Documentation
¶
Index ¶
- Constants
- func IPCMetadataClientInterceptor(log *logger.Logger) connect.UnaryInterceptorFunc
- type AccessTokenVerifier
- type AuthNConfig
- type Authentication
- func (a *Authentication) AccessTokenVerifier() AccessTokenVerifier
- func (a Authentication) ConnectAuthNInterceptor() connect.UnaryInterceptorFunc
- func (a Authentication) ConnectAuthZInterceptor() connect.UnaryInterceptorFunc
- func (a Authentication) IPCUnaryServerInterceptor() connect.UnaryInterceptorFunc
- func (a Authentication) MuxHandler(handler http.Handler) http.Handler
- type AuthenticatorOption
- type Config
- type DPoPConfig
- type DPoPNonceError
- type DPoPNonceMalformedError
- type DPoPProofError
- type OIDCConfiguration
- type TokenVerifier
Constants ¶
const ( ActionRead = "read" ActionWrite = "write" ActionDelete = "delete" ActionUnsafe = "unsafe" ActionOther = "other" )
const (
// DiscoveryPath is the path to the discovery endpoint
DiscoveryPath = "/.well-known/openid-configuration"
)
Variables ¶
This section is empty.
Functions ¶
func IPCMetadataClientInterceptor ¶ added in v0.11.0
func IPCMetadataClientInterceptor(log *logger.Logger) connect.UnaryInterceptorFunc
IPCMetadataClientInterceptor transfers gRPC outgoing metadata to Connect request headers for IPC calls
Types ¶
type AccessTokenVerifier ¶ added in v0.15.0
type AccessTokenVerifier interface {
VerifyAccessToken(ctx context.Context, tokenRaw string) (jwt.Token, error)
}
AccessTokenVerifier validates raw access tokens.
type AuthNConfig ¶
type AuthNConfig struct {
// Deprecated: use DPoP.Enforce (server.auth.dpop.enforce) instead. Still honored
// during the migration window: DPoP is enforced when either field is true.
EnforceDPoP bool `mapstructure:"enforceDPoP" json:"enforceDPoP" default:"false"`
Issuer string `mapstructure:"issuer" json:"issuer"`
Audience string `mapstructure:"audience" json:"audience"`
Policy internalauthz.PolicyConfig `mapstructure:"policy" json:"policy"`
CacheRefresh string `mapstructure:"cache_refresh_interval" json:"cache_refresh_interval"`
DPoPSkew time.Duration `mapstructure:"dpopskew" json:"dpopskew" default:"1h"`
TokenSkew time.Duration `mapstructure:"skew" json:"skew" default:"1m"`
DPoP DPoPConfig `mapstructure:"dpop" json:"dpop"`
}
AuthNConfig is the configuration need for the platform to validate tokens
type Authentication ¶
type Authentication struct {
// contains filtered or unexported fields
}
Authentication holds a jwks cache and information about the openid configuration
func NewAuthenticator ¶
func NewAuthenticator(ctx context.Context, cfg Config, logger *logger.Logger, wellknownRegistration func(namespace string, config any) error, opts ...AuthenticatorOption) (*Authentication, error)
Creates new authN which is used to verify tokens for a set of given issuers
func (*Authentication) AccessTokenVerifier ¶ added in v0.15.0
func (a *Authentication) AccessTokenVerifier() AccessTokenVerifier
AccessTokenVerifier returns the authenticator's shared access-token verifier.
func (Authentication) ConnectAuthNInterceptor ¶ added in v0.17.0
func (a Authentication) ConnectAuthNInterceptor() connect.UnaryInterceptorFunc
ConnectAuthNInterceptor authenticates Connect requests and enriches the request context with configured token claims needed by later middleware.
func (Authentication) ConnectAuthZInterceptor ¶ added in v0.17.0
func (a Authentication) ConnectAuthZInterceptor() connect.UnaryInterceptorFunc
ConnectAuthZInterceptor authorizes Connect requests using token and configured claims already stored in the request context.
func (Authentication) IPCUnaryServerInterceptor ¶ added in v0.5.0
func (a Authentication) IPCUnaryServerInterceptor() connect.UnaryInterceptorFunc
IPCUnaryServerInterceptor is a grpc interceptor that: 1. translates known IPC Connect request headers back to incoming metadata 2. reauthorizes routes that are configured for IPC reauth 3. rehydrates auth context from propagated incoming metadata without revalidating it
func (Authentication) MuxHandler ¶
func (a Authentication) MuxHandler(handler http.Handler) http.Handler
verifyTokenHandler is a http handler that verifies the token
type AuthenticatorOption ¶ added in v0.18.0
type AuthenticatorOption func(*Authentication)
AuthenticatorOption is a functional option for configuring Authentication.
func WithAuthzResolverRegistry ¶ added in v0.18.0
func WithAuthzResolverRegistry(registry *internalauthz.ResolverRegistry) AuthenticatorOption
WithAuthzResolverRegistry sets the authorization resolver registry. When set, the interceptors will call resolvers to extract authorization dimensions.
type Config ¶
type Config struct {
Enabled bool `mapstructure:"enabled" json:"enabled" default:"true"`
PublicRoutes []string `mapstructure:"-" json:"-"`
// Used for re-authentication of IPC connections
IPCReauthRoutes []string `mapstructure:"-" json:"-"`
AuthNConfig `mapstructure:",squash"`
// Programmatic role provider overrides (not loaded from config)
RoleProvider platformauthz.RoleProvider `mapstructure:"-" json:"-"`
RoleProviderFactories map[string]platformauthz.RoleProviderFactory `mapstructure:"-" json:"-"`
}
AuthConfig pulls AuthN and AuthZ together
type DPoPConfig ¶ added in v0.18.0
type DPoPConfig struct {
// Enforce requires access tokens to be DPoP-bound. Replaces the deprecated
// top-level server.auth.enforceDPoP field.
Enforce bool `mapstructure:"enforce" json:"enforce" default:"false"`
RequireNonce bool `mapstructure:"require_nonce" json:"require_nonce" default:"false"`
NonceExpiration time.Duration `mapstructure:"nonce_expiration" json:"nonce_expiration" default:"5m"`
// StrictHTU requires the htu claim in DPoP JWTs to include the origin
// (scheme + host). When false (default), a path-only htu is accepted as
// long as the path matches, easing SDK skew during rollout.
StrictHTU bool `mapstructure:"strict_htu" json:"strict_htu" default:"false"`
}
func (DPoPConfig) Validate ¶ added in v0.18.0
func (c DPoPConfig) Validate() error
type DPoPNonceError ¶ added in v0.18.0
type DPoPNonceError struct {
Message string
}
DPoPNonceError indicates a missing or expired nonce that the client should retry with a fresh one.
func (*DPoPNonceError) Error ¶ added in v0.18.0
func (e *DPoPNonceError) Error() string
type DPoPNonceMalformedError ¶ added in v0.18.0
type DPoPNonceMalformedError struct {
Message string
}
DPoPNonceMalformedError indicates the nonce claim was present but had an invalid type or format. Unlike DPoPNonceError, this is not retryable — the client sent a malformed proof.
func (*DPoPNonceMalformedError) Error ¶ added in v0.18.0
func (e *DPoPNonceMalformedError) Error() string
type DPoPProofError ¶ added in v0.19.0
type DPoPProofError struct {
// contains filtered or unexported fields
}
DPoPProofError marks a non-retryable DPoP proof rejection (tampered htu/htm, bad ath, replayed jti, malformed nonce). Handlers translate it into a WWW-Authenticate: DPoP error="invalid_dpop_proof" challenge per RFC 9449 §7.1.
func (*DPoPProofError) Error ¶ added in v0.19.0
func (e *DPoPProofError) Error() string
func (*DPoPProofError) Unwrap ¶ added in v0.19.0
func (e *DPoPProofError) Unwrap() error
type OIDCConfiguration ¶
type OIDCConfiguration struct {
Issuer string `json:"issuer"`
AuthorizationEndpoint string `json:"authorization_endpoint"`
TokenEndpoint string `json:"token_endpoint"`
UserinfoEndpoint string `json:"userinfo_endpoint"`
JwksURI string `json:"jwks_uri"`
ResponseTypesSupported []string `json:"response_types_supported"`
SubjectTypesSupported []string `json:"subject_types_supported"`
IDTokenSigningAlgValuesSupported []string `json:"id_token_signing_alg_values_supported"`
RequireRequestURIRegistration bool `json:"require_request_uri_registration"`
}
OIDCConfiguration holds the openid configuration for the issuer. Currently only required fields are included (https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata)
func DiscoverOIDCConfiguration ¶
func DiscoverOIDCConfiguration(ctx context.Context, issuer string, logger *logger.Logger) (*OIDCConfiguration, error)
DiscoverOPENIDConfiguration discovers the openid configuration for the issuer provided
type TokenVerifier ¶ added in v0.15.0
type TokenVerifier struct {
// contains filtered or unexported fields
}
TokenVerifier validates access tokens against the platform's configured IdP.
func NewTokenVerifier ¶ added in v0.15.0
func NewTokenVerifier(ctx context.Context, cfg AuthNConfig, log *logger.Logger) (*TokenVerifier, error)
NewTokenVerifier creates a reusable verifier backed by the IdP JWKS endpoint.
func (*TokenVerifier) VerifyAccessToken ¶ added in v0.15.0
VerifyAccessToken validates the provided raw JWT and returns the parsed token on success.
Directories
¶
| Path | Synopsis |
|---|---|
|
Package authz provides the authorization interface and types for the OpenTDF platform.
|
Package authz provides the authorization interface and types for the OpenTDF platform. |
|
casbin
Package casbin registers the Casbin authorization engine and dispatches to the configured versioned implementation.
|
Package casbin registers the Casbin authorization engine and dispatches to the configured versioned implementation. |
|
casbin/v1
Package v1 provides the legacy path-based Casbin authorization implementation.
|
Package v1 provides the legacy path-based Casbin authorization implementation. |
|
casbin/v2
Package v2 provides the resource/dimension-based Casbin authorization implementation.
|
Package v2 provides the resource/dimension-based Casbin authorization implementation. |