extauthz

package
v0.13.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 17, 2026 License: Apache-2.0 Imports: 46 Imported by: 0

Documentation

Index

Constants

View Source
const (
	HeaderForwardedClientCert = "x-forwarded-client-cert"
	HeaderAuthorization       = "authorization"
	HeaderCookie              = "cookie"
	HeaderCSRFToken           = "x-csrf-token"
	SessionCookiePrefix       = "__Host-Http-SESSION-"
	LogPrefixCheck            = "Check(): "
	LogPrefixClientCert       = "Client Certs: "
	LogPrefixBearerToken      = "Bearer Token: "
	LogPrefixSessionCookie    = "Session cookie: "
)
View Source
const (
	HeaderTraceparent = "traceparent"
	HeaderTracestate  = "tracestate"
	HeaderBaggage     = "baggage"
)

Span and attribute names for the per-Check application span.

View Source
const (
	UNKNOWN checkResultCode = iota
	ALLOWED
	TENANT_BLOCKED
	DENIED
	UNAUTHENTICATED
)
View Source
const (
	DefaultCMKPathPrefix = "/cmk/v1/"
)

Variables

View Source
var (
	ReExSubject        = regexp.MustCompile(`Subject="([^"]+)"`)
	ErrSubjectNotFound = errors.New("subject not found")
)

Functions

This section is empty.

Types

type Server

type Server struct {
	// contains filtered or unexported fields
}

func NewServer

func NewServer(opts ...ServerOption) (*Server, error)

NewServer creates a new server and applies the given options.

func (*Server) Check

Check authorizes the request based on either client certificate, bearer token or session cookie.

func (*Server) Close added in v0.5.0

func (s *Server) Close() error

Close starts any internal processes required by the server.

func (*Server) Start added in v0.5.0

func (s *Server) Start() error

Start starts any internal processes required by the server.

type ServerOption

type ServerOption func(*Server) error

ServerOption is used to configure a server.

func WithAuditLogger added in v0.13.0

func WithAuditLogger(logger audit.Logger) ServerOption

func WithAuditQueue added in v0.13.0

func WithAuditQueue(q *auditqueue.Queue) ServerOption

WithAuditQueue sets the asynchronous dispatcher used to deliver audit events off the Check() hot path.

func WithCSRFSecret added in v0.10.0

func WithCSRFSecret(secret []byte) ServerOption

func WithClientDataSigner added in v0.5.0

func WithClientDataSigner(cdp *clientdata.Signer) ServerOption

func WithCountUnknown added in v0.13.0

func WithCountUnknown(count bool) ServerOption

WithCountUnknown controls whether UNKNOWN results (no credentials presented) are included in the unauthenticated burst count.

func WithFeatureGates added in v0.3.0

func WithFeatureGates(fg *commoncfg.FeatureGates) ServerOption

func WithMetrics added in v0.13.0

func WithMetrics(m *metric.Metrics) ServerOption

WithMetrics sets the audit-pipeline metrics.

func WithOIDCHandler added in v0.5.0

func WithOIDCHandler(hdl oidcHandlerInterface) ServerOption

func WithPolicyEngine

func WithPolicyEngine(pe policies.Engine) ServerOption

func WithRateStore added in v0.13.0

func WithRateStore(rs ratestore.RateStore) ServerOption

WithRateStore sets the cross-pod store used to detect unauthenticated request bursts. When unset the server uses a no-op store and never emits burst events.

func WithSessionManager added in v0.9.8

func WithSessionManager(sessionManager sessionManagerInterface) ServerOption

func WithSessionPathPrefixes added in v0.9.8

func WithSessionPathPrefixes(sessionPathPrefixes []string) ServerOption

func WithTracer added in v0.12.0

func WithTracer(t trace.Tracer) ServerOption

WithTracer overrides the default OpenTelemetry tracer used to emit the per-Check application span. The default tracer is obtained from the global TracerProvider at NewServer time (see NewServer). Tests use this option to inject an SDK tracer backed by an in-memory exporter.

func WithTrustedSubjects

func WithTrustedSubjects(m map[string]string) ServerOption

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL