dpop

package
v1.7.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: MIT Imports: 18 Imported by: 0

Documentation

Overview

Package dpop verifies the ES256/P-256 profile of RFC 9449 sender proofs. Proofs establish possession of a key, never user identity or authorization.

Index

Constants

View Source
const NonceLifetime = 5 * time.Minute

NonceLifetime is how long a server nonce stays current.

Variables

View Source
var (
	ErrInvalidProof      = errors.New("invalid DPoP proof")
	ErrReplay            = errors.New("DPoP proof already used")
	ErrReplayUnavailable = errors.New("DPoP replay protection unavailable")
	// ErrNonceRequired refuses an otherwise valid proof without a current
	// server nonce (RFC 9449 §8); the client retries with a fresh one.
	ErrNonceRequired = errors.New("DPoP nonce required")
)

Functions

func Verify added in v1.5.0

func Verify(r *http.Request, c Check) (string, error)

Verify verifies exactly one DPoP header against c and the request method, and returns the proof key's RFC 7638 thumbprint (unpadded base64url). Call only after authenticating the access token.

Types

type Check added in v1.5.0

type Check struct {
	// URL is the trusted request URL: from server configuration or trusted
	// routing, never unvalidated forwarding headers.
	URL string
	// AccessToken is the token the proof must hash (ath); "" at a token
	// endpoint, where a proof carries none.
	AccessToken string
	// Thumbprint is the bound token's cnf.jkt; "" binds a new token to the
	// proof's key.
	Thumbprint string
	Replay     ReplayGuard
	// Nonces, when set, requires a current server nonce.
	Nonces *Nonces
}

Check is what a proof must match.

type Nonces added in v1.5.0

type Nonces struct {
	// contains filtered or unexported fields
}

Nonces issues and checks RFC 9449 §8 server nonces without state: a nonce is its issue time and an HMAC of it under a key every replica shares. Replay is still the replay guard's job; a nonce bounds how far ahead a proof can be made.

func NewNonces added in v1.5.0

func NewNonces(key []byte) (*Nonces, error)

NewNonces keys nonces with key, at least 32 random bytes.

func (*Nonces) Issue added in v1.5.0

func (n *Nonces) Issue(now time.Time) string

Issue is a nonce current from now.

func (*Nonces) Valid added in v1.5.0

func (n *Nonces) Valid(nonce string, now time.Time) bool

Valid reports whether nonce was issued under this key within NonceLifetime of now.

type ReplayGuard

type ReplayGuard func(ctx context.Context, key string, ttl time.Duration) (bool, error)

ReplayGuard atomically claims key until ttl elapses. It returns true only for the first claim. All receiver replicas must share the same store. Errors must fail closed; implementations must not evict live claims to admit others. Keys are fixed-size SHA-256 digests; ttl is at most 121 seconds.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL