Documentation
¶
Overview ¶
Package auth defines the small values shared by request authentication providers and their consumers. It contains no verifier or authorization policy.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ( ErrUnauthenticated = errors.New("authentication required") ErrForbidden = errors.New("authentication policy refused") ErrSenderProofRequired = errors.New("sender proof required") ErrExpired = errors.New("credential expired") ErrRevoked = errors.New("credential revoked") )
Authentication failures are classified with errors.Is. Providers may wrap their own errors; consumers must not expose provider error text to clients.
Functions ¶
This section is empty.
Types ¶
type Identity ¶
type Identity struct {
Kind Kind
Issuer string
Subject string
Email string
Username string
SessionID string
EmailVerified bool
}
Identity identifies the authenticated actor within its issuer's namespace. Subject is stable: it is not a display name or an application-specific account mapping. Contact and session fields are optional metadata, not authority.
type Kind ¶
type Kind string
Kind records verified credential provenance, never a role or permission.
type PermissionChecker ¶
PermissionChecker is an optional capability of an authenticated Principal. Can evaluates the exact scope and permission without verifying the request again. It must retain credential ceilings and scope bindings. Consumers must deny privileged access when this capability is absent; never infer a grant from identity metadata. An error never grants. One matching ErrExpired or ErrRevoked (with ErrUnauthenticated) is a credential failure: the credential ended after the request was verified, so answer 401. Any other error denotes an unavailable check: answer 503.
type Principal ¶
type Principal interface {
Identity() Identity
}
Principal is the result of verifying one HTTP request, including any required sender proof. Consumers retain it only for that request; they must not reuse it for another request or after changing the credential, method, or signed URL. Identity-only providers need not implement PermissionChecker.