auth

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: MIT Imports: 2 Imported by: 0

Documentation

Overview

Package auth defines the small values shared by request authentication providers and their consumers. It contains no verifier or authorization policy.

Index

Constants

This section is empty.

Variables

View Source
var (
	ErrUnauthenticated     = errors.New("authentication required")
	ErrForbidden           = errors.New("authentication policy refused")
	ErrUnavailable         = errors.New("authentication unavailable")
	ErrSenderProofRequired = errors.New("sender proof required")
	ErrExpired             = errors.New("credential expired")
	ErrRevoked             = errors.New("credential revoked")
)

Authentication failures are classified with errors.Is. Providers may wrap their own errors; consumers must not expose provider error text to clients.

Functions

This section is empty.

Types

type Identity

type Identity struct {
	Kind          Kind
	Issuer        string
	Subject       string
	Email         string
	Username      string
	SessionID     string
	EmailVerified bool
}

Identity identifies the authenticated actor within its issuer's namespace. Subject is stable: it is not a display name or an application-specific account mapping. Contact and session fields are optional metadata, not authority.

type Kind

type Kind string

Kind records verified credential provenance, never a role or permission.

const (
	KindUser              Kind = "user"
	KindAPIKey            Kind = "api_key"
	KindRemoteApplication Kind = "remote_application"
	KindDelegated         Kind = "delegated"
	KindDeviceKey         Kind = "device_key"
)

type PermissionChecker

type PermissionChecker interface {
	Can(context.Context, Scope, string) (bool, error)
}

PermissionChecker is an optional capability of an authenticated Principal. Can evaluates the exact scope and permission without verifying the request again. It must retain credential ceilings and scope bindings. Consumers must deny privileged access when this capability is absent; never infer a grant from identity metadata. An error never grants. One matching ErrExpired or ErrRevoked (with ErrUnauthenticated) is a credential failure: the credential ended after the request was verified, so answer 401. Any other error denotes an unavailable check: answer 503.

type Principal

type Principal interface {
	Identity() Identity
}

Principal is the result of verifying one HTTP request, including any required sender proof. Consumers retain it only for that request; they must not reuse it for another request or after changing the credential, method, or signed URL. Identity-only providers need not implement PermissionChecker.

type Scope

type Scope struct {
	Authority string
	ID        string
}

Scope names an authority-owned immutable resource. Names and request selectors do not grant authority; the host resolves this value before checking access.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL