auth

package
v0.18.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jun 23, 2026 License: BSD-3-Clause-Clear Imports: 32 Imported by: 0

README

Auth Package

This package handles authentication (authn) and authorization (authz) for the OpenTDF platform.

Package Structure

auth/
├── authn.go           # Authentication middleware and token validation
├── casbin.go          # V1 Casbin enforcer (legacy, path-based authz)
├── config.go          # Configuration types
├── discovery.go       # OIDC discovery
└── authz/             # V2 authorization system
    ├── authorizer.go  # Authorizer interface and factory
    ├── resolver.go    # AuthzResolver for fine-grained resource authorization
    └── casbin/        # V2 Casbin implementation with multi-claim support

Security Guidelines

Never Log Sensitive Authentication Data

DO NOT log the following:

  1. JWT Tokens - Never log full tokens, even at DEBUG level

    • Tokens can be replayed if logs are compromised
    • Tokens may contain PII in claims
    • Large tokens can be used for DoS attacks (disk/memory exhaustion)
    • Unsanitized token content can enable log injection attacks
  2. Credentials - Never log passwords, API keys, or secrets

  3. Full UserInfo responses - May contain PII

Safe to log:

  • Claim names (e.g., which claim was missing)
  • Extracted role/group names (after validation)
  • Subject identifiers (if not sensitive in your context)
  • Error types and messages (without embedding tokens)
Example: What NOT to do
// BAD - logs full token (security risk)
e.logger.Debug("processing token", slog.Any("token", token))

// BAD - token in error message
e.logger.Error("auth failed", slog.String("token", tokenString))
Example: Safe logging
// GOOD - no sensitive data
e.logger.Debug("extracting roles from token")

// GOOD - only logs claim name, not value
e.logger.Warn("claim not found", slog.String("claim", claimName))

// GOOD - logs extracted, bounded data
e.logger.Debug("roles extracted", slog.Int("count", len(roles)))
Log Injection Prevention

Even when logging "safe" data extracted from tokens, be aware that:

  • Claims can contain newlines (fake log entries)
  • Claims can contain ANSI escape codes
  • Claims can be arbitrarily large

Consider truncating or sanitizing any user-controlled data before logging.

V1 vs V2 Authorization

  • V1 (casbin.go): Legacy path-based authorization using (subject, resource, action)
  • V2 (authz/casbin/): RPC + dimensions authorization using (subject, rpc, dimensions) with support for fine-grained resource authorization via AuthzResolver

V1 is being maintained for backward compatibility. New features should use V2.

Documentation

Index

Constants

View Source
const (
	ActionRead   = "read"
	ActionWrite  = "write"
	ActionDelete = "delete"
	ActionUnsafe = "unsafe"
	ActionOther  = "other"
)
View Source
const (
	// DiscoveryPath is the path to the discovery endpoint
	DiscoveryPath = "/.well-known/openid-configuration"
)

Variables

This section is empty.

Functions

func IPCMetadataClientInterceptor added in v0.11.0

func IPCMetadataClientInterceptor(log *logger.Logger) connect.UnaryInterceptorFunc

IPCMetadataClientInterceptor transfers gRPC outgoing metadata to Connect request headers for IPC calls

Types

type AccessTokenVerifier added in v0.15.0

type AccessTokenVerifier interface {
	VerifyAccessToken(ctx context.Context, tokenRaw string) (jwt.Token, error)
}

AccessTokenVerifier validates raw access tokens.

type AuthNConfig

type AuthNConfig struct {
	EnforceDPoP  bool                       `mapstructure:"enforceDPoP" json:"enforceDPoP" default:"false"`
	Issuer       string                     `mapstructure:"issuer" json:"issuer"`
	Audience     string                     `mapstructure:"audience" json:"audience"`
	Policy       internalauthz.PolicyConfig `mapstructure:"policy" json:"policy"`
	CacheRefresh string                     `mapstructure:"cache_refresh_interval" json:"cache_refresh_interval"`
	DPoPSkew     time.Duration              `mapstructure:"dpopskew" json:"dpopskew" default:"1h"`
	TokenSkew    time.Duration              `mapstructure:"skew" json:"skew" default:"1m"`
	DPoP         DPoPConfig                 `mapstructure:"dpop" json:"dpop"`
}

AuthNConfig is the configuration need for the platform to validate tokens

type Authentication

type Authentication struct {
	// contains filtered or unexported fields
}

Authentication holds a jwks cache and information about the openid configuration

func NewAuthenticator

func NewAuthenticator(ctx context.Context, cfg Config, logger *logger.Logger, wellknownRegistration func(namespace string, config any) error, opts ...AuthenticatorOption) (*Authentication, error)

Creates new authN which is used to verify tokens for a set of given issuers

func (*Authentication) AccessTokenVerifier added in v0.15.0

func (a *Authentication) AccessTokenVerifier() AccessTokenVerifier

AccessTokenVerifier returns the authenticator's shared access-token verifier.

func (Authentication) ConnectAuthNInterceptor added in v0.17.0

func (a Authentication) ConnectAuthNInterceptor() connect.UnaryInterceptorFunc

ConnectAuthNInterceptor authenticates Connect requests and enriches the request context with configured token claims needed by later middleware.

func (Authentication) ConnectAuthZInterceptor added in v0.17.0

func (a Authentication) ConnectAuthZInterceptor() connect.UnaryInterceptorFunc

ConnectAuthZInterceptor authorizes Connect requests using token and configured claims already stored in the request context.

func (Authentication) IPCUnaryServerInterceptor added in v0.5.0

func (a Authentication) IPCUnaryServerInterceptor() connect.UnaryInterceptorFunc

IPCUnaryServerInterceptor is a grpc interceptor that: 1. verifies the token in the metadata 2. reauthorizes the token if the route is in the list 3. translates known IPC Connect request headers back to context metadata for downstream consumers

func (Authentication) MuxHandler

func (a Authentication) MuxHandler(handler http.Handler) http.Handler

verifyTokenHandler is a http handler that verifies the token

type AuthenticatorOption added in v0.18.0

type AuthenticatorOption func(*Authentication)

AuthenticatorOption is a functional option for configuring Authentication.

func WithAuthzResolverRegistry added in v0.18.0

func WithAuthzResolverRegistry(registry *internalauthz.ResolverRegistry) AuthenticatorOption

WithAuthzResolverRegistry sets the authorization resolver registry. When set, the interceptors will call resolvers to extract authorization dimensions.

type Config

type Config struct {
	Enabled      bool     `mapstructure:"enabled" json:"enabled" default:"true"`
	PublicRoutes []string `mapstructure:"-" json:"-"`
	// Used for re-authentication of IPC connections
	IPCReauthRoutes []string `mapstructure:"-" json:"-"`
	AuthNConfig     `mapstructure:",squash"`

	// Programmatic role provider overrides (not loaded from config)
	RoleProvider          platformauthz.RoleProvider                   `mapstructure:"-" json:"-"`
	RoleProviderFactories map[string]platformauthz.RoleProviderFactory `mapstructure:"-" json:"-"`
}

AuthConfig pulls AuthN and AuthZ together

type DPoPConfig added in v0.18.0

type DPoPConfig struct {
	RequireNonce    bool          `mapstructure:"require_nonce" json:"require_nonce" default:"false"`
	NonceExpiration time.Duration `mapstructure:"nonce_expiration" json:"nonce_expiration" default:"5m"`
	// StrictHTU requires the htu claim in DPoP JWTs to include the origin
	// (scheme + host). When false (default), a path-only htu is accepted as
	// long as the path matches, easing SDK skew during rollout.
	StrictHTU bool `mapstructure:"strict_htu" json:"strict_htu" default:"false"`
}

func (DPoPConfig) Validate added in v0.18.0

func (c DPoPConfig) Validate() error

type DPoPNonceError added in v0.18.0

type DPoPNonceError struct {
	Message string
}

DPoPNonceError indicates a missing or expired nonce that the client should retry with a fresh one.

func (*DPoPNonceError) Error added in v0.18.0

func (e *DPoPNonceError) Error() string

type DPoPNonceMalformedError added in v0.18.0

type DPoPNonceMalformedError struct {
	Message string
}

DPoPNonceMalformedError indicates the nonce claim was present but had an invalid type or format. Unlike DPoPNonceError, this is not retryable — the client sent a malformed proof.

func (*DPoPNonceMalformedError) Error added in v0.18.0

func (e *DPoPNonceMalformedError) Error() string

type OIDCConfiguration

type OIDCConfiguration struct {
	Issuer                           string   `json:"issuer"`
	AuthorizationEndpoint            string   `json:"authorization_endpoint"`
	TokenEndpoint                    string   `json:"token_endpoint"`
	UserinfoEndpoint                 string   `json:"userinfo_endpoint"`
	JwksURI                          string   `json:"jwks_uri"`
	ResponseTypesSupported           []string `json:"response_types_supported"`
	SubjectTypesSupported            []string `json:"subject_types_supported"`
	IDTokenSigningAlgValuesSupported []string `json:"id_token_signing_alg_values_supported"`
	RequireRequestURIRegistration    bool     `json:"require_request_uri_registration"`
}

OIDCConfiguration holds the openid configuration for the issuer. Currently only required fields are included (https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata)

func DiscoverOIDCConfiguration

func DiscoverOIDCConfiguration(ctx context.Context, issuer string, logger *logger.Logger) (*OIDCConfiguration, error)

DiscoverOPENIDConfiguration discovers the openid configuration for the issuer provided

type TokenVerifier added in v0.15.0

type TokenVerifier struct {
	// contains filtered or unexported fields
}

TokenVerifier validates access tokens against the platform's configured IdP.

func NewTokenVerifier added in v0.15.0

func NewTokenVerifier(ctx context.Context, cfg AuthNConfig, log *logger.Logger) (*TokenVerifier, error)

NewTokenVerifier creates a reusable verifier backed by the IdP JWKS endpoint.

func (*TokenVerifier) VerifyAccessToken added in v0.15.0

func (v *TokenVerifier) VerifyAccessToken(ctx context.Context, tokenRaw string) (jwt.Token, error)

VerifyAccessToken validates the provided raw JWT and returns the parsed token on success.

Directories

Path Synopsis
Package authz provides the authorization interface and types for the OpenTDF platform.
Package authz provides the authorization interface and types for the OpenTDF platform.
casbin
Package casbin registers the Casbin authorization engine and dispatches to the configured versioned implementation.
Package casbin registers the Casbin authorization engine and dispatches to the configured versioned implementation.
casbin/v1
Package v1 provides the legacy path-based Casbin authorization implementation.
Package v1 provides the legacy path-based Casbin authorization implementation.
casbin/v2
Package v2 provides the resource/dimension-based Casbin authorization implementation.
Package v2 provides the resource/dimension-based Casbin authorization implementation.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL