Documentation
¶
Index ¶
- Constants
- Variables
- type Server
- type ServerOption
- func WithAuditLogger(logger audit.Logger) ServerOption
- func WithAuditQueue(q *auditqueue.Queue) ServerOption
- func WithCSRFSecret(secret []byte) ServerOption
- func WithClientDataSigner(cdp *clientdata.Signer) ServerOption
- func WithCountUnknown(count bool) ServerOption
- func WithFeatureGates(fg *commoncfg.FeatureGates) ServerOption
- func WithMetrics(m *metric.Metrics) ServerOption
- func WithOIDCHandler(hdl oidcHandlerInterface) ServerOption
- func WithPolicyEngine(pe policies.Engine) ServerOption
- func WithRateStore(rs ratestore.RateStore) ServerOption
- func WithSessionManager(sessionManager sessionManagerInterface) ServerOption
- func WithSessionPathPrefixes(sessionPathPrefixes []string) ServerOption
- func WithTracer(t trace.Tracer) ServerOption
- func WithTrustedSubjects(m map[string]string) ServerOption
Constants ¶
const ( HeaderForwardedClientCert = "x-forwarded-client-cert" HeaderAuthorization = "authorization" HeaderCookie = "cookie" HeaderCSRFToken = "x-csrf-token" SessionCookiePrefix = "__Host-Http-SESSION-" LogPrefixCheck = "Check(): " LogPrefixClientCert = "Client Certs: " LogPrefixBearerToken = "Bearer Token: " LogPrefixSessionCookie = "Session cookie: " )
const ( HeaderTraceparent = "traceparent" HeaderTracestate = "tracestate" HeaderBaggage = "baggage" )
Span and attribute names for the per-Check application span.
const ( UNKNOWN checkResultCode = iota ALLOWED TENANT_BLOCKED DENIED UNAUTHENTICATED )
const (
DefaultCMKPathPrefix = "/cmk/v1/"
)
Variables ¶
var ( ReExSubject = regexp.MustCompile(`Subject="([^"]+)"`) ErrSubjectNotFound = errors.New("subject not found") )
Functions ¶
This section is empty.
Types ¶
type Server ¶
type Server struct {
// contains filtered or unexported fields
}
func NewServer ¶
func NewServer(opts ...ServerOption) (*Server, error)
NewServer creates a new server and applies the given options.
func (*Server) Check ¶
func (srv *Server) Check(ctx context.Context, req *envoyauth.CheckRequest) (*envoyauth.CheckResponse, error)
Check authorizes the request based on either client certificate, bearer token or session cookie.
type ServerOption ¶
ServerOption is used to configure a server.
func WithAuditLogger ¶ added in v0.13.0
func WithAuditLogger(logger audit.Logger) ServerOption
func WithAuditQueue ¶ added in v0.13.0
func WithAuditQueue(q *auditqueue.Queue) ServerOption
WithAuditQueue sets the asynchronous dispatcher used to deliver audit events off the Check() hot path.
func WithCSRFSecret ¶ added in v0.10.0
func WithCSRFSecret(secret []byte) ServerOption
func WithClientDataSigner ¶ added in v0.5.0
func WithClientDataSigner(cdp *clientdata.Signer) ServerOption
func WithCountUnknown ¶ added in v0.13.0
func WithCountUnknown(count bool) ServerOption
WithCountUnknown controls whether UNKNOWN results (no credentials presented) are included in the unauthenticated burst count.
func WithFeatureGates ¶ added in v0.3.0
func WithFeatureGates(fg *commoncfg.FeatureGates) ServerOption
func WithMetrics ¶ added in v0.13.0
func WithMetrics(m *metric.Metrics) ServerOption
WithMetrics sets the audit-pipeline metrics.
func WithOIDCHandler ¶ added in v0.5.0
func WithOIDCHandler(hdl oidcHandlerInterface) ServerOption
func WithPolicyEngine ¶
func WithPolicyEngine(pe policies.Engine) ServerOption
func WithRateStore ¶ added in v0.13.0
func WithRateStore(rs ratestore.RateStore) ServerOption
WithRateStore sets the cross-pod store used to detect unauthenticated request bursts. When unset the server uses a no-op store and never emits burst events.
func WithSessionManager ¶ added in v0.9.8
func WithSessionManager(sessionManager sessionManagerInterface) ServerOption
func WithSessionPathPrefixes ¶ added in v0.9.8
func WithSessionPathPrefixes(sessionPathPrefixes []string) ServerOption
func WithTracer ¶ added in v0.12.0
func WithTracer(t trace.Tracer) ServerOption
WithTracer overrides the default OpenTelemetry tracer used to emit the per-Check application span. The default tracer is obtained from the global TracerProvider at NewServer time (see NewServer). Tests use this option to inject an SDK tracer backed by an in-memory exporter.
func WithTrustedSubjects ¶
func WithTrustedSubjects(m map[string]string) ServerOption