCStart ¶ added in v0.148.0
OIDCStart is where to send the browser to sign in with a provider.
type OIDCStepUpResult ¶ added in v0.148.0
type OIDCStepUpResult struct {
TokenSet iam.TokenSet `json:"token_set"`
FreshAuth FreshAuth `json:"fresh_auth"`
Provider string `json:"provider"`
}
OIDCStepUpResult is StepUpResult from a provider callback asked for JSON.
type PageQuery ¶ added in v0.148.0
PageQuery is ?cursor= and ?limit= of every paged list. The cursor is opaque; limit is 1-500 (default 50).
type PasskeyCapabilities ¶ added in v0.148.0
type PasskeyCapabilities struct {
Login bool `json:"login"`
}
type PasswordCapabilities ¶ added in v0.148.0
type PasswordCapabilities struct {
MinLength int `json:"min_length"`
MaxLength int `json:"max_length"`
RequireUppercase bool `json:"require_uppercase"`
RequireLowercase bool `json:"require_lowercase"`
RequireDigit bool `json:"require_digit"`
RequireSymbol bool `json:"require_symbol"`
AllowCommon bool `json:"allow_common"`
}
PasswordCapabilities is everything a browser needs to pre-validate a new password except the blocklist itself. AllowCommon says the blocklist is off.
type PasswordChangeRequest ¶ added in v0.148.0
type PasswordLoginRequest ¶ added in v0.148.0
type PasswordRequest ¶ added in v0.148.0
type PasswordRequest struct {
Password string `json:"password"`
}
PasswordRequest carries a password that re-authenticates the session.
type PasswordResetConfirmRequest ¶ added in v0.148.0
type PasswordlessCapabilities ¶ added in v0.148.0
type PasswordlessResult ¶ added in v0.148.0
type PasswordlessResult struct {
TokenSet iam.TokenSet `json:"token_set"`
ReturnTo *string `json:"return_to"`
}
PasswordlessResult is a passwordless sign-in's session.
type PasswordlessStartRequest ¶ added in v0.148.0
type PermissionSet ¶ added in v0.148.0
type PermissionSet struct {
GroupID string `json:"group_id"`
Permissions []iam.Perm `json:"permissions"`
}
PermissionSet is the caller's effective grants in one group.
type PreferredLanguage ¶ added in v0.148.0
type PreferredLanguage struct {
PreferredLanguage string `json:"preferred_language"`
}
type PreferredLanguageRequest ¶ added in v0.148.0
type PreferredLanguageRequest struct {
PreferredLanguage string `json:"preferred_language"`
}
type RateLimitResult ¶
type RateLimitResult struct {
Allowed bool
RetryAfter time.Duration
Availability *authflow.ActionAvailability
}
type RateLimiter ¶
RateLimiter is a minimal interface used by adapters.
type RateLimiterWithResult ¶
type RegisterRequest ¶ added in v0.148.0
type RegistrationCapabilities ¶ added in v0.148.0
type RegistrationResult ¶ added in v0.148.0
type RegistrationResult struct {
User RegistrationUser `json:"user"`
TokenSet iam.TokenSet `json:"token_set"`
}
RegistrationResult is a registration that signed in: who registered, and the session. A registration waiting on a verification code answers 202.
type RegistrationUser ¶ added in v0.148.0
type RemovedRole ¶ added in v0.148.0
type RemovedRoles ¶ added in v0.148.0
type RemovedRoles struct {
RemovedRoles []RemovedRole `json:"removed_roles"`
}
RemovedRoles are the roles disabling a factor removed, because they need MFA the account no longer has.
type Reply ¶ added in v0.148.0
Reply is one success outcome of a route: its status and body. Body is a zero value of the body's type, nil for none.
type ReturnToRequest ¶ added in v0.148.0
type ReturnToRequest struct {
ReturnTo string `json:"return_to"`
}
type RoleInfo ¶ added in v0.148.0
RoleInfo is one role of a group's persona and the permissions it grants.
type RouteSpec ¶
type RouteSpec struct {
Method string
Path string
Surface Surface
Group iam.RouteGroup
// Auth is the tier the route enforces before its handler runs.
Auth iam.RouteAuthTier
// Perm is the permission the route requires; `<persona>` stands for the
// addressed group's persona. The route checks it when Auth is
// AuthPermission; otherwise the operation does.
Perm string
// Bucket is the per-IP rate-limit bucket applied in front of the handler
// ("" = none). Per-identifier and branch-specific buckets stay in the
// handler.
Bucket string
// MountedWhen is the configuration the route needs.
MountedWhen Feature
// MFAEnrollmentExempt marks the 2FA enroll/challenge/verify surface a
// forced-enrollment-gated user must still reach (#243).
MFAEnrollmentExempt bool
// Query, Request: the query string and the JSON body (zero values; nil
// for none). Responses: every success outcome.
Query any
Request any
Responses []Reply
// Handler is the mounted handler, set by APIRoutes and OIDCBrowserRoutes.
Handler http.Handler
// contains filtered or unexported fields
}
RouteSpec is one route of AuthKit's HTTP surface: the static catalog entry that mounts it, gates it and documents it. Paths are prefix-neutral, with ServeMux wildcards.
func Catalog ¶ added in v0.148.0
func Catalog() []RouteSpec
Catalog is AuthKit's whole HTTP surface, every route a configuration can mount. It needs no database: APIRoutes and OIDCBrowserRoutes select a Service's routes from it, and internal/cmd/contract generates openapi.json and the TypeScript wire types from it.
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service wraps the internal AuthKit engine with net/http mounting helpers.
func New ¶
New assembles the HTTP layer over the engine, which also authenticates its requests, from the normalized configuration. authkit.New is the only production caller.
func (*Service) APIRoutes ¶
func (s *Service) APIRoutes(groups ...iam.RouteGroup) []RouteSpec
APIRoutes returns this Service's JSON API routes: the catalog's API routes its configuration mounts, in the given groups (all when none), each wrapped in its gate, rate limit and language middleware.
func (*Service) Capabilities ¶
func (s *Service) Capabilities() Capabilities
func (*Service) Close ¶
func (s *Service) Close()
Close stops the background work New started: the memory limiter sweep. The engine and Redis client are borrowed and remain owned by the host. Idempotent; safe on a nil Service.
func (*Service) GroupHandler ¶
func (s *Service) GroupHandler(op GroupOp) http.HandlerFunc
GroupHandler returns the handler for one group route. It:
- derives the caller's actor (401 if none; 403 for a delegation);
- resolves :group_id to a live group;
- refuses a group whose persona lacks the route, like an unknown group;
- authorizes the route's permission on the group with the engine's live Can, for every actor kind (403 on deny);
- performs the operation, whose engine call applies its own rules.
func (*Service) JWKSHandler ¶
JWKSHandler returns a handler for GET /.well-known/jwks.json. The key set is read per request so a hot-reloaded rotation or key removal is published immediately (ak#392).
func (*Service) OIDCBrowserRoutes ¶
func (s *Service) OIDCBrowserRoutes(groups ...iam.RouteGroup) []RouteSpec
OIDCBrowserRoutes returns the browser OIDC routes, prefix-neutral.
func (*Service) SMSAvailable ¶
SMSAvailable reports whether phone-based flows should be offered (a sender is configured and, if checked, found able to deliver).
type SolanaAccount ¶ added in v0.148.0
type SolanaCapabilities ¶ added in v0.148.0
type SolanaCapabilities struct {
Login bool `json:"login"`
}
type SolanaChallenge ¶ added in v0.148.0
type SolanaChallengeRequest ¶ added in v0.148.0
type SolanaLink ¶ added in v0.148.0
type SolanaLink struct {
SolanaAddress string `json:"solana_address"`
}
type SolanaLoginResult ¶ added in v0.148.0
type SolanaLoginResult struct {
TokenSet iam.TokenSet `json:"token_set"`
Created bool `json:"created"`
User SolanaUser `json:"user"`
}
type SolanaSignInOutput ¶ added in v0.148.0
type SolanaSignInOutput struct {
Account SolanaAccount `json:"account"`
Signature string `json:"signature"`
SignedMessage string `json:"signedMessage"`
}
type SolanaSignInRequest ¶ added in v0.148.0
type SolanaSignInRequest struct {
Output SolanaSignInOutput `json:"output"`
}
SolanaSignInRequest is the wallet-standard sign-in output: the one camelCase body on the wire.
type SolanaUser ¶ added in v0.148.0
type StepUpResult ¶ added in v0.148.0
type StepUpResult struct {
TokenSet iam.TokenSet `json:"token_set"`
FreshAuth FreshAuth `json:"fresh_auth"`
}
StepUpResult is a re-authenticated session: a fresh access token whose assurance claims match the session.
type Surface ¶ added in v0.148.0
type Surface string
Surface is where a route is anchored beneath the mount's base path.
type TokenRefreshRequest ¶ added in v0.148.0
type TokenRequest ¶ added in v0.148.0
type TokenRequest struct {
Token string `json:"token"`
}
type TwoFactorCapabilities ¶ added in v0.148.0
type TwoFactorCapabilities struct {
Mode iam.TwoFactorMode `json:"mode"`
Methods []iam.TwoFactorMethod `json:"methods"`
}
TwoFactorCapabilities is the 2FA policy and the second factors a user can enroll now (Client.TwoFactorMethods).
type TwoFactorChallengeRequest ¶ added in v0.148.0
type TwoFactorEnrollRequest ¶ added in v0.148.0
type TwoFactorEnrollResult ¶ added in v0.148.0
type TwoFactorEnrollResult struct {
Method string `json:"method"`
Enabled bool `json:"enabled"`
Secret *string `json:"secret"`
OTPAuthURI *string `json:"otpauth_uri"`
BackupCodes []string `json:"backup_codes"`
TokenSet *iam.TokenSet `json:"token_set"`
FreshAuth *FreshAuth `json:"fresh_auth"`
}
TwoFactorEnrollResult is a TOTP enrollment started (Secret, OTPAuthURI) or a factor enabled (Enabled, BackupCodes on the first factor; TokenSet when the enrollment signed the caller in or re-verified the session, with FreshAuth for the latter).
type TwoFactorFactor ¶ added in v0.148.0
type TwoFactorFactorQuery ¶ added in v0.148.0
type TwoFactorFactorQuery struct {
FactorID string `query:"factor_id"`
}
type TwoFactorStatus ¶ added in v0.148.0
type TwoFactorStatus struct {
Enabled bool `json:"enabled"`
Method string `json:"method"`
PhoneNumber *string `json:"phone_number"`
DefaultFactor *TwoFactorFactor `json:"default_factor"`
Factors []TwoFactorFactor `json:"factors"`
AllowedMethods []string `json:"allowed_methods"`
BackupCodesRemaining int `json:"backup_codes_remaining"`
}
type TwoFactorStepUpRequest ¶ added in v0.148.0
type TwoFactorVerifyRequest ¶ added in v0.148.0
type UserListQuery ¶ added in v0.148.0
type UserProfile ¶ added in v0.148.0
type UserProfile = authflow.UserProfile
UserProfile is GET /me: the account and its sign-in, security and naming state.
type UsernameCapabilities ¶ added in v0.148.0
type UsernameCapabilities struct {
MinLength int `json:"min_length"`
MaxLength int `json:"max_length"`
Pattern string `json:"pattern"`
Renames bool `json:"renames"`
RenameIntervalSeconds int64 `json:"rename_interval_seconds"`
FormerNames naming.PolicyInfo `json:"former_names"`
}
UsernameCapabilities is the interactive username rule. Pattern is the fixed character rule; length is bounded separately. Renames says whether users may rename themselves, and how often.
type UsernameChange ¶ added in v0.148.0
type UsernameRequest ¶ added in v0.148.0
type UsernameRequest struct {
Username string `json:"username"`
}
type VerificationCapabilities ¶ added in v0.148.0
type VerificationCapabilities struct {
Registration string `json:"registration"`
}
type WebAuthnCredential ¶ added in v0.148.0
type WebAuthnCredential = json.RawMessage
WebAuthnCredential is a browser's WebAuthn credential response, passed through as the browser produced it.
type WireField ¶ added in v0.148.0
type WireField struct {
Name string
Type reflect.Type
// Optional marks an omitempty member, absent when zero: only protocol
// documents (JWKS) have them.
Optional bool
// Tag is the field's full json tag.
Tag string
}
WireField is one JSON member of an object.
Source Files
¶
- account_recovery.go
- admin_roles.go
- admin_routes.go
- admin_signins.go
- audit.go
- auth_token_post.go
- auth_tokens.go
- availability.go
- backend.go
- backend_apps.go
- backend_flows.go
- backend_groups.go
- backend_invites.go
- backend_sessions.go
- backend_users.go
- browser_error.go
- buckets.go
- catalog.go
- client_ip.go
- confirm_errors.go
- contact_channel.go
- cookies.go
- delegated_token.go
- device_keys.go
- errors.go
- group_apikeys.go
- group_invites.go
- group_members.go
- group_routes.go
- internal_errors.go
- json_boundary.go
- jwks_get.go
- language.go
- login_continuation.go
- logout_delete.go
- mount.go
- oidc_browser.go
- oidc_util.go
- passkeys.go
- password_login_post.go
- passwordless.go
- permission_gate.go
- permission_group_routes.go
- providers.go
- providers_get.go
- ratelimit.go
- refresh_cookie.go
- register.go
- register_availability.go
- respond.go
- routes.go
- server.go
- service.go
- solana_siws.go
- step_up.go
- user_2fa.go
- user_2fa_verify_post.go
- user_me_get.go
- user_password_post.go
- user_routes.go
- user_sessions.go
- util.go
- wire.go
- wiremodel.go