jose

package
v1.0.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: MIT Imports: 15 Imported by: 0

Documentation

Overview

Package jose is AuthKit's JWT mechanics: signing with a keys.Signer, signature verification, the token types, claim readers, sender-binding (cnf) claims and JWKS serving. golang-jwt stays behind it, out of the public API. It holds no policy: which issuers, audiences and token profiles are trusted is verify's and the engine's.

Index

Constants

View Source
const (
	ConfirmationClaim           = "cnf"
	CertificateThumbprintMember = "x5t#S256"
	JWKThumbprintMember         = "jkt"
)

Sender binding (cnf) of a delegated token: RFC 8705 binds it to an X.509 certificate (x5t#S256), RFC 9449 to a DPoP key (jkt). Both thumbprints are the unpadded base64url SHA-256 the claim itself carries.

View Source
const (
	AccessTokenType          = "access+jwt"
	DelegatedAccessTokenType = "delegated-access+jwt"
	// RemoteApplicationAccessTokenType is a remote application acting as
	// itself: no sub, no delegated_sub; its identity is the validated iss.
	RemoteApplicationAccessTokenType = "remote-application-access+jwt"
	ServiceJWTType                   = "service+jwt"
)

JOSE typ header values: each AuthKit token class has its own.

Variables

View Source
var Algorithms = []string{"RS256", "ES256", "ES384", "ES512", "EdDSA"}

Algorithms are the JWS algorithms AuthKit verifies: asymmetric only, so "none" and HS* never pass.

View Source
var ErrInvalidConfirmation = errors.New("invalid cnf claim")

ErrInvalidConfirmation is a cnf claim that is not exactly one recognized member holding a thumbprint.

View Source
var ErrSignature = errors.New("jose: invalid signature")

ErrSignature is a signature that does not verify under the key it names.

Functions

func Audiences

func Audiences(claims map[string]any) []string

Audiences is the aud claim as a list, blanks dropped.

func CertificateThumbprint

func CertificateThumbprint(der []byte) string

CertificateThumbprint is RFC 8705's x5t#S256 of certificate DER.

func Confirmation

func Confirmation(token string) (member, thumbprint string, err error)

Confirmation parses token's cnf claim strictly: absent, or exactly {"x5t#S256": t} or {"jkt": t}. member is "" when there is none.

func JWKS

func JWKS(src keys.Source) keys.JWKS

JWKS publishes a key source's public keys, sorted by kid; the active key carries its signer's alg.

func Object

func Object(claims map[string]any, key string) map[string]json.RawMessage

Object is the object-valued claim key with each member kept as raw JSON, nil when absent, empty or not an object.

func RawClaim

func RawClaim(token, key string) (raw json.RawMessage, present bool, err error)

RawClaim reads one top-level claim off the payload strictly: a duplicate key, which a decoded map would silently collapse, is an error.

func RequestToken

func RequestToken(r *http.Request) (token string, dpop bool)

RequestToken is the request's one Authorization credential and whether it uses the DPoP scheme; "" unless the header is exactly "Bearer <token>" or "DPoP <token>".

func ServeJWKS

func ServeJWKS(w http.ResponseWriter, r *http.Request, ks keys.JWKS)

ServeJWKS writes ks with the caching contract a CDN-fronted JWKS needs: ETag and Cache-Control on every answer, the 304 included (RFC 7232 requires the validator there); If-None-Match matched per RFC 7232 §3.2 ("*", lists, weak "W/"); and nosniff.

func Sign

func Sign(ctx context.Context, signer keys.Signer, typ string, claims map[string]any) (string, error)

Sign signs claims as a compact JWS with signer; typ, when set, becomes the header's typ.

func String

func String(claims map[string]any, key string) string

String is the string claim key, or "".

func Strings

func Strings(claims map[string]any, key string) []string

Strings is the string-array claim key; non-string elements are skipped. It is nil when the claim is absent and non-nil when present, even if empty.

func Time

func Time(claims map[string]any, key string) (time.Time, bool)

Time is the NumericDate claim key.

func Unverified

func Unverified(token string) (typ string, claims map[string]any, ok bool)

Unverified decodes token's header typ and claims WITHOUT checking the signature: only to route a token to the key that will verify it, or to read the typ of a token whose signature was already verified.

func ValidThumbprint

func ValidThumbprint(s string) bool

ValidThumbprint reports whether s is an unpadded base64url SHA-256.

func Verify

func Verify(token string, keyFor KeyFunc) (typ string, claims map[string]any, err error)

Verify checks token's signature with the key keyFor returns, for an alg in Algorithms. It returns the header typ and the claims; on error the claims are set when the token parsed, only for choosing an error to report. A signature failure is ErrSignature; keyFor's error is returned wrapped.

Types

type KeyFunc

type KeyFunc func(alg, kid string, claims map[string]any) (crypto.PublicKey, error)

KeyFunc returns the key a token's signature must verify under, from its header alg and kid and its unverified claims.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL