ident

package
v0.148.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: MIT Imports: 4 Imported by: 0

Documentation

Overview

Package ident builds iam identifiers from strings AuthKit already trusts: stored rows, verified token claims, its compiled role schema and its own tests. A string that fails the syntax check yields the zero value, which matches and grants nothing. Host input goes through the schema instead (Client.Persona, Client.Permission, Client.Role).

Index

Constants

View Source
const MaxIssuerLen = 512

MaxIssuerLen bounds a remote-application issuer.

Variables

View Source
var (
	RootUsersRead   = Perm("root:users:read")   // list and read accounts and their sign-ins
	RootUsersBan    = Perm("root:users:ban")    // ban / unban an account
	RootUsersDelete = Perm("root:users:delete") // soft-delete and restore an account
	RootUsersManage = Perm("root:users:manage") // edit another account, revoke its sessions
	RootUsersInvite = Perm("root:users:invite") // invite someone to create an account
)

The intrinsic root permissions gating AuthKit's account administration.

Functions

func CredentialsManage

func CredentialsManage(p iam.Persona) iam.Perm

CredentialsManage gates creating, revoking and re-roling API keys and remote applications. Registered with CredentialsRead.

func CredentialsRead

func CredentialsRead(p iam.Persona) iam.Perm

CredentialsRead gates listing API keys. Registered only for personas with API keys or remote applications.

func IntrinsicRootPermissions

func IntrinsicRootPermissions() []iam.Perm

IntrinsicRootPermissions are the root permissions every deployment registers besides the members built-ins.

func MembersManage

func MembersManage(p iam.Persona) iam.Perm

MembersManage gates adding, removing and re-roling members and invitations.

func MembersRead

func MembersRead(p iam.Persona) iam.Perm

MembersRead gates listing a group's members and its role catalog.

func Perm

func Perm(s string) iam.Perm

func Perms

func Perms(ss []string) []iam.Perm

Perms converts each string with Perm.

func Persona

func Persona(s string) iam.Persona

func Role

func Role(persona iam.Persona, name string) iam.Role

Role is persona's role name; the zero Role when either is invalid.

func RoleText

func RoleText(s string) iam.Role

RoleText reads a role's text form `<persona>:<name>`, as rows store it; the zero Role when it is malformed.

func Strings

func Strings[T fmt.Stringer](vs []T) []string

Strings is each value's String.

func ValidIssuer

func ValidIssuer(iss string) bool

ValidIssuer reports whether iss has the shape every registered remote-application issuer has: an absolute http(s) URL with a host, at most MaxIssuerLen bytes, no whitespace or control characters. Registration enforces it, and the verifier applies it to a token's self-asserted iss before any store lookup.

func ValidSegment

func ValidSegment(s string) bool

ValidSegment reports whether s is one permission segment (a persona, resource, action or role name): [a-z][a-z0-9-]*.

func ValidateGrantPattern

func ValidateGrantPattern(g string) error

ValidateGrantPattern checks what a role holds: a concrete permission or a namespace-anchored glob, never a bare `*`:

<persona>:<resource>:<action>   a concrete permission
<persona>:<resource>:*          every action on a resource
<persona>:*                     the whole persona namespace (the owner)

It is stricter than iam.Perm.Matches: it refuses mid-glob forms such as `persona:*:action`.

func ValidatePermission

func ValidatePermission(p string) error

ValidatePermission checks a concrete catalog permission: exactly three segments `<persona>:<resource>:<action>` (`merchant:catalog:update`).

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL