Documentation
¶
Overview ¶
Package jose is AuthKit's JWT mechanics: signing with a keys.Signer, signature verification, the token types, claim readers, sender-binding (cnf) claims and JWKS serving. golang-jwt stays behind it, out of the public API. It holds no policy: which issuers, audiences and token profiles are trusted is verify's and the engine's.
Index ¶
- Constants
- Variables
- func Audiences(claims map[string]any) []string
- func CertificateThumbprint(der []byte) string
- func Confirmation(token string) (member, thumbprint string, err error)
- func JWKS(src keys.Source) keys.JWKS
- func Object(claims map[string]any, key string) map[string]json.RawMessage
- func RawClaim(token, key string) (raw json.RawMessage, present bool, err error)
- func RequestToken(r *http.Request) (token string, dpop bool)
- func ServeJWKS(w http.ResponseWriter, r *http.Request, ks keys.JWKS)
- func Sign(ctx context.Context, signer keys.Signer, typ string, claims map[string]any) (string, error)
- func StaticKey(k iam.RemoteApplicationKey) (string, crypto.PublicKey, error)
- func String(claims map[string]any, key string) string
- func Strings(claims map[string]any, key string) []string
- func Time(claims map[string]any, key string) (time.Time, bool)
- func Unverified(token string) (typ string, claims map[string]any, ok bool)
- func ValidThumbprint(s string) bool
- func Verify(token string, keyFor KeyFunc) (typ string, claims map[string]any, err error)
- type KeyFunc
Constants ¶
const ( ConfirmationClaim = "cnf" CertificateThumbprintMember = "x5t#S256" JWKThumbprintMember = "jkt" )
Sender binding (cnf) of a delegated token: RFC 8705 binds it to an X.509 certificate (x5t#S256), RFC 9449 to a DPoP key (jkt). Both thumbprints are the unpadded base64url SHA-256 the claim itself carries.
const ( AccessTokenType = "access+jwt" DelegatedAccessTokenType = "delegated-access+jwt" // RemoteApplicationAccessTokenType is a remote application acting as // itself: no sub, no delegated_sub; its identity is the validated iss. RemoteApplicationAccessTokenType = "remote-application-access+jwt" ServiceJWTType = "service+jwt" )
JOSE typ header values: each AuthKit token class has its own.
Variables ¶
var Algorithms = []string{"RS256", "ES256", "ES384", "ES512", "EdDSA"}
Algorithms are the JWS algorithms AuthKit verifies: asymmetric only, so "none" and HS* never pass.
var ErrInvalidConfirmation = errors.New("invalid cnf claim")
ErrInvalidConfirmation is a cnf claim that is not exactly one recognized member holding a thumbprint.
var ErrSignature = errors.New("jose: invalid signature")
ErrSignature is a signature that does not verify under the key it names.
Functions ¶
func CertificateThumbprint ¶
CertificateThumbprint is RFC 8705's x5t#S256 of certificate DER.
func Confirmation ¶
Confirmation parses token's cnf claim strictly: absent, or exactly {"x5t#S256": t} or {"jkt": t}. member is "" when there is none.
func JWKS ¶
JWKS publishes a key source's public keys, sorted by kid; the active key carries its signer's alg.
func Object ¶
Object is the object-valued claim key with each member kept as raw JSON, nil when absent, empty or not an object.
func RawClaim ¶
func RawClaim(token, key string) (raw json.RawMessage, present bool, err error)
RawClaim reads one top-level claim off the payload strictly: a duplicate key, which a decoded map would silently collapse, is an error.
func RequestToken ¶
RequestToken is the request's one Authorization credential and whether it uses the DPoP scheme; "" unless the header is exactly "Bearer <token>" or "DPoP <token>".
func ServeJWKS ¶
ServeJWKS writes ks with the caching contract a CDN-fronted JWKS needs: ETag and Cache-Control on every answer, the 304 included (RFC 7232 requires the validator there); If-None-Match matched per RFC 7232 §3.2 ("*", lists, weak "W/"); and nosniff.
func Sign ¶
func Sign(ctx context.Context, signer keys.Signer, typ string, claims map[string]any) (string, error)
Sign signs claims as a compact JWS with signer; typ, when set, becomes the header's typ.
func StaticKey ¶ added in v1.1.0
StaticKey is k's kid and public key, from exactly one of its PEM and JWK, under AuthKit's key policy. An empty KID takes the JWK's kid.
func Strings ¶
Strings is the string-array claim key; non-string elements are skipped. It is nil when the claim is absent and non-nil when present, even if empty.
func Unverified ¶
Unverified decodes token's header typ and claims WITHOUT checking the signature: only to route a token to the key that will verify it, or to read the typ of a token whose signature was already verified.
func ValidThumbprint ¶
ValidThumbprint reports whether s is an unpadded base64url SHA-256.
func Verify ¶
Verify checks token's signature with the key keyFor returns, for an alg in Algorithms. It returns the header typ and the claims; on error the claims are set when the token parsed, only for choosing an error to report. A signature failure is ErrSignature; keyFor's error is returned wrapped.