Documentation
¶
Overview ¶
Package dpop verifies the ES256/P-256 profile of RFC 9449 sender proofs. Proofs establish possession of a key, never user identity or authorization.
Index ¶
Constants ¶
const NonceLifetime = 5 * time.Minute
NonceLifetime is how long a server nonce stays current.
Variables ¶
var ( ErrInvalidProof = errors.New("invalid DPoP proof") ErrReplay = errors.New("DPoP proof already used") // ErrNonceRequired refuses an otherwise valid proof without a current // server nonce (RFC 9449 §8); the client retries with a fresh one. ErrNonceRequired = errors.New("DPoP nonce required") )
Functions ¶
Types ¶
type Check ¶ added in v1.5.0
type Check struct {
// URL is the trusted request URL: from server configuration or trusted
// routing, never unvalidated forwarding headers.
URL string
// AccessToken is the token the proof must hash (ath); "" at a token
// endpoint, where a proof carries none.
AccessToken string
// Thumbprint is the bound token's cnf.jkt; "" binds a new token to the
// proof's key.
Thumbprint string
Replay ReplayGuard
// Nonces, when set, requires a current server nonce.
Nonces *Nonces
}
Check is what a proof must match.
type Nonces ¶ added in v1.5.0
type Nonces struct {
// contains filtered or unexported fields
}
Nonces issues and checks RFC 9449 §8 server nonces without state: a nonce is its issue time and an HMAC of it under a key every replica shares. Replay is still the replay guard's job; a nonce bounds how far ahead a proof can be made.
type ReplayGuard ¶
ReplayGuard atomically claims key until ttl elapses. It returns true only for the first claim. All receiver replicas must share the same store. Errors must fail closed; implementations must not evict live claims to admit others. Keys are fixed-size SHA-256 digests; ttl is at most 121 seconds.