Documentation
¶
Overview ¶
Package server exposes mounted OpenVaultDB databases over the minimal HTTP API documented in docs/api.md.
Index ¶
- type CORSConfig
- type GrantIdentityConfig
- type Membership
- type MembershipResolver
- type Option
- func WithAccessInstanceID(id string) Option
- func WithAuth(cfg *auth.Config) Option
- func WithCORS(cfg *CORSConfig) Option
- func WithDataDir(dir string) Option
- func WithGrantIdentity(config GrantIdentityConfig) Option
- func WithOwnerAuthorization(authorize OwnerAuthorization) Option
- func WithPrincipalResolver(resolve PrincipalResolver) Option
- type OwnerAuthorization
- type PrincipalResolver
- type Server
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type CORSConfig ¶
type CORSConfig struct {
// contains filtered or unexported fields
}
CORSConfig holds the allowed-origin set for the CORS middleware. A nil *CORSConfig means CORS is disabled — no headers are added.
func ParseCORSOrigins ¶
func ParseCORSOrigins(values []string) *CORSConfig
ParseCORSOrigins builds a CORSConfig from a list of origin strings. Each element may be:
- "*" — allow any origin (dev only)
- "https://example.com" — exact origin match
- "http://localhost:4200" — exact (scheme + host + port)
Comma-separated values within a single element are split automatically so both --cors "a,b" and --cors a --cors b are equivalent.
func (*CORSConfig) AllowedOrigin ¶
func (c *CORSConfig) AllowedOrigin(origin string) string
AllowedOrigin returns the value to echo back in Access-Control-Allow-Origin, or "" when the origin is not allowed. Exported for testing.
type GrantIdentityConfig ¶ added in v0.4.0
type GrantIdentityConfig struct {
Bootstrap access.PrincipalRef
Resolve MembershipResolver
}
GrantIdentityConfig maps verified bearer grants to typed identities. Bootstrap must come from persistent host configuration. It is never derived from a token, generated on startup, or inferred from a provider subject.
type Membership ¶ added in v0.4.0
Membership is authoritative current state, loaded anew for each request. External OAuth/OIDC bindings remain in the deployment's identity directory.
type MembershipResolver ¶ added in v0.4.0
type MembershipResolver func(context.Context, access.PrincipalRef) (Membership, error)
type Option ¶
type Option func(*Server)
Option configures the Server.
func WithAccessInstanceID ¶ added in v0.5.0
WithAccessInstanceID supplies a stable deployment identity, shared by all mounts on this server. It must come from persistent host configuration.
func WithAuth ¶
WithAuth enables authentication: the connect flow endpoints are served and every data/admin request must carry the owner token or a scoped app token.
func WithCORS ¶
func WithCORS(cfg *CORSConfig) Option
WithCORS configures CORS header injection for browser clients. A nil cfg disables CORS entirely (zero behavior change, the default).
func WithDataDir ¶
WithDataDir enables runtime database creation (POST /v1/databases): each created database gets a manifest YAML plus an inGitDB data directory under dir, so a restart rescan (mount.Dir) remounts them.
func WithGrantIdentity ¶ added in v0.4.0
func WithGrantIdentity(config GrantIdentityConfig) Option
WithGrantIdentity reuses token authentication and capability checks. It adds typed subject/actor propagation and current membership resolution; it does not validate arbitrary external bearer tokens or create an identity store.
func WithOwnerAuthorization ¶ added in v0.5.0
func WithOwnerAuthorization(authorize OwnerAuthorization) Option
func WithPrincipalResolver ¶ added in v0.4.0
func WithPrincipalResolver(resolve PrincipalResolver) Option
type OwnerAuthorization ¶ added in v0.5.0
OwnerAuthorization is a trusted deployment binding to each owner's existing authorization authority. A grant at OpenVaultDB never grants administration or protected-row inspection at a lower owner.
type PrincipalResolver ¶ added in v0.4.0
PrincipalResolver maps an authenticated actor to current internal identity and memberships. Implementations are trusted server configuration; callers cannot supply roles, groups, or policy variables in a DTQL request.