authkit

package module
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: MIT Imports: 14 Imported by: 0

Documentation

Overview

Package authkit connects ContentKit to AuthKit accounts: account avatars on ContentKit's slots (Avatars) and content authors (Authors). It is a module of its own, so ContentKit's core never imports AuthKit.

An account's avatar is its user folder's avatar slot (media.UserKind, media.AvatarSlotName). Its stable link (media.Reader.SlotLink) never changes, so the account's AuthKit public metadata names it once, under Key ("avatar"): hosts and auth-ui read public_metadata.avatar. Hosts sharing one account store share the key, so the site where the user last set an avatar is the one shown everywhere.

Index

Constants

View Source
const DefaultKey = "avatar"

DefaultKey is the public-metadata key naming an account's avatar link.

Variables

This section is empty.

Functions

func AvatarLink(u iam.PublicUser, key string) string

AvatarLink is the avatar link an account's public metadata names under key: an absolute http(s) URL without a query or fragment, else "".

Types

type Authors

type Authors struct {
	Directory Directory
	// Key is the public-metadata key; default DefaultKey.
	Key string
	// Width is the avatar's display width in CSS pixels: Avatar is the link
	// at it; default 64.
	Width int
	// Slot gives AvatarSrcSet's widths; default media.AvatarSlot.
	Slot   *media.Slot
	Logger *slog.Logger
}

Authors is content's UserEnricher over AuthKit: each id's display name (tombstones and unknown ids get AuthKit's fallback) and the avatar its public metadata names. A directory failure is logged and degrades to fallback names without avatars; it never fails a listing.

func (*Authors) UsersByIDs

func (a *Authors) UsersByIDs(ctx context.Context, ids []string) (map[string]content.PublicUser, error)

type Avatars

type Avatars struct {
	Directory Directory
	Links     SlotLinker
	// Staff may change any account's avatar, checked live in the root group;
	// zero: nobody but the account's user.
	Staff iam.Perm
	// Key is the public-metadata key; default DefaultKey.
	Key string
	// Slot is the avatar slot; default media.AvatarSlotName.
	Slot string
}

Avatars are account avatars: CanUpload decides who may change one and SlotChanged names it in the account's public metadata.

func (*Avatars) CanUpload

func (a *Avatars) CanUpload(ctx context.Context, actor access.Actor, t media.UploadTarget) (media.UploadGrant, error)

CanUpload authorizes the avatar slot of user folders: a signed-in user their own (Owner them and not Exempt, so the host's upload limiter applies), staff holding Staff anyone's (Exempt). It refuses every other target: a host routes its other kinds before it. It reads the verified claims AuthKit's middleware put in ctx; only the staff check reads the database.

func (*Avatars) SlotChanged

func (a *Avatars) SlotChanged(ctx context.Context, _ pgx.Tx, ref contentref.ContentRef, slot string, set bool) error

SlotChanged is the avatar's media.Hooks.SlotChanged: when a user's avatar is set or replaced, their public metadata's Key becomes its stable link, one idempotent merge patch outside the slot index transaction (AuthKit may live in another database). A removal writes nothing, since the link then serves the host's default; an erased account is done. Other slots pass.

type Directory

type Directory interface {
	Can(ctx context.Context, actor iam.Actor, ref iam.GroupRef, perm iam.Perm) (bool, error)
	PatchPublicMetadata(ctx context.Context, actor iam.Actor, userID string, patch map[string]any, opts ...ak.Option) error
	PublicUsers(ctx context.Context, ids []string) (map[string]iam.PublicUser, error)
}

Directory is what this package uses of *authkit.Client.

type SlotLinker

type SlotLinker interface {
	SlotLink(ref contentref.ContentRef, slot string) string
}

SlotLinker builds a slot's stable URL: *media.Reader with ReadURL set.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL