Documentation
¶
Overview ¶
Package authkitfiber bridges AuthKit's net/http middleware to Fiber v3. Mount registers AuthKit's routes directly on the application. Verification policy stays in verify. Handlers read the verified caller from c.Context() (verify.ActorFromContext, verify.ClaimsFromContext) and write AuthKit errors with status, body := iam.ErrorResponse(err); c.Status(status).JSON(body).
Index ¶
- Constants
- func Mount(app *fiber.App, s Surface) error
- func Optional(a verify.Authenticator) fiber.Handler
- func RequirePermission(a verify.Authority, perm iam.Perm) fiber.Handler
- func RequirePermissionOn(a verify.Authority, ref iam.GroupRef, perm iam.Perm) fiber.Handler
- func RequireSession(a verify.Authority) fiber.Handler
- func Required(a verify.Authenticator) fiber.Handler
- func Sensitive(a verify.Authority) fiber.Handler
- func SetGroup(c fiber.Ctx, ref iam.GroupRef)
- func Use(mw ...func(http.Handler) http.Handler) fiber.Handler
- type Surface
Constants ¶
const RouteNamePrefix = "authkit."
RouteNamePrefix identifies routes registered by Mount in app.GetRoutes().
Variables ¶
This section is empty.
Functions ¶
func Mount ¶
Mount registers every AuthKit route natively on app, each visible through app.GetRoutes() and named "authkit.METHOD /path" (GET routes also as HEAD). Call it during setup, before serving requests. Every route is served by the surface's one handler, which keeps AuthKit's authentication, JSON guards and cookie protections. Unmatched requests continue through Fiber's routing. Existing routes with the same method and normalized path cause an error; normalization honors CaseSensitive and StrictRouting. Exclude a replaced AuthKit route with HTTPConfig.Exclude. Every mounted method must be enabled by the app's RequestMethods configuration.
func Optional ¶
func Optional(a verify.Authenticator) fiber.Handler
Optional is verify.Optional in a Fiber chain.
func RequirePermission ¶
RequirePermission is verify.RequirePermission in a Fiber chain, in the group SetGroup attached.
func RequirePermissionOn ¶ added in v0.147.0
RequirePermissionOn is verify.RequirePermissionOn in a Fiber chain.
func RequireSession ¶ added in v0.147.0
RequireSession is verify.RequireSession in a Fiber chain.
func Required ¶
func Required(a verify.Authenticator) fiber.Handler
Required is verify.Required in a Fiber chain: a is the *authkit.Client (or a *verify.Verifier).
func SetGroup ¶ added in v0.147.0
SetGroup attaches the permission group the request acts in, for RequirePermission: call it from the handler that resolves the route's entity.
func Use ¶
Use runs synchronous net/http authentication middleware around Fiber's downstream handlers. Context values and cancellation flow in both directions; Fiber errors are returned to its error handler. Middleware must not retain the converted request after returning. Streaming and hijacking are not supported. This bridge is for authentication and context middleware, not request rewriting or wrappers that intercept downstream response bodies.