Documentation
¶
Overview ¶
Package jose is AuthKit's JWT mechanics: signing with a keys.Signer, signature verification, the token types, claim readers, sender-binding (cnf) claims and JWKS serving. golang-jwt stays behind it, out of the public API. It holds no policy: which issuers, audiences and token profiles are trusted is verify's and the engine's.
Index ¶
- Constants
- Variables
- func Audiences(claims map[string]any) []string
- func CertificateThumbprint(der []byte) string
- func Confirmation(token string) (member, thumbprint string, err error)
- func JWKS(src keys.Source) keys.JWKS
- func Object(claims map[string]any, key string) map[string]json.RawMessage
- func RawClaim(token, key string) (raw json.RawMessage, present bool, err error)
- func RequestToken(r *http.Request) (token string, dpop bool)
- func ServeJWKS(w http.ResponseWriter, r *http.Request, ks keys.JWKS)
- func Sign(ctx context.Context, signer keys.Signer, typ string, claims map[string]any) (string, error)
- func String(claims map[string]any, key string) string
- func Strings(claims map[string]any, key string) []string
- func Time(claims map[string]any, key string) (time.Time, bool)
- func Unverified(token string) (typ string, claims map[string]any, ok bool)
- func ValidThumbprint(s string) bool
- func Verify(token string, keyFor KeyFunc) (typ string, claims map[string]any, err error)
- type KeyFunc
Constants ¶
const ( ConfirmationClaim = "cnf" CertificateThumbprintMember = "x5t#S256" JWKThumbprintMember = "jkt" )
Sender binding (cnf) of a delegated token: RFC 8705 binds it to an X.509 certificate (x5t#S256), RFC 9449 to a DPoP key (jkt). Both thumbprints are the unpadded base64url SHA-256 the claim itself carries.
const ( AccessTokenType = "access+jwt" DelegatedAccessTokenType = "delegated-access+jwt" // RemoteApplicationAccessTokenType is a remote application acting as // itself: no sub, no delegated_sub; its identity is the validated iss. RemoteApplicationAccessTokenType = "remote-application-access+jwt" ServiceJWTType = "service+jwt" )
JOSE typ header values: each AuthKit token class has its own.
Variables ¶
var Algorithms = []string{"RS256", "ES256", "ES384", "ES512", "EdDSA"}
Algorithms are the JWS algorithms AuthKit verifies: asymmetric only, so "none" and HS* never pass.
var ErrInvalidConfirmation = errors.New("invalid cnf claim")
ErrInvalidConfirmation is a cnf claim that is not exactly one recognized member holding a thumbprint.
var ErrSignature = errors.New("jose: invalid signature")
ErrSignature is a signature that does not verify under the key it names.
Functions ¶
func CertificateThumbprint ¶
CertificateThumbprint is RFC 8705's x5t#S256 of certificate DER.
func Confirmation ¶
Confirmation parses token's cnf claim strictly: absent, or exactly {"x5t#S256": t} or {"jkt": t}. member is "" when there is none.
func JWKS ¶
JWKS publishes a key source's public keys, sorted by kid; the active key carries its signer's alg.
func Object ¶
Object is the object-valued claim key with each member kept as raw JSON, nil when absent, empty or not an object.
func RawClaim ¶
func RawClaim(token, key string) (raw json.RawMessage, present bool, err error)
RawClaim reads one top-level claim off the payload strictly: a duplicate key, which a decoded map would silently collapse, is an error.
func RequestToken ¶
RequestToken is the request's one Authorization credential and whether it uses the DPoP scheme; "" unless the header is exactly "Bearer <token>" or "DPoP <token>".
func ServeJWKS ¶
ServeJWKS writes ks with the caching contract a CDN-fronted JWKS needs: ETag and Cache-Control on every answer, the 304 included (RFC 7232 requires the validator there); If-None-Match matched per RFC 7232 §3.2 ("*", lists, weak "W/"); and nosniff.
func Sign ¶
func Sign(ctx context.Context, signer keys.Signer, typ string, claims map[string]any) (string, error)
Sign signs claims as a compact JWS with signer; typ, when set, becomes the header's typ.
func Strings ¶
Strings is the string-array claim key; non-string elements are skipped. It is nil when the claim is absent and non-nil when present, even if empty.
func Unverified ¶
Unverified decodes token's header typ and claims WITHOUT checking the signature: only to route a token to the key that will verify it, or to read the typ of a token whose signature was already verified.
func ValidThumbprint ¶
ValidThumbprint reports whether s is an unpadded base64url SHA-256.
func Verify ¶
Verify checks token's signature with the key keyFor returns, for an alg in Algorithms. It returns the header typ and the claims; on error the claims are set when the token parsed, only for choosing an error to report. A signature failure is ErrSignature; keyFor's error is returned wrapped.