Documentation
¶
Overview ¶
Package token signs and verifies media access tokens, shared by the host signer and the access worker so the format cannot drift:
{kid}.{exp}.base64url(HMAC-SHA256(secret, "{scope}|{exp}"))
A scope is either a folder prefix ending in "/", which covers the objects directly under it, or one object key. A download scope binds a Content-Disposition name: "{key}#dl={name}". An editor scope, "{folder}#editor", covers the objects directly under a temp/ folder and is accepted only by VerifyEditor; Verify never accepts it, nor VerifyEditor any other scope. Tokens are bearer tokens, revoked only by expiry.
Index ¶
Constants ¶
const CookieName = "mt"
CookieName carries a folder token in cookie delivery mode.
const DefaultWindow = 4 * time.Hour
DefaultWindow aligns expiries so tokens and URLs repeat within a window.
Variables ¶
Functions ¶
func Attachment ¶
Attachment is the Content-Disposition for a signed download name: an ASCII fallback plus the RFC 5987 UTF-8 name.
func DownloadScope ¶
DownloadScope scopes a token to one key served under a download name.
func EditorScope ¶ added in v0.52.0
EditorScope scopes a token to the editor views directly under folder.
Types ¶
type Ring ¶
type Ring struct {
// contains filtered or unexported fields
}
Ring signs with the current key and verifies with the current or previous one.