token

package
v0.58.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 25, 2026 License: MIT Imports: 8 Imported by: 0

Documentation

Overview

Package token signs and verifies media access tokens, shared by the host signer and the access worker so the format cannot drift:

{kid}.{exp}.base64url(HMAC-SHA256(secret, "{scope}|{exp}"))

A scope is either a folder prefix ending in "/", which covers the objects directly under it, or one object key. A download scope binds a Content-Disposition name: "{key}#dl={name}". An editor scope, "{folder}#editor", covers the objects directly under a temp/ folder and is accepted only by VerifyEditor; Verify never accepts it, nor VerifyEditor any other scope. Tokens are bearer tokens, revoked only by expiry.

Index

Constants

View Source
const CookieName = "mt"

CookieName carries a folder token in cookie delivery mode.

View Source
const DefaultWindow = 4 * time.Hour

DefaultWindow aligns expiries so tokens and URLs repeat within a window.

Variables

View Source
var (
	ErrMalformed  = errors.New("token: malformed")
	ErrExpired    = errors.New("token: expired")
	ErrUnknownKey = errors.New("token: unknown key")
	ErrInvalid    = errors.New("token: signature does not cover this path")
)

Functions

func Attachment

func Attachment(name string) string

Attachment is the Content-Disposition for a signed download name: an ASCII fallback plus the RFC 5987 UTF-8 name.

func DownloadScope

func DownloadScope(key, name string) string

DownloadScope scopes a token to one key served under a download name.

func EditorScope added in v0.52.0

func EditorScope(folder string) string

EditorScope scopes a token to the editor views directly under folder.

func Expiry

func Expiry(now time.Time, ttl, window time.Duration) time.Time

Expiry is ceil((now + ttl) / window) * window.

func FileScope

func FileScope(key string) string

FileScope scopes a token to one object key.

Types

type Key

type Key struct {
	ID     string
	Secret []byte
}

Key is one signing key.

func ParseKey

func ParseKey(s string) (Key, error)

ParseKey parses "{kid}:{base64 secret}" (standard or URL alphabet, padding optional), the form hosts and the access worker read from their secret store.

type Ring

type Ring struct {
	// contains filtered or unexported fields
}

Ring signs with the current key and verifies with the current or previous one.

func NewRing

func NewRing(current Key, previous *Key) (Ring, error)

NewRing validates keys: ids are non-empty without '.', secrets at least 32 bytes.

func ParseRing

func ParseRing(current, previous string) (Ring, error)

ParseRing builds a ring from ParseKey strings; previous may be empty.

func (Ring) Sign

func (r Ring) Sign(scope string, exp time.Time) string

Sign signs scope until exp with the current key.

func (Ring) Verify

func (r Ring) Verify(tok, key, dl string, now time.Time) error

Verify checks tok for object key at now. A non-empty dl requires a download scope for exactly that name; otherwise the token must cover the key itself or the folder directly containing it.

func (Ring) VerifyEditor added in v0.52.0

func (r Ring) VerifyEditor(tok, key string, now time.Time) error

VerifyEditor checks tok for object key at now under an editor scope for the folder directly containing key, and nothing else.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL