token

package
v0.62.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 2, 2026 License: MIT Imports: 9 Imported by: 0

Documentation

Overview

Package token signs and verifies media access tokens, shared by the host signer and the access agent so the format cannot drift:

{kid}.{exp}.base64url(HMAC-SHA256(secret, "{scope}|{exp}"))

The one access scope is an item's, "{ns}/{kind}/{id}": every private file of the item or none. Tokens are bearer tokens, revoked only by expiry.

Index

Constants

View Source
const CookieName = "mt"

CookieName carries an item token in cookie delivery mode.

View Source
const DefaultWindow = 4 * time.Hour

DefaultWindow aligns expiries so tokens and URLs repeat within a window.

Variables

View Source
var (
	ErrMalformed  = errors.New("token: malformed")
	ErrExpired    = errors.New("token: expired")
	ErrUnknownKey = errors.New("token: unknown key")
	ErrInvalid    = errors.New("token: signature does not cover this path")
)

Functions

func Expiry

func Expiry(now time.Time, ttl, window time.Duration) time.Time

Expiry rounds now+ttl up to a window. Token timestamps store whole Unix seconds, so fractional-second windows round up to whole seconds.

func ItemScope added in v0.62.0

func ItemScope(ns, kind, id string) string

ItemScope covers every private file of one item: "{ns}/{kind}/{id}".

Types

type Key

type Key struct {
	ID     string
	Secret []byte
}

Key is one signing key.

func ParseKey

func ParseKey(s string) (Key, error)

ParseKey parses "{kid}:{base64 secret}" (standard or URL alphabet, padding optional), the form hosts and the access worker read from their secret store.

type Ring

type Ring struct {
	// contains filtered or unexported fields
}

Ring signs with the current key and verifies with the current or previous one.

func NewRing

func NewRing(current Key, previous *Key) (Ring, error)

NewRing validates keys: ids are non-empty without '.', secrets at least 32 bytes.

func ParseRing

func ParseRing(current, previous string) (Ring, error)

ParseRing builds a ring from ParseKey strings; previous may be empty.

func (Ring) Sign

func (r Ring) Sign(scope string, exp time.Time) string

Sign signs scope until exp with the current key.

func (Ring) VerifyPrivate added in v0.62.0

func (r Ring) VerifyPrivate(tok, key string, now time.Time) error

VerifyPrivate checks tok for the private object key "{ns}/{kind}/{id}/private/{name}" at now: its item's token.

func (Ring) VerifyScope added in v0.62.0

func (r Ring) VerifyScope(tok, scope string, now time.Time) error

VerifyScope checks tok for exactly scope at now.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL