Documentation
¶
Index ¶
- Constants
- Variables
- func Conform(t reflect.Type, v any) []string
- func DefaultRateLimits() map[string]ratelimit.Limit
- func ErrorMetadata() map[errmodel.Code]any
- func IsPage(t reflect.Type) bool
- func PageItem(t reflect.Type) reflect.Type
- func SanitizeReturnTo(value string) string
- type APIKeyCreateRequest
- type AdminUserUpdateRequest
- type AuthResult
- type AuthStatus
- type Availability
- type AvailabilityField
- type AvailabilityQuery
- type Backend
- type BackupCodes
- type BanRequest
- type Capabilities
- type ChannelCapabilities
- type ClientIPFunc
- type CodeOrLinkRequest
- type CookieVariant
- type DelegatedTokenRequest
- type DeviceKeyEnrollBeginRequest
- type DeviceKeyEnrollFinishRequest
- type DeviceKeyEnrollment
- type DeviceKeyLoginBeginRequest
- type DeviceKeyLoginChallenge
- type DeviceKeyLoginFinishRequest
- type EmailChangeRequest
- type EnrollmentStep
- type ExternalLoginProvider
- type Feature
- type FreshAuth
- type GroupOp
- type GroupQuery
- type IdentifierPasswordRequest
- type IdentifierRequest
- type InvitationCreateRequest
- type InvitationRedeemRequest
- type LabelRequest
- type MemberListQuery
- type MemberRoleRequest
- type Mount
- type MountPaths
- type OIDCCallbackQuery
- type OIDCExchangeRequest
- type OIDCLoginQuery
- type OIDCLoginStartRequest
- type OIDCStart
- type PageQuery
- type PasskeyCapabilities
- type PasswordCapabilities
- type PasswordChangeRequest
- type PasswordLoginRequest
- type PasswordRequest
- type PasswordResetConfirmRequest
- type PasswordlessCapabilities
- type PasswordlessStartRequest
- type PermissionSet
- type PhoneChangeRequest
- type ProfileUpdateRequest
- type ProviderError
- type RateLimitResult
- type RateLimiter
- type RateLimiterWithResult
- type RegisterRequest
- type RegistrationCapabilities
- type Reply
- type ReturnToRequest
- type RoleInfo
- type RouteSpec
- type SecondFactorStep
- type Service
- func (s *Service) APIRoutes(groups ...iam.RouteGroup) []RouteSpec
- func (s *Service) Backend() Backend
- func (s *Service) Capabilities() Capabilities
- func (s *Service) Close()
- func (s *Service) GroupHandler(op GroupOp) http.HandlerFunc
- func (s *Service) JWKSHandler() http.Handler
- func (s *Service) OIDCBrowserRoutes(groups ...iam.RouteGroup) []RouteSpec
- type SessionEventQuery
- type SignInKey
- type SignInKeyKind
- type SolanaAccount
- type SolanaCapabilities
- type SolanaChallenge
- type SolanaChallengeRequest
- type SolanaSignInOutput
- type SolanaSignInRequest
- type Surface
- type TokenRefreshRequest
- type TokenRequest
- type TwoFactorCapabilities
- type TwoFactorChallengeRequest
- type TwoFactorFactor
- type TwoFactorFactorCreateRequest
- type TwoFactorFactorCreated
- type TwoFactorFactorUpdateRequest
- type TwoFactorRequired
- type TwoFactorSendRequest
- type TwoFactorSetup
- type TwoFactorSetupRequest
- type TwoFactorStatus
- type TwoFactorStepUpRequest
- type TwoFactorVerifyRequest
- type UserListQuery
- type UserProfile
- type UserSecurity
- type UsernameCapabilities
- type UsersQuery
- type VerificationCapabilities
- type VerificationStep
- type WebAuthnCredential
- type WireField
- type WireKind
Constants ¶
const ( // 2FA-specific rate limit buckets RL2FAStartPhone = "auth_2fa_start_phone" RL2FAStartTOTP = "auth_2fa_start_totp" RL2FAStartEmail = "auth_2fa_start_email" RL2FAEnable = "auth_2fa_enable" RL2FADisable = "auth_2fa_disable" RL2FARegenerateCodes = "auth_2fa_regenerate_codes" RL2FAVerify = "auth_2fa_verify" RLAuthToken = "auth_token" RLAuthRegister = "auth_register" RLAuthRegisterAvailability = "auth_register_availability" RLAuthRegisterAbandon = "auth_register_abandon" RLInviteCreate = "auth_invite_create" RLInviteRedeem = "auth_invite_redeem" RLAPIKeyMint = "auth_api_key_mint" RLPasswordLogin = "auth_password_login" RLPasswordStepUp = "auth_password_step_up" RLPasswordlessStart = "auth_passwordless_start" RLPasswordlessConfirm = "auth_passwordless_confirm" RLPasskeyRegister = "auth_passkey_register" RLPasskeyLogin = "auth_passkey_login" RLDeviceKeyEnrollBegin = "auth_device_key_enroll_begin" RLDeviceKeyEnrollFinish = "auth_device_key_enroll_finish" RLDeviceKeyLoginBegin = "auth_device_key_login_begin" RLDeviceKeyLoginFinish = "auth_device_key_login_finish" RLDeviceKeysManage = "auth_device_keys_manage" RLAuthLogout = "auth_logout" RLAuthSessionsList = "auth_sessions_list" RLAuthSessionsRevoke = "auth_sessions_revoke" RLAuthSessionsRevokeAll = "auth_sessions_revoke_all" // #261 delegated-token mint (authenticated; bounds signing cost per IP). RLDelegatedTokenMint = "delegated_token_mint" RLPasswordResetRequest = "auth_pwd_reset_request" RLPasswordResetConfirm = "auth_pwd_reset_confirm" // #312: one bucket per contact flow, whichever channel the identifier names. RLVerifyRequest = "auth_verify_request" RLVerifyConfirm = "auth_verify_confirm" RLContactChangeRequest = "auth_contact_change_request" RLOIDCStart = "auth_oidc_start" RLOIDCCallback = "auth_oidc_callback" RLUserPasswordChange = "auth_user_password_change" RLUserMe = "auth_user_me" RLUserUpdate = "auth_user_update" RLStepUp2FASend = "auth_step_up_2fa_send" RLUserDelete = "auth_user_delete" RLUserUnlinkProvider = "auth_user_unlink_provider" RLAdminRead = "auth_admin_read" RLAdminWrite = "auth_admin_write" // Solana SIWS authentication RLSolanaChallenge = "auth_solana_challenge" RLSolanaLogin = "auth_solana_login" RLSolanaLink = "auth_solana_link" )
Bucket names used by authkit endpoints; they key HTTPConfig.RateLimits.
const ( CookieRefresh cookieKind = "refresh" CookieOIDCState cookieKind = "oidc_state" OIDCStatePrefix = "authkit_oauth_state_" )
const OIDCPath = "/oidc"
Mount layout. The whole surface lives beneath one base path: the path of the issuer, so verifiers find JWKS at the issuer plus iam.JWKSPath. Beneath it, browser OIDC sits at OIDCPath and the JSON API at APIPath. The surface is ONE handler.
Variables ¶
var CookieRegistry = []CookieVariant{ {Kind: CookieRefresh, Name: "authkit_rt", Path: "/", Current: true}, {Kind: CookieRefresh, Name: "__Host-authkit_rt", Path: "/", Secure: true, Current: true}, {Kind: CookieOIDCState, Name: OIDCStatePrefix, Path: "/", Current: true}, {Kind: CookieOIDCState, Name: "__Host-" + OIDCStatePrefix, Path: "/", Secure: true, Current: true}, }
CookieRegistry is append-only.
var Features = []Feature{FeaturePasskeys, FeaturePasswordless, FeatureRegistration, FeatureTwoFactor, FeatureSolana, FeatureOIDC, FeatureDelegated, FeatureDeviceKeys, FeatureGroups, FeatureAPIKeys}
Features lists every Feature a route can be mounted under.
Functions ¶
func Conform ¶ added in v0.148.0
Conform checks decoded JSON v against t's wire form and lists every difference: a missing or unknown member, a null where none is allowed, a wrong JSON type, a time not in UTC.
func DefaultRateLimits ¶
DefaultRateLimits returns AuthKit's built-in per-endpoint rate limits, per client IP; "default" applies to any bucket not listed. Hosts overlay them with HTTPConfig.RateLimits or replace the limiter.
func ErrorMetadata ¶ added in v0.149.0
ErrorMetadata is the metadata shape of every code that carries metadata (zero values); every other code's metadata is null. The contract generator publishes it, and the integration suites check every error against it.
func SanitizeReturnTo ¶
sanitizeReturnTo admits only a same-origin absolute path: a leading "/" but not "//" or "/\" (browsers read both as scheme-relative), no control characters, no scheme or host. Anything else becomes "/".
Types ¶
type APIKeyCreateRequest ¶ added in v0.148.0
type AdminUserUpdateRequest ¶ added in v0.149.0
type AdminUserUpdateRequest struct {
Email *string `json:"email"`
PhoneNumber *string `json:"phone_number"`
Username *string `json:"username"`
AvatarURL *string `json:"avatar_url"`
PreferredLanguage *string `json:"preferred_language"`
}
AdminUserUpdateRequest is PATCH /admin/users/{user_id}: an absent field is unchanged.
type AuthResult ¶ added in v0.149.0
type AuthResult struct {
Status AuthStatus `json:"status"`
TokenSet *iam.TokenSet `json:"token_set"`
User *iam.User `json:"user"`
// Created: this sign-in created the account.
Created bool `json:"created"`
ReturnTo *string `json:"return_to"`
// FreshAuth: the session's step-up state after a re-authentication.
FreshAuth *FreshAuth `json:"fresh_auth"`
// DeviceKey: a device-key sign-in's key.
DeviceKey *iam.DeviceKey `json:"device_key"`
SecondFactor *SecondFactorStep `json:"second_factor"`
Enrollment *EnrollmentStep `json:"enrollment"`
Verification *VerificationStep `json:"verification"`
Recovery *authflow.AccountRecoveryConfirmation `json:"recovery"`
}
AuthResult is every sign-in and re-authentication answer: a session, or the one next step the status names. Only the members of that status are set; the rest are null.
type AuthStatus ¶ added in v0.149.0
type AuthStatus string
AuthStatus is where a sign-in stands.
const ( // AuthComplete: signed in (or re-authenticated); token_set and user are set. AuthComplete AuthStatus = "complete" // AuthSecondFactorRequired: the first factor passed; answer second_factor // at POST /2fa/verify (or switch factor at POST /2fa/challenge). AuthSecondFactorRequired AuthStatus = "second_factor_required" // AuthEnrollmentRequired: the account must add a second factor first; // enrollment.token_set reaches only POST /me/2fa/setup and /me/2fa/factors. AuthEnrollmentRequired AuthStatus = "enrollment_required" // AuthVerificationRequired: a code went to verification.identifier; confirm // it at POST /verify/confirm. AuthVerificationRequired AuthStatus = "verification_required" // AuthAccountRecoveryRequired: the account is deleted and restorable; // confirm recovery.token at POST /account/recovery/confirm. AuthAccountRecoveryRequired AuthStatus = "account_recovery_required" )
type Availability ¶ added in v0.148.0
type Availability struct {
Username *AvailabilityField `json:"username"`
Email *AvailabilityField `json:"email"`
PhoneNumber *AvailabilityField `json:"phone_number"`
}
Availability answers each field asked for; null for a field not asked.
type AvailabilityField ¶ added in v0.148.0
AvailabilityField is one answer; Error is the wire code that makes the value unavailable.
type AvailabilityQuery ¶ added in v0.148.0
type Backend ¶
type Backend interface {
ops.Operations
// contains filtered or unexported methods
}
Backend is the engine capability the HTTP layer drives: the operations the Client exposes (ops.Operations) plus the flows only the HTTP layer runs. The engine implements it; hosts never see it. Each domain's flow methods live in its own backend_<domain>.go.
type BackupCodes ¶ added in v0.148.0
type BackupCodes struct {
BackupCodes []string `json:"backup_codes"`
}
type BanRequest ¶ added in v0.148.0
BanRequest is the ban to put in force; a null until bans indefinitely.
type Capabilities ¶ added in v0.148.0
type Capabilities struct {
Registration RegistrationCapabilities `json:"registration"`
ExternalLoginProviders []ExternalLoginProvider `json:"external_login_providers"`
Username UsernameCapabilities `json:"username"`
Password PasswordCapabilities `json:"password"`
Passwordless PasswordlessCapabilities `json:"passwordless"`
Passkeys PasskeyCapabilities `json:"passkeys"`
Solana SolanaCapabilities `json:"solana"`
Verification VerificationCapabilities `json:"verification"`
Channels ChannelCapabilities `json:"channels"`
TwoFactor TwoFactorCapabilities `json:"two_factor"`
Languages []string `json:"languages"`
Paths MountPaths `json:"paths"`
}
Capabilities is the public, static feature discovery.
type ChannelCapabilities ¶ added in v0.148.0
ChannelCapabilities says which contact channels can deliver now: a sender is configured and its latest health check, if any, passed.
type ClientIPFunc ¶
ClientIPFunc determines the client IP used for rate limiting and auditing.
Returning an empty string means "unknown" and causes rate limiting to fail open.
func ClientIPFromForwardedHeaders ¶
func ClientIPFromForwardedHeaders(trusted, cloudflare []netip.Prefix) ClientIPFunc
ClientIPFromForwardedHeaders derives the client IP behind proxies the host declared. A peer inside trusted or cloudflare enables the right-to-left X-Forwarded-For walk (hops in either set are skipped as our own). Only a peer inside cloudflare may additionally be trusted for CF-Connecting-IP, and only as a fallback when X-Forwarded-For yields nothing: a generic reverse proxy forwards CF-Connecting-IP verbatim, so honouring it from any trusted peer let a client pick its own rate-limit key (ak#298). Any other peer resolves to itself.
Hosts that pass a cloudflare set must also lock the origin down to Cloudflare ingress; otherwise a client that reaches the origin directly is its own peer and both headers are ignored, which is the safe outcome.
func DefaultClientIP ¶
func DefaultClientIP() ClientIPFunc
DefaultClientIP returns the immediate peer IP from RemoteAddr.
This intentionally includes private and loopback peers so embedded/local deployments still get default rate-limit protection. Hosts behind reverse proxies should use ClientIPFromForwardedHeaders with trusted proxy CIDRs when they need the original public client IP instead of the proxy peer.
type CodeOrLinkRequest ¶ added in v0.148.0
type CookieVariant ¶
type CookieVariant struct {
Kind cookieKind
Name string
Path string
Domain string // AuthKit never sets Domain: every variant is host-only
Secure bool // issued on HTTPS deployments (always true for __Host-)
// Current marks the variant AuthKit issues now, per Secure mode.
Current bool
}
CookieVariant is one cookie shape AuthKit issues. An OIDC state name is a prefix completed by stateCookieName.
func CurrentCookie ¶
func CurrentCookie(kind cookieKind, secure bool) CookieVariant
func (CookieVariant) Identity ¶
func (v CookieVariant) Identity() string
Identity names a variant in testdata/cookie-registry.golden.
type DelegatedTokenRequest ¶ added in v0.148.0
type DelegatedTokenRequest struct {
// TTLSeconds is an optional override, clamped into the configured
// floor/ceiling; absent or <= 0 mints the configured default.
TTLSeconds int `json:"ttl_seconds"`
// Audiences is an optional narrowing; every requested audience must be in
// the configured allowlist. Absent mints the full configured list.
Audiences []string `json:"audiences"`
// DelegateCertificateDERB64URL is the delegate's public X.509 leaf as
// unpadded base64url DER; the token is bound to exactly this certificate.
// Omitted when a DPoP proof binds the token instead.
DelegateCertificateDERB64URL string `json:"delegate_certificate_der_b64url"`
// RequestedGrant is one host-schema JSON object passed to the authorizer
// verbatim and never copied into the token.
RequestedGrant json.RawMessage `json:"requested_grant"`
}
type DeviceKeyEnrollBeginRequest ¶ added in v0.148.0
type DeviceKeyEnrollFinishRequest ¶ added in v0.148.0
type DeviceKeyEnrollment ¶ added in v0.148.0
type DeviceKeyEnrollment struct {
EnrollmentID string `json:"enrollment_id"`
Challenge string `json:"challenge"`
ExpiresAt time.Time `json:"expires_at"`
}
DeviceKeyEnrollment is an enrollment ceremony in progress: the challenge to sign, beside the code emailed to the address.
type DeviceKeyLoginBeginRequest ¶ added in v0.148.0
type DeviceKeyLoginBeginRequest struct {
DeviceKeyID string `json:"device_key_id"`
}
type DeviceKeyLoginChallenge ¶ added in v0.148.0
type DeviceKeyLoginChallenge struct {
ChallengeID string `json:"challenge_id"`
Challenge string `json:"challenge"`
ExpiresAt time.Time `json:"expires_at"`
}
DeviceKeyLoginChallenge is the challenge a device key signs to sign in.
type DeviceKeyLoginFinishRequest ¶ added in v0.148.0
type EmailChangeRequest ¶ added in v0.149.0
type EmailChangeRequest struct {
Email string `json:"email"`
}
type EnrollmentStep ¶ added in v0.149.0
type EnrollmentStep struct {
TokenSet iam.TokenSet `json:"token_set"`
AllowedMethods []iam.TwoFactorMethod `json:"allowed_methods"`
}
EnrollmentStep is a sign-in waiting on a first second factor. TokenSet is a restricted enrollment token, not a session.
type ExternalLoginProvider ¶ added in v0.148.0
type Feature ¶ added in v0.148.0
type Feature string
Feature is the configuration a route needs to be mounted.
const ( Always Feature = "" FeaturePasskeys Feature = "passkeys" // Passkeys.RPID set FeaturePasswordless Feature = "passwordless" // passwordless login on FeatureRegistration Feature = "registration" // registration not closed FeatureTwoFactor Feature = "two_factor" // two-factor authentication not disabled FeatureSolana Feature = "solana" // a Solana network set FeatureOIDC Feature = "oidc" // an identity provider configured FeatureDelegated Feature = "delegated" // delegated-token audiences declared FeatureDeviceKeys Feature = "device_keys" // device keys on FeatureGroups Feature = "groups" // a persona besides root FeatureAPIKeys Feature = "api_keys" // a persona whose groups hold API keys )
type FreshAuth ¶ added in v0.148.0
FreshAuth is the session's step-up state after a re-authentication.
type GroupOp ¶
type GroupOp int
GroupOp is the operation a group route performs.
func (GroupOp) Available ¶
Available reports whether groups of persona p have the operation. Every group, root included, has members, roles and invitations.
type GroupQuery ¶ added in v0.148.0
type GroupQuery struct {
GroupID string `query:"group_id"`
}
type IdentifierPasswordRequest ¶ added in v0.148.0
type IdentifierRequest ¶ added in v0.148.0
type IdentifierRequest struct {
Identifier string `json:"identifier"`
}
type InvitationCreateRequest ¶ added in v0.148.0
type InvitationCreateRequest struct {
Role string `json:"role"`
Email string `json:"email"`
ExpiresAt *time.Time `json:"expires_at"`
}
InvitationCreateRequest makes an invite link (no email), or emails an invitation. A root invitation with an email and no role invites someone to register.
type InvitationRedeemRequest ¶ added in v0.149.0
type InvitationRedeemRequest struct {
Code string `json:"code"`
}
type LabelRequest ¶ added in v0.148.0
type LabelRequest struct {
Label string `json:"label"`
}
type MemberListQuery ¶ added in v0.148.0
type MemberListQuery struct {
PageQuery
Kind []string `query:"kind"`
Role []string `query:"role"`
Expand []string `query:"expand"`
}
MemberListQuery filters a group's members; kind and role repeat, and expand=user adds each user member's PublicUser.
type MemberRoleRequest ¶ added in v0.149.0
type MemberRoleRequest struct {
Role string `json:"role"`
}
MemberRoleRequest is the role a member holds in the group.
type Mount ¶
type Mount struct {
// contains filtered or unexported fields
}
Mount is the canonical HTTP handler and its route catalog. Framework adapters use the catalog to register native routes, delegating requests to ServeHTTP so AuthKit still owns path values, authentication, JSON and cookie guards.
func NewMount ¶
NewMount builds the full AuthKit surface — JSON API, browser OIDC and JWKS — as ONE net/http handler plus its route catalog, as Config.HTTP declares it. Every route keeps the gate its RouteSpec carries; the mount adds no auth and removes none. Excluding a route does not alter the MFA-enrollment exempt set, so a shadowed enroll route stays reachable through the host's replacement.
type MountPaths ¶ added in v0.148.0
type MountPaths struct {
API string `json:"api"`
OIDC *string `json:"oidc"`
JWKS *string `json:"jwks"`
}
MountPaths are the serving mount's anchors as full paths, so a client that knows one AuthKit URL finds the rest; null when not mounted.
type OIDCCallbackQuery ¶ added in v0.148.0
type OIDCExchangeRequest ¶ added in v0.149.0
type OIDCExchangeRequest struct {
Code string `json:"code"`
}
OIDCExchangeRequest trades a browser OIDC result's one-time code.
type OIDCLoginQuery ¶ added in v0.148.0
type OIDCLoginStartRequest ¶ added in v0.149.0
type OIDCStart ¶ added in v0.148.0
OIDCStart is where to send the browser to sign in with a provider.
type PageQuery ¶ added in v0.148.0
PageQuery is ?cursor= and ?limit= of every paged list. The cursor is opaque; limit is 1-500 (default 50).
type PasskeyCapabilities ¶ added in v0.148.0
type PasskeyCapabilities struct {
Login bool `json:"login"`
}
type PasswordCapabilities ¶ added in v0.148.0
type PasswordCapabilities struct {
MinLength int `json:"min_length"`
MaxLength int `json:"max_length"`
RequireUppercase bool `json:"require_uppercase"`
RequireLowercase bool `json:"require_lowercase"`
RequireDigit bool `json:"require_digit"`
RequireSymbol bool `json:"require_symbol"`
AllowCommon bool `json:"allow_common"`
}
PasswordCapabilities is everything a browser needs to pre-validate a new password except the blocklist itself. AllowCommon says the blocklist is off.
type PasswordChangeRequest ¶ added in v0.148.0
type PasswordLoginRequest ¶ added in v0.148.0
type PasswordRequest ¶ added in v0.148.0
type PasswordRequest struct {
Password string `json:"password"`
}
PasswordRequest carries a password that re-authenticates the session.
type PasswordResetConfirmRequest ¶ added in v0.148.0
type PasswordlessCapabilities ¶ added in v0.148.0
type PasswordlessStartRequest ¶ added in v0.148.0
type PermissionSet ¶ added in v0.148.0
type PermissionSet struct {
GroupID string `json:"group_id"`
Role *iam.Role `json:"role"`
Permissions []iam.Perm `json:"permissions"`
}
PermissionSet is the caller's role and effective permissions in one group, expanded over the persona's catalog: set membership, no pattern matching.
type PhoneChangeRequest ¶ added in v0.149.0
type PhoneChangeRequest struct {
PhoneNumber string `json:"phone_number"`
}
type ProfileUpdateRequest ¶ added in v0.149.0
type ProfileUpdateRequest struct {
Username *string `json:"username"`
PreferredLanguage *string `json:"preferred_language"`
AvatarURL *string `json:"avatar_url"`
}
ProfileUpdateRequest is PATCH /me: an absent field is unchanged; an empty avatar_url clears it.
type ProviderError ¶ added in v0.149.0
type ProviderError struct {
ProviderError string `json:"provider_error"`
}
ProviderError is provider_error's metadata: the identity provider's own error code.
type RateLimitResult ¶
type RateLimitResult struct {
Allowed bool
RetryAfter time.Duration
Availability *authflow.ActionAvailability
}
type RateLimiter ¶
RateLimiter is a minimal interface used by adapters.
type RateLimiterWithResult ¶
type RegisterRequest ¶ added in v0.148.0
type RegistrationCapabilities ¶ added in v0.148.0
type Reply ¶ added in v0.148.0
Reply is one success outcome of a route: its status and body. Body is a zero value of the body's type, nil for none.
type ReturnToRequest ¶ added in v0.148.0
type ReturnToRequest struct {
ReturnTo string `json:"return_to"`
}
type RoleInfo ¶ added in v0.148.0
RoleInfo is one role of a group's persona and every permission it grants, expanded from its patterns over the persona's catalog.
type RouteSpec ¶
type RouteSpec struct {
Method string
Path string
Surface Surface
Group iam.RouteGroup
// Auth is the tier the route enforces before its handler runs.
Auth iam.RouteAuthTier
// Perm is the permission the route requires; `<persona>` stands for the
// addressed group's persona. The route checks it when Auth is
// AuthPermission; otherwise the operation does.
Perm string
// Bucket is the per-IP rate-limit bucket applied in front of the handler
// ("" = none). Per-identifier and branch-specific buckets stay in the
// handler.
Bucket string
// MountedWhen is the configuration the route needs.
MountedWhen Feature
// StepUp: the caller must have signed in recently (a step-up, MFA-fresh
// when enrolled), checked after the session (M7).
StepUp bool
// MFAEnrollmentExempt marks the 2FA enroll/challenge/verify surface a
// forced-enrollment-gated user must still reach (#243).
MFAEnrollmentExempt bool
// Query, Request: the query string and the JSON body (zero values; nil
// for none). Responses: every success outcome.
Query any
Request any
Responses []Reply
// Handler is the mounted handler, set by APIRoutes and OIDCBrowserRoutes.
Handler http.Handler
// contains filtered or unexported fields
}
RouteSpec is one route of AuthKit's HTTP surface: the static catalog entry that mounts it, gates it and documents it. Paths are prefix-neutral, with ServeMux wildcards.
func Catalog ¶ added in v0.148.0
func Catalog() []RouteSpec
Catalog is AuthKit's whole HTTP surface, every route a configuration can mount. It needs no database: APIRoutes and OIDCBrowserRoutes select a Service's routes from it, and internal/cmd/contract generates openapi.json and the TypeScript wire types from it.
type SecondFactorStep ¶ added in v0.149.0
type SecondFactorStep struct {
UserID string `json:"user_id"`
Challenge string `json:"challenge"`
Factor TwoFactorFactor `json:"factor"`
Factors []TwoFactorFactor `json:"factors"`
}
SecondFactorStep is a sign-in waiting on its second factor: the challenge to answer, the factor its code went to, and the factors to switch to.
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service wraps the internal AuthKit engine with net/http mounting helpers.
func New ¶
New assembles the HTTP layer over the engine, which also authenticates its requests, from the normalized configuration. authkit.New is the only production caller.
func (*Service) APIRoutes ¶
func (s *Service) APIRoutes(groups ...iam.RouteGroup) []RouteSpec
APIRoutes returns this Service's JSON API routes: the catalog's API routes its configuration mounts, in the given groups (all when none), each wrapped in its gate, rate limit and language middleware.
func (*Service) Capabilities ¶
func (s *Service) Capabilities() Capabilities
func (*Service) Close ¶
func (s *Service) Close()
Close stops the background work New started: the memory limiter sweep. The engine and Redis client are borrowed and remain owned by the host. Idempotent; safe on a nil Service.
func (*Service) GroupHandler ¶
func (s *Service) GroupHandler(op GroupOp) http.HandlerFunc
GroupHandler returns the handler for one group route. It:
- derives the caller's actor (401 if none; 403 for a delegation);
- resolves :group_id (`root` is the root group) to a live group;
- refuses a group whose persona lacks the route, like an unknown group;
- authorizes the route's permission on the group with the engine's live Can, for every actor kind (403 on deny);
- for a change to the root group, requires a user who signed in recently (M7): step_up_required otherwise, 403 for any other actor;
- performs the operation, whose engine call applies its own rules.
func (*Service) JWKSHandler ¶
JWKSHandler returns a handler for GET /.well-known/jwks.json. The key set is read per request so a hot-reloaded rotation or key removal is published immediately (ak#392).
func (*Service) OIDCBrowserRoutes ¶
func (s *Service) OIDCBrowserRoutes(groups ...iam.RouteGroup) []RouteSpec
OIDCBrowserRoutes returns the browser OIDC routes, prefix-neutral.
type SessionEventQuery ¶ added in v0.149.0
SessionEventQuery pages a session history, newest first; kind repeats.
type SignInKey ¶ added in v0.149.0
type SignInKey struct {
ID string `json:"id"`
Kind SignInKeyKind `json:"kind"`
Label *string `json:"label"`
CreatedAt time.Time `json:"created_at"`
LastUsedAt *time.Time `json:"last_used_at"`
Current bool `json:"current"`
}
SignInKey is one of the caller's passkeys or device keys. Current marks the device key behind the request's token.
type SignInKeyKind ¶ added in v0.149.0
type SignInKeyKind string
SignInKeyKind names a sign-in key's protocol.
const ( SignInKeyPasskey SignInKeyKind = "passkey" SignInKeyDeviceKey SignInKeyKind = "device_key" )
type SolanaAccount ¶ added in v0.148.0
type SolanaCapabilities ¶ added in v0.148.0
type SolanaCapabilities struct {
Login bool `json:"login"`
}
type SolanaChallenge ¶ added in v0.148.0
type SolanaChallengeRequest ¶ added in v0.148.0
type SolanaSignInOutput ¶ added in v0.148.0
type SolanaSignInOutput struct {
Account SolanaAccount `json:"account"`
Signature string `json:"signature"`
SignedMessage string `json:"signedMessage"`
}
type SolanaSignInRequest ¶ added in v0.148.0
type SolanaSignInRequest struct {
Output SolanaSignInOutput `json:"output"`
}
SolanaSignInRequest is the wallet-standard sign-in output: the one camelCase body on the wire.
type Surface ¶ added in v0.148.0
type Surface string
Surface is where a route is anchored beneath the mount's base path.
type TokenRefreshRequest ¶ added in v0.148.0
type TokenRequest ¶ added in v0.148.0
type TokenRequest struct {
Token string `json:"token"`
}
type TwoFactorCapabilities ¶ added in v0.148.0
type TwoFactorCapabilities struct {
Mode iam.TwoFactorMode `json:"mode"`
Methods []iam.TwoFactorMethod `json:"methods"`
}
TwoFactorCapabilities is the 2FA policy and the second factors a user can enroll now (Client.TwoFactorMethods).
type TwoFactorChallengeRequest ¶ added in v0.148.0
type TwoFactorFactor ¶ added in v0.148.0
type TwoFactorFactor struct {
ID string `json:"id"`
Method string `json:"method"`
IsDefault bool `json:"is_default"`
Destination *string `json:"destination"`
}
TwoFactorFactor is one second factor. Destination is the masked address its codes go to; null for an authenticator app.
type TwoFactorFactorCreateRequest ¶ added in v0.149.0
type TwoFactorFactorCreateRequest struct {
Method string `json:"method"`
Code string `json:"code"`
PhoneNumber *string `json:"phone_number"`
Default bool `json:"default"`
}
TwoFactorFactorCreateRequest adds the factor whose setup code it carries.
type TwoFactorFactorCreated ¶ added in v0.149.0
type TwoFactorFactorCreated struct {
Factor TwoFactorFactor `json:"factor"`
BackupCodes []string `json:"backup_codes"`
Auth *AuthResult `json:"auth"`
}
TwoFactorFactorCreated is a factor added. BackupCodes are the first factor's, shown once ([] otherwise). Auth is the sign-in an enrollment token finished, or the session's fresh token when the code re-verified it; null otherwise.
type TwoFactorFactorUpdateRequest ¶ added in v0.149.0
type TwoFactorFactorUpdateRequest struct {
Default bool `json:"default"`
}
type TwoFactorRequired ¶ added in v0.149.0
type TwoFactorRequired struct {
Method string `json:"method"`
}
TwoFactorRequired is 2fa_required's metadata: the second factor a device-key ceremony must carry.
type TwoFactorSendRequest ¶ added in v0.149.0
type TwoFactorSendRequest struct {
Method string `json:"method"`
}
TwoFactorSendRequest names the second factor a step-up code goes to (the default when empty).
type TwoFactorSetup ¶ added in v0.149.0
type TwoFactorSetup struct {
Method string `json:"method"`
Destination *string `json:"destination"`
Secret *string `json:"secret"`
OTPAuthURI *string `json:"otpauth_uri"`
}
TwoFactorSetup is a factor's setup under way: where its code went, or the authenticator app's secret.
type TwoFactorSetupRequest ¶ added in v0.149.0
type TwoFactorSetupRequest struct {
Method string `json:"method"`
PhoneNumber *string `json:"phone_number"`
}
TwoFactorSetupRequest starts a factor's setup: a code to the email or phone, or an authenticator app's secret.
type TwoFactorStatus ¶ added in v0.148.0
type TwoFactorStatus struct {
Enabled bool `json:"enabled"`
Factors []TwoFactorFactor `json:"factors"`
AllowedMethods []iam.TwoFactorMethod `json:"allowed_methods"`
BackupCodesRemaining int `json:"backup_codes_remaining"`
}
TwoFactorStatus is the caller's second factors.
type TwoFactorStepUpRequest ¶ added in v0.148.0
type TwoFactorVerifyRequest ¶ added in v0.148.0
type UserListQuery ¶ added in v0.148.0
type UserProfile ¶ added in v0.148.0
type UserProfile = authflow.UserProfile
UserProfile is GET /me: the account and its sign-in and naming state.
type UserSecurity ¶ added in v0.149.0
type UserSecurity = authflow.UserSecurity
UserSecurity is GET /me/security: the session's freshness and the account's step-up and MFA state.
type UsernameCapabilities ¶ added in v0.148.0
type UsernameCapabilities struct {
MinLength int `json:"min_length"`
MaxLength int `json:"max_length"`
Pattern string `json:"pattern"`
Renames bool `json:"renames"`
RenameIntervalSeconds int64 `json:"rename_interval_seconds"`
FormerNames naming.PolicyInfo `json:"former_names"`
}
UsernameCapabilities is the interactive username rule. Pattern is the fixed character rule; length is bounded separately. Renames says whether users may rename themselves, and how often.
type UsersQuery ¶ added in v0.149.0
UsersQuery looks public users up by id (comma-separated, at most 100) or by username (former names resolve too).
type VerificationCapabilities ¶ added in v0.148.0
type VerificationCapabilities struct {
Registration string `json:"registration"`
}
type VerificationStep ¶ added in v0.149.0
type VerificationStep struct {
Identifier string `json:"identifier"`
Channel string `json:"channel"`
}
VerificationStep is a sign-in waiting on a contact proof; the code went to Identifier over Channel ("email" or "phone").
type WebAuthnCredential ¶ added in v0.148.0
type WebAuthnCredential = json.RawMessage
WebAuthnCredential is a browser's WebAuthn credential response, passed through as the browser produced it.
type WireField ¶ added in v0.148.0
type WireField struct {
Name string
Type reflect.Type
// Optional marks an omitempty member, absent when zero: only protocol
// documents (JWKS) have them.
Optional bool
// Tag is the field's full json tag.
Tag string
}
WireField is one JSON member of an object.
Source Files
¶
- account_recovery.go
- admin_routes.go
- admin_signins.go
- audit.go
- auth_token_post.go
- auth_tokens.go
- availability.go
- backend.go
- backend_apps.go
- backend_flows.go
- backend_groups.go
- backend_invites.go
- backend_sessions.go
- backend_users.go
- browser_error.go
- buckets.go
- catalog.go
- client_ip.go
- confirm_errors.go
- contact_channel.go
- cookies.go
- delegated_token.go
- device_keys.go
- error_metadata.go
- errors.go
- group_apikeys.go
- group_invites.go
- group_members.go
- group_routes.go
- internal_errors.go
- json_boundary.go
- jwks_get.go
- language.go
- login_continuation.go
- logout_delete.go
- me.go
- me_2fa.go
- me_contact.go
- me_password.go
- me_sessions.go
- mount.go
- oidc_browser.go
- oidc_util.go
- passkeys.go
- password_login_post.go
- passwordless.go
- permission_gate.go
- permission_group_routes.go
- providers.go
- providers_get.go
- public_users.go
- ratelimit.go
- refresh_cookie.go
- register.go
- register_availability.go
- respond.go
- routes.go
- server.go
- service.go
- sign_in_keys.go
- solana_siws.go
- step_up.go
- user_2fa_verify_post.go
- util.go
- wire.go
- wiremodel.go