server

package
v0.5.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 12, 2026 License: Apache-2.0 Imports: 28 Imported by: 0

Documentation

Overview

Package server exposes mounted OpenVaultDB databases over the minimal HTTP API documented in docs/api.md.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type CORSConfig

type CORSConfig struct {
	// contains filtered or unexported fields
}

CORSConfig holds the allowed-origin set for the CORS middleware. A nil *CORSConfig means CORS is disabled — no headers are added.

func ParseCORSOrigins

func ParseCORSOrigins(values []string) *CORSConfig

ParseCORSOrigins builds a CORSConfig from a list of origin strings. Each element may be:

Comma-separated values within a single element are split automatically so both --cors "a,b" and --cors a --cors b are equivalent.

func (*CORSConfig) AllowedOrigin

func (c *CORSConfig) AllowedOrigin(origin string) string

AllowedOrigin returns the value to echo back in Access-Control-Allow-Origin, or "" when the origin is not allowed. Exported for testing.

type GrantIdentityConfig added in v0.4.0

type GrantIdentityConfig struct {
	Bootstrap access.PrincipalRef
	Resolve   MembershipResolver
}

GrantIdentityConfig maps verified bearer grants to typed identities. Bootstrap must come from persistent host configuration. It is never derived from a token, generated on startup, or inferred from a provider subject.

type Membership added in v0.4.0

type Membership struct {
	Roles    []string
	Groups   []string
	Revision string
}

Membership is authoritative current state, loaded anew for each request. External OAuth/OIDC bindings remain in the deployment's identity directory.

type MembershipResolver added in v0.4.0

type MembershipResolver func(context.Context, access.PrincipalRef) (Membership, error)

type Option

type Option func(*Server)

Option configures the Server.

func WithAccessInstanceID added in v0.5.0

func WithAccessInstanceID(id string) Option

WithAccessInstanceID supplies a stable deployment identity, shared by all mounts on this server. It must come from persistent host configuration.

func WithAuth

func WithAuth(cfg *auth.Config) Option

WithAuth enables authentication: the connect flow endpoints are served and every data/admin request must carry the owner token or a scoped app token.

func WithCORS

func WithCORS(cfg *CORSConfig) Option

WithCORS configures CORS header injection for browser clients. A nil cfg disables CORS entirely (zero behavior change, the default).

func WithDataDir

func WithDataDir(dir string) Option

WithDataDir enables runtime database creation (POST /v1/databases): each created database gets a manifest YAML plus an inGitDB data directory under dir, so a restart rescan (mount.Dir) remounts them.

func WithGrantIdentity added in v0.4.0

func WithGrantIdentity(config GrantIdentityConfig) Option

WithGrantIdentity reuses token authentication and capability checks. It adds typed subject/actor propagation and current membership resolution; it does not validate arbitrary external bearer tokens or create an identity store.

func WithOwnerAuthorization added in v0.5.0

func WithOwnerAuthorization(authorize OwnerAuthorization) Option

func WithPrincipalResolver added in v0.4.0

func WithPrincipalResolver(resolve PrincipalResolver) Option

type OwnerAuthorization added in v0.5.0

type OwnerAuthorization func(context.Context, *auth.Principal, az.Source, string, az.Resource) bool

OwnerAuthorization is a trusted deployment binding to each owner's existing authorization authority. A grant at OpenVaultDB never grants administration or protected-row inspection at a lower owner.

type PrincipalResolver added in v0.4.0

type PrincipalResolver func(context.Context, *auth.Principal) (access.Principal, error)

PrincipalResolver maps an authenticated actor to current internal identity and memberships. Implementations are trusted server configuration; callers cannot supply roles, groups, or policy variables in a DTQL request.

type Server

type Server struct {
	// contains filtered or unexported fields
}

Server serves one or more mounted databases.

func New

func New(version string, dbs map[string]*core.Database, opts ...Option) *Server

New creates a Server over mounted databases keyed by database id.

func (*Server) Handler

func (s *Server) Handler() http.Handler

Handler builds the HTTP handler. Middleware order (outermost first):

  1. CORS (when --cors is set) — short-circuits preflight OPTIONS before auth
  2. Auth (when --auth is set) — Layer-1 token validation
  3. Per-handler capability checks — Layer-2

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL