Documentation
¶
Overview ¶
Package token signs and verifies media access tokens, shared by the host signer and the access agent so the format cannot drift:
{kid}.{exp}.base64url(HMAC-SHA256(secret, "{scope}|{exp}"))
The one access scope is an item's, "{ns}/{kind}/{id}": every private file of the item or none. Tokens are bearer tokens, revoked only by expiry.
Index ¶
Constants ¶
View Source
const CookieName = "mt"
CookieName carries an item token in cookie delivery mode.
View Source
const DefaultWindow = 4 * time.Hour
DefaultWindow aligns expiries so tokens and URLs repeat within a window.
Variables ¶
Functions ¶
Types ¶
type Ring ¶
type Ring struct {
// contains filtered or unexported fields
}
Ring signs with the current key and verifies with the current or previous one.
func (Ring) VerifyPrivate ¶ added in v0.62.0
VerifyPrivate checks tok for the private object key "{ns}/{kind}/{id}/private/{name}" at now: its item's token.
Click to show internal directories.
Click to hide internal directories.