Documentation
¶
Overview ¶
Package requests defines structures to represent requests' bodies from API.
Index ¶
- type AcceptInvite
- type AccessPolicyCreate
- type AccessPolicyDelete
- type AccessPolicyFilter
- type AccessPolicyGet
- type AccessPolicyIDParam
- type AccessPolicyList
- type AccessPolicySubject
- type AccessPolicyUpdate
- type AuthLocalUser
- type AuthTokenGet
- type AuthTokenSwap
- type CancelMembershipInvitation
- type CreateAPIKey
- type CreateInstallKey
- type CreateTag
- type CreateUserToken
- type DeleteAPIKey
- type DeleteTag
- type DeviceAuth
- type DeviceCreateTag
- type DeviceDelete
- type DeviceDeleteCustomField
- type DeviceGet
- type DeviceIdentity
- type DeviceInfo
- type DeviceList
- type DeviceLoginCodeResolve
- type DeviceLookup
- type DeviceOffline
- type DevicePairingAccept
- type DevicePairingCreate
- type DevicePairingStatus
- type DeviceParam
- type DeviceRemoveTag
- type DeviceRename
- type DeviceSetCustomField
- type DeviceUpdate
- type DeviceUpdateStatus
- type DeviceUpdateTag
- type EditSSHAccessMode
- type EnrollmentCallback
- type FingerprintParam
- type GenerateInvitationLink
- type GetStats
- type GetSystemInfo
- type LeaveNamespace
- type ListAPIKey
- type ListInstallKey
- type ListInstallKeyEvents
- type ListPublicKeys
- type ListSessions
- type ListTags
- type MemberList
- type MemberParam
- type NamespaceAddMember
- type NamespaceCreate
- type NamespaceDelete
- type NamespaceEdit
- type NamespaceGet
- type NamespaceList
- type NamespaceMembershipInvitationList
- type NamespaceRemoveMember
- type NamespaceUpdateMember
- type OptionalTime
- type PublicKeyAuth
- type PublicKeyCreate
- type PublicKeyDelete
- type PublicKeyFilter
- type PublicKeyGet
- type PublicKeyTagAdd
- type PublicKeyTagRemove
- type PublicKeyTagsUpdate
- type PublicKeyUpdate
- type PullTag
- type PushTag
- type RegisterUser
- type ResolveDevice
- type ResolveInvitation
- type RevealInstallKey
- type RoleBody
- type SSHApprovalConfirm
- type SSHApprovalCreate
- type SSHApprovalGet
- type SSHApprovalReject
- type SSHApprovalStatus
- type SSHIdentityCreate
- type SSHIdentityDelete
- type SSHIdentityIDParam
- type SSHIdentityList
- type SSHIdentityUpdate
- type ServiceAccountCreate
- type ServiceAccountDelete
- type ServiceAccountIDParam
- type ServiceAccountList
- type SessionAuthenticatedSet
- type SessionCreate
- type SessionEditRecordStatus
- type SessionEvent
- type SessionFinish
- type SessionGet
- type SessionIDParam
- type SessionKeepAlive
- type SessionSeat
- type SessionUpdate
- type Setup
- type SystemInstallScript
- type TagBody
- type TagDelete
- type TagParam
- type TagRename
- type TenantParam
- type UpdateAPIKey
- type UpdateInstallKey
- type UpdateTag
- type UpdateUser
- type UserMembershipInvitationList
- type UserParam
- type UserPasswordUpdate
- type WebReauthVerify
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type AcceptInvite ¶
type AccessPolicyCreate ¶
type AccessPolicyCreate struct {
Name string `json:"name" validate:"required"`
Subject AccessPolicySubject `json:"subject" validate:"required"`
Filter AccessPolicyFilter `json:"filter" validate:"required"`
Logins []string `json:"logins" validate:"required,min=1,dive,required"`
SourceIP []string `json:"source_ip" validate:"omitempty,dive,cidr|ip"`
Action string `json:"action" validate:"omitempty,oneof=allow deny"`
RequireReauth bool `json:"require_reauth" validate:""`
ReauthPeriod *int `json:"reauth_period" validate:"omitempty,gte=0"`
TenantID string `json:"-"`
}
AccessPolicyCreate is the structure to represent the request data for the create access policy endpoint.
type AccessPolicyDelete ¶
type AccessPolicyDelete struct {
AccessPolicyIDParam
TenantID string `json:"-"`
}
AccessPolicyDelete is the structure to represent the request data for the delete access policy endpoint.
type AccessPolicyFilter ¶
type AccessPolicyFilter struct {
Hostname string `json:"hostname,omitempty" validate:"required_without=Tags,excluded_with=Tags,regexp"`
Tags []string `json:"tags,omitempty" validate:"required_without=Hostname"`
}
AccessPolicyFilter selects the devices an access policy applies to. It is either a hostname regexp or a set of tags, never both, mirroring the public-key filter shape.
type AccessPolicyGet ¶
type AccessPolicyGet struct {
AccessPolicyIDParam
TenantID string `json:"-"`
}
AccessPolicyGet is the structure to represent the request data for the get access policy endpoint.
type AccessPolicyIDParam ¶
type AccessPolicyIDParam struct {
ID string `param:"id" validate:"required"`
}
AccessPolicyIDParam represents an access policy id as a path param.
type AccessPolicyList ¶
type AccessPolicyList struct {
TenantID string `json:"-"`
}
AccessPolicyList is the structure to represent the request data for the list access policies endpoint.
type AccessPolicySubject ¶
type AccessPolicySubject struct {
Type string `json:"type" validate:"required,oneof=user role all-members"`
Value string `json:"value"`
}
AccessPolicySubject identifies who an access policy grants access to.
type AccessPolicyUpdate ¶
type AccessPolicyUpdate struct {
AccessPolicyIDParam
Name string `json:"name" validate:"required"`
Subject AccessPolicySubject `json:"subject" validate:"required"`
Filter AccessPolicyFilter `json:"filter" validate:"required"`
Logins []string `json:"logins" validate:"required,min=1,dive,required"`
SourceIP []string `json:"source_ip" validate:"omitempty,dive,cidr|ip"`
Action string `json:"action" validate:"omitempty,oneof=allow deny"`
RequireReauth bool `json:"require_reauth" validate:""`
ReauthPeriod *int `json:"reauth_period" validate:"omitempty,gte=0"`
TenantID string `json:"-"`
}
AccessPolicyUpdate is the structure to represent the request data for the update access policy endpoint.
type AuthLocalUser ¶ added in v0.18.0
type AuthLocalUser struct {
// Identifier represents an username or email.
//
// TODO: change json tag from username to identifier and update the OpenAPI.
Identifier models.UserAuthIdentifier `json:"username" validate:"required"`
Password string `json:"password" validate:"required"`
}
AuthLocalUser is the structure to represent the request body for the user auth endpoint.
type AuthTokenGet ¶
type AuthTokenGet struct {
UserParam
}
AuthTokenGet is the structure to represent the request data for get auth token endpoint.
type AuthTokenSwap ¶
type AuthTokenSwap struct {
TenantParam
}
AuthTokenSwap is the structure to represent the request data for swap auth token endpoint.
type CreateAPIKey ¶ added in v0.15.0
type CreateAPIKey struct {
UserID string `header:"X-ID"`
TenantID string `header:"X-Tenant-ID"`
Role authorizer.Role `header:"X-Role"`
Name string `json:"name" validate:"required,api-key_name"`
ExpiresAt int `json:"expires_at" validate:"required,api-key_expires-at"`
Key string `json:"key" validate:"omitempty,uuid"`
OptRole authorizer.Role `json:"role" validate:"omitempty,member_role"`
}
type CreateInstallKey ¶
type CreateInstallKey struct {
UserID string `header:"X-ID"`
TenantID string `header:"X-Tenant-ID"`
Name string `json:"name" validate:"required,api-key_name"`
// Mode is the enrollment policy. Omitted defaults to "automatic". Mode-specific fields
// (WebhookURL/WebhookSecret, AllowedMACs) are validated in the service.
Mode string `json:"mode" validate:"omitempty,oneof=automatic manual webhook allowlist"`
// WebhookURL and WebhookSecret configure the webhook mode; AllowedMACs configures the allowlist mode.
WebhookURL string `json:"webhook_url" validate:"omitempty,url"`
WebhookSecret string `json:"webhook_secret"`
AllowedMACs []string `json:"allowed_macs" validate:"omitempty,dive,required"`
// WebhookTimeout (seconds, max 15) is the synchronous request timeout; WebhookCallbackTTL (seconds,
// max 24h) is the deferred-decision token's validity. 0/omitted uses the server default.
WebhookTimeout int `json:"webhook_timeout" validate:"omitempty,min=0,max=15"`
WebhookCallbackTTL int `json:"webhook_callback_ttl" validate:"omitempty,min=0,max=86400"`
// ExpiresAt is the absolute date the key expires. A null (or omitted) value means the key never
// expires. When set, it must be in the future.
ExpiresAt *time.Time `json:"expires_at"`
// UsageLimit caps how many devices may enroll: 1 is single-use (one-off), a higher value is that
// many devices, 0 (or omitted) is unlimited. Whether the key is reusable is derived from this.
UsageLimit int `json:"usage_limit" validate:"omitempty,min=0"`
Ephemeral bool `json:"ephemeral"`
// EphemeralTimeout is how many minutes an ephemeral device may stay offline before removal
// (1-10). Only honored when Ephemeral is true; defaults to the maximum when omitted.
EphemeralTimeout int `json:"ephemeral_timeout" validate:"omitempty,min=1,max=10"`
Tags []string `json:"tags" validate:"omitempty,dive,required"`
}
type CreateUserToken ¶ added in v0.16.0
type DeleteAPIKey ¶ added in v0.16.0
type DeviceAuth ¶
type DeviceAuth struct {
Info *DeviceInfo `json:"info" validate:"required"`
Sessions []string `json:"sessions,omitempty"`
Hostname string `json:"hostname,omitempty" validate:"required_without=Identity,omitempty,device_name" hash:"-"`
Identity *DeviceIdentity `json:"identity,omitempty" validate:"required_without=Hostname,omitempty"`
PublicKey string `json:"public_key" validate:"required"`
TenantID string `json:"tenant_id" validate:"required"`
InstallKey string `json:"install_key,omitempty"`
RealIP string `header:"X-Real-IP"`
// ForwardedHost/ForwardedProto carry the public base (set by the gateway) so a webhook-mode
// enrollment can build an absolute callback URL for the integrator.
ForwardedHost string `header:"X-Forwarded-Host"`
ForwardedProto string `header:"X-Forwarded-Proto"`
}
DeviceAuth is the structure to represent the request data for device auth endpoint.
type DeviceCreateTag ¶
type DeviceCreateTag struct {
DeviceParam
TagBody
}
DeviceCreateTag is the structure to represent the request data for device create tag endpoint.
type DeviceDelete ¶
type DeviceDelete struct {
DeviceParam
}
DeviceDelete is the structure to represent the request data for delete device endpoint.
type DeviceDeleteCustomField ¶ added in v0.25.0
type DeviceDeleteCustomField struct {
TenantID string `header:"X-Tenant-ID"`
DeviceParam
Key string `param:"key" validate:"required,min=1,max=64"`
}
type DeviceGet ¶
type DeviceGet struct {
DeviceParam
}
DeviceGet is the structure to represent the request data for get device endpoint.
type DeviceIdentity ¶
type DeviceIdentity struct {
MAC string `json:"mac"`
}
type DeviceInfo ¶
type DeviceList ¶ added in v0.16.0
type DeviceLoginCodeResolve ¶
type DeviceLoginCodeResolve struct {
Code string `param:"code" validate:"required"`
}
DeviceLoginCodeResolve is the structure to represent the request data for the device login code resolve endpoint.
type DeviceLookup ¶
type DeviceLookup struct {
TenantID string `query:"tenant_id" validate:"required"`
Name string `query:"name" validate:"required"`
}
DeviceLookup is the structure to represent the request data for lookup device endpoint.
type DeviceOffline ¶
type DeviceOffline struct {
DeviceParam
}
DeviceOffline is the structure to represent the request data for offline device endpoint.
type DevicePairingAccept ¶
type DevicePairingAccept struct {
Code string `param:"code" validate:"required"`
TenantID string `json:"tenant_id" validate:"required,uuid"`
}
DevicePairingAccept is the structure to represent the request data for the device pairing accept endpoint. The code is validated (normalized + checked) in the service, not here, since its charset/length is the pairing-code alphabet, not hexadecimal.
type DevicePairingCreate ¶
type DevicePairingCreate struct {
Info *DeviceInfo `json:"info" validate:"required"`
Hostname string `json:"hostname,omitempty" validate:"required_without=Identity,omitempty,device_name" hash:"-"`
Identity *DeviceIdentity `json:"identity,omitempty" validate:"required_without=Hostname,omitempty"`
PublicKey string `json:"public_key" validate:"required"`
Code string `json:"code,omitempty"`
}
DevicePairingCreate is the structure to represent the request data for the device pairing creation endpoint. It mirrors DeviceAuth minus the tenant, which the user chooses at accept time.
Code is optional: when set, the agent was handed a pre-authorized pairing code at install time (see PrepareDevicePairing), so instead of minting a code for a user to accept, the server claims it and accepts the device automatically.
type DevicePairingStatus ¶
type DevicePairingStatus struct {
Code string `param:"code" validate:"required"`
}
DevicePairingStatus is the structure to represent the request data for the device pairing status endpoint.
type DeviceParam ¶
type DeviceParam struct {
UID string `param:"uid" validate:"required"`
}
DeviceParam is a structure to represent and validate a device UID as path param.
type DeviceRemoveTag ¶
type DeviceRemoveTag struct {
DeviceParam
TagBody
}
DeviceRemoveTag is the structure to represent the request data for device remove tag endpoint.
type DeviceRename ¶
type DeviceRename struct {
DeviceParam
Name string `json:"name" validate:"required"`
}
DeviceRename is the structure to represent the request data for rename device endpoint.
type DeviceSetCustomField ¶ added in v0.25.0
type DeviceSetCustomField struct {
TenantID string `header:"X-Tenant-ID"`
DeviceParam
Key string `param:"key" validate:"required,min=1,max=64"`
Value string `json:"value" validate:"max=256"`
}
type DeviceUpdate ¶
type DeviceUpdateStatus ¶
type DeviceUpdateStatus struct {
TenantID string `header:"X-Tenant-ID"`
UID string `param:"uid" validate:"required"`
Status string `param:"status" validate:"required,oneof=accepted pending rejected"`
}
DeviceStatus is the structure to represent the request data for update device status to pending endpoint.
type DeviceUpdateTag ¶
type DeviceUpdateTag struct {
DeviceParam
Tags []string `json:"tags" validate:"required,min=0,max=3,unique,dive,min=3,max=255,alphanum,ascii,excludes=/@&:"`
}
DeviceUpdateTag is the structure to represent the request data for device update tags endpoint.
type EditSSHAccessMode ¶
type EditSSHAccessMode struct {
TenantParam
SSHAccessMode string `json:"ssh_access_mode" validate:"required,oneof=legacy identity"`
}
EditSSHAccessMode is the structure to represent the request data for the edit SSH access mode endpoint.
type EnrollmentCallback ¶
type EnrollmentCallback struct {
Token string `param:"token" validate:"required"`
Decision string `json:"decision" validate:"required,oneof=accept reject"`
Reason string `json:"reason"`
}
EnrollmentCallback is a webhook integrator's deferred decision, redeemed against the signed callback token embedded in the URL. The token is the credential (no API key), so there is no tenant header.
type FingerprintParam ¶
type FingerprintParam struct {
Fingerprint string `param:"fingerprint" validate:"required"`
}
FingerprintParam is a structure to represent and validate a public key fingerprint as path param.
type GenerateInvitationLink ¶
type GenerateInvitationLink struct {
ForwardedHost string `header:"X-Forwarded-Host" validate:"required"`
ForwardedProto string `header:"X-Forwarded-Proto"`
TenantID string `param:"tenant" validate:"required,uuid"`
UserID string `header:"X-ID" validate:"required"`
MemberEmail string `json:"email" validate:"required"`
MemberRole authorizer.Role `json:"role" validate:"required,member_role"`
}
type GetSystemInfo ¶ added in v0.18.0
type LeaveNamespace ¶ added in v0.17.1
type LeaveNamespace struct {
UserID string `header:"X-ID" validate:"required"`
// TenantID represents the namespace that the user intends to leave.
TenantID string `param:"tenant" validate:"required,uuid"`
// AuthenticatedTenantID represents the namespace to which the user is currently authenticated.
AuthenticatedTenantID string `header:"X-Tenant-ID" validate:"required"`
}
type ListAPIKey ¶ added in v0.16.0
type ListInstallKey ¶
type ListInstallKeyEvents ¶
type ListInstallKeyEvents struct {
TenantID string `header:"X-Tenant-ID"`
// ID is the install key's digest. History is keyed by digest, not name: names are unique only per
// namespace and can be reused (the system "legacy" key) or renamed, so a name would be ambiguous.
ID string `param:"id" validate:"required"`
query.Paginator
query.Sorter
}
type ListPublicKeys ¶ added in v0.21.0
type ListSessions ¶ added in v0.21.0
type MemberList ¶
type MemberList struct {
TenantID string `param:"tenant" validate:"required,uuid"`
query.Paginator
}
MemberList is the structure to represent the request data for the list namespace members endpoint, consistent with the rest of the /namespaces/:tenant family.
type MemberParam ¶
type MemberParam struct {
MemberUID string `param:"uid" validate:"required"`
}
MemberParam is a structure to represent and validate a member UID as path param.
type NamespaceAddMember ¶ added in v0.16.0
type NamespaceAddMember struct {
ForwardedHost string `header:"X-Forwarded-Host" validate:"required"`
ForwardedProto string `header:"X-Forwarded-Proto"`
UserID string `header:"X-ID" validate:"required"`
TenantID string `param:"tenant" validate:"required,uuid"`
MemberEmail string `json:"email" validate:"required"`
MemberRole authorizer.Role `json:"role" validate:"required,member_role"`
}
type NamespaceCreate ¶
type NamespaceCreate struct {
UserID string `header:"X-ID" validate:"required"`
Name string `json:"name" validate:"required,hostname_rfc1123,excludes=."`
TenantID string `json:"tenant" validate:"omitempty,uuid"`
Type string `json:"type" validate:"omitempty,lowercase,oneof=personal team"`
}
NamespaceCreate is the structure to represent the request data for create namespace endpoint.
type NamespaceDelete ¶
type NamespaceDelete struct {
TenantParam
}
NamespaceDelete is the structure to represent the request data for delete namespace endpoint.
type NamespaceEdit ¶
type NamespaceEdit struct {
TenantParam
Name string `json:"name" validate:"omitempty,hostname_rfc1123,excludes=."`
Settings struct {
SessionRecord *bool `json:"session_record" validate:"omitempty"`
ConnectionAnnouncement *string `json:"connection_announcement" validate:"omitempty,min=0,max=4096"`
} `json:"settings"`
}
NamespaceEdit is the structure to represent the request data for edit namespace endpoint.
type NamespaceGet ¶
type NamespaceGet struct {
TenantParam
}
NamespaceGet is the structure to represent the request data for get namespace endpoint.
type NamespaceList ¶ added in v0.17.0
type NamespaceList struct {
UserID string `header:"X-ID"`
TenantID string `header:"X-Tenant-ID"`
// IsAdmin comes from the authenticated identity; a client-supplied X-Admin is overwritten.
IsAdmin bool `header:"X-Admin"`
query.Paginator
query.Filters
}
NamespaceList is the structure to represent the request data for list namespaces endpoint.
type NamespaceMembershipInvitationList ¶
type NamespaceMembershipInvitationList struct {
// ForwardedHost is only used to build the copyable invite_url; it's optional so a missing
// header degrades to omitting the link rather than failing the whole listing.
ForwardedHost string `header:"X-Forwarded-Host"`
ForwardedProto string `header:"X-Forwarded-Proto"`
TenantID string `param:"tenant" validate:"required"`
UserID string `header:"X-ID" validate:"required"`
query.Paginator
query.Sorter
query.Filters
}
type NamespaceRemoveMember ¶ added in v0.16.0
type NamespaceUpdateMember ¶ added in v0.16.0
type NamespaceUpdateMember struct {
UserID string `header:"X-ID" validate:"required"`
TenantID string `param:"tenant" validate:"required,uuid"`
MemberID string `param:"uid" validate:"required"`
MemberRole authorizer.Role `json:"role" validate:"omitempty,member_role"`
}
type OptionalTime ¶
OptionalTime carries RFC 7396 (JSON Merge Patch) semantics for a nullable field in a partial update: an omitted key leaves the value unchanged (Present is false), an explicit null clears it (Present is true, Value is nil), and a timestamp sets it.
func (*OptionalTime) UnmarshalJSON ¶
func (o *OptionalTime) UnmarshalJSON(data []byte) error
type PublicKeyAuth ¶
type PublicKeyAuth struct {
Fingerprint string `json:"fingerprint" validate:"required"`
Data string `json:"data" validate:"required"`
}
PublicKeyAuth is the structure to represent the request data for public key auth endpoint.
type PublicKeyCreate ¶
type PublicKeyCreate struct {
Data []byte `json:"data" validate:"required"`
Filter PublicKeyFilter `json:"filter" validate:"required"`
Name string `json:"name" validate:"required"`
Username string `json:"username" validate:"required,regexp"`
TenantID string `json:"-"`
Fingerprint string `json:"-"`
}
PublicKeyCreate is the structure to represent the request data for create public key endpoint.
type PublicKeyDelete ¶
type PublicKeyDelete struct {
FingerprintParam
}
PublicKeyDelete is the structure to represent the request data for delete public key endpoint.
type PublicKeyFilter ¶
type PublicKeyGet ¶
type PublicKeyGet struct {
FingerprintParam
TenantParam
}
PublicKeyGet is the structure to represent the request data for get public key endpoint.
type PublicKeyTagAdd ¶
type PublicKeyTagAdd struct {
FingerprintParam
TagParam
}
PublicKeyTagAdd is the structure to represent the request data for add tag to public key endpoint.
type PublicKeyTagRemove ¶
type PublicKeyTagRemove struct {
FingerprintParam
TagParam
}
PublicKeyTagRemove is the structure to represent the request data for remove tag from public key endpoint.
type PublicKeyTagsUpdate ¶
type PublicKeyTagsUpdate struct {
FingerprintParam
Tags []string `json:"tags" validate:"required,min=1,max=3,unique,dive,min=3,max=255,alphanum,ascii,excludes=/@&:"`
}
PublicKeyTagsUpdate is the structure to represent the request data for update tags from public key endpoint.
type PublicKeyUpdate ¶
type PublicKeyUpdate struct {
FingerprintParam
// Name is the public key's name.
Name string `json:"name" validate:"required"`
// Username is the public key's username.
Username string `json:"username" validate:"required,regexp"`
// Filter is the public key's filter.
Filter PublicKeyFilter `json:"filter" validate:"required"`
}
PublicKeyUpdate is the structure to represent the request data for update public key endpoint.
type PullTag ¶ added in v0.21.0
type PullTag struct {
TenantID string `param:"tenant" header:"X-Tenant-ID" validate:"required,uuid"`
Name string `param:"name" validate:"required,min=3,max=255,alphanum,ascii,excludes=/@&:"`
// TargetID is the identifier of the target to pull the tag of.
// For the reason cannot of it can be a list of things (UID for device, ID for firewall, etc...), it
// cannot be parsed and must be set manually
TargetID string `validate:"required"`
}
type PushTag ¶ added in v0.21.0
type PushTag struct {
TenantID string `param:"tenant" header:"X-Tenant-ID" validate:"required,uuid"`
Name string `param:"name" validate:"required,min=3,max=255,alphanum,ascii,excludes=/@&:"`
// TargetID is the identifier of the target to push the tag on.
// For the reason cannot of it can be a list of things (UID for device, ID for firewall, etc...), it
// cannot be parsed and must be set manually
TargetID string `validate:"required"`
}
type RegisterUser ¶
type RegisterUser struct {
Name string `json:"name" validate:"required,name"`
Username string `json:"username" validate:"required,username"`
// Email is required for open self-registration, but omitted on the invite flow:
// there the email is derived from the invitation the Sig resolves to (the invitee
// can't retarget it), so it's optional when a Sig is present.
Email string `json:"email" validate:"required_without=Sig,omitempty,email"`
Password string `json:"password" validate:"required,password"`
EmailMarketing bool `json:"email_marketing"`
// Sig is the invitation code from the accept-invite link. When present, it proves
// the email was already validated (the invitee clicked the link) and identifies the
// invitation. It's a human-readable pairing code, not a UUID.
Sig string `json:"sig" validate:"omitempty"`
}
type ResolveDevice ¶ added in v0.19.1
type ResolveInvitation ¶
type ResolveInvitation struct {
Invite string `query:"invite" validate:"required"`
}
ResolveInvitation resolves a pending invitation from its invite code alone — the only thing the accept-invite link carries. Public: the code is the credential.
type RevealInstallKey ¶
type RoleBody ¶
type RoleBody struct {
Role string `json:"role" validate:"required,oneof=administrator operator observer"`
}
RoleBody is a structure to represent and validate a namespace role as request body.
type SSHApprovalConfirm ¶
type SSHApprovalConfirm struct {
Code string `param:"code" validate:"required"`
// ExpiresIn is how many days the key being bound should keep working,
// omitted for a key that never expires. Only meaningful for the identity
// kind, since a re-auth binds nothing.
ExpiresIn *int `json:"expires_in" validate:"omitempty,min=1"`
}
SSHApprovalConfirm is the request data for the accept endpoint.
type SSHApprovalCreate ¶
type SSHApprovalCreate struct {
SessionUID string `json:"session_uid" validate:"required"`
SSHID string `json:"sshid" validate:"required"`
TenantID string `json:"tenant_id" validate:"required,uuid"`
DeviceUID string `json:"device_uid" validate:"required"`
DeviceName string `json:"device_name" validate:""`
Username string `json:"username" validate:"required"`
IPAddress string `json:"ip_address" validate:"required"`
// Kind is what confirming will do: bind the key as an identity, or refresh an
// existing identity's re-auth window.
Kind models.SSHApprovalKind `json:"kind" validate:"required,oneof=identity reauth"`
Fingerprint string `json:"fingerprint" validate:"required"`
Data []byte `json:"data" validate:"required"`
// ReauthPeriod carries the policy's window so the console can say how long
// confirming lasts. Only meaningful for the reauth kind.
ReauthPeriod *int `json:"reauth_period" validate:""`
}
SSHApprovalCreate is the payload the SSH gateway posts to open a JIT login approval. The gateway only posts it once it knows a browser step is actually needed, so the presented key and the kind come with it. It has already resolved the target device and namespace, so it passes them through; the API does not re-parse the SSHID.
type SSHApprovalGet ¶
type SSHApprovalGet struct {
Code string `param:"code" validate:"required"`
}
SSHApprovalGet is the request data for the endpoint the console page uses to render the approval request details.
type SSHApprovalReject ¶
type SSHApprovalReject struct {
Code string `param:"code" validate:"required"`
}
SSHApprovalReject is the request data for the deny endpoint.
type SSHApprovalStatus ¶
type SSHApprovalStatus struct {
Code string `param:"code" validate:"required"`
// Wait asks the API to hold the request open until the login is decided
// instead of answering "pending" right away. The gateway sets it so the
// person is not left staring at a frozen terminal for a poll interval after
// they already decided.
Wait bool `query:"wait" validate:""`
}
SSHApprovalStatus is the request data for the status endpoint the gateway polls. The code is validated (normalized + checked) in the service.
type SSHIdentityCreate ¶
type SSHIdentityCreate struct {
TenantID string `json:"-"`
UserID string `json:"-"`
Name string `json:"name" validate:""`
// Data is the OpenSSH public key to enroll.
Data string `json:"data" validate:"required"`
// Source says whether this is a key somebody pasted or the web terminal
// enrolling its own browser-held one, defaulting to the former. The caller
// asserts it, so it may only ever label the identity — the approval path is
// not accepted here precisely because that one the server knows for itself.
Source models.SSHIdentitySource `json:"source" validate:"omitempty,oneof=manual browser"`
// ExpiresIn is how many days the key should keep working, omitted for a key
// that never expires. The gateway refuses a login with an expired key.
ExpiresIn *int `json:"expires_in" validate:"omitempty,min=1"`
}
SSHIdentityCreate is the request data for manually enrolling an SSH public key (paste a key in the console) as an identity for the caller.
type SSHIdentityDelete ¶
type SSHIdentityDelete struct {
SSHIdentityIDParam
TenantID string `json:"-"`
UserID string `json:"-"`
// Manage reports whether the caller holds the SSHIdentityManage permission,
// allowing them to revoke another member's identity.
Manage bool `json:"-"`
}
SSHIdentityDelete is the request data for revoking an enrolled SSH identity.
type SSHIdentityIDParam ¶
type SSHIdentityIDParam struct {
ID string `param:"id" validate:"required"`
}
SSHIdentityIDParam represents an SSH identity id as a path param.
type SSHIdentityList ¶
type SSHIdentityList struct {
TenantID string `json:"-"`
UserID string `json:"-"`
All bool `query:"all"`
}
SSHIdentityList is the request data for listing the caller's enrolled SSH identities in the current namespace. All lists every member's identities and requires the SSHIdentityManage permission.
type SSHIdentityUpdate ¶
type SSHIdentityUpdate struct {
SSHIdentityIDParam
TenantID string `json:"-"`
UserID string `json:"-"`
Name string `json:"name" validate:"required"`
}
SSHIdentityUpdate is the request data for renaming an enrolled SSH identity.
type ServiceAccountCreate ¶
type ServiceAccountCreate struct {
TenantID string `json:"-"`
Name string `json:"name" validate:"required"`
// Data is the OpenSSH public key to enroll for the service account.
Data string `json:"data" validate:"required"`
// SingleUse burns the key after one established SSH session (Vault-OTP style:
// consumed per access, not per enrollment).
SingleUse bool `json:"single_use"`
// ExpiresIn is the key's TTL in days from creation; nil means it never
// expires. Service-account only.
ExpiresIn *int `json:"expires_in" validate:"omitempty,min=1"`
}
ServiceAccountCreate is the request data for creating a service account: a display name plus the OpenSSH public key to enroll as its first identity.
type ServiceAccountDelete ¶
type ServiceAccountDelete struct {
ServiceAccountIDParam
TenantID string `json:"-"`
}
ServiceAccountDelete is the request data for deleting a service account. Removing the account cascades to its membership and every SSH identity it holds.
type ServiceAccountIDParam ¶
type ServiceAccountIDParam struct {
ID string `param:"id" validate:"required"`
}
ServiceAccountIDParam represents a service account id as a path param.
type ServiceAccountList ¶
type ServiceAccountList struct {
TenantID string `json:"-"`
}
ServiceAccountList is the request data for listing a namespace's service accounts.
type SessionAuthenticatedSet ¶
type SessionAuthenticatedSet struct {
SessionIDParam
Authenticated bool `json:"authenticated" validate:"required"`
}
SessionAuthenticatedSet is the structure to represent the request data for set authenticated session endpoint.
type SessionCreate ¶
type SessionCreate struct {
UID string `json:"uid" validate:"required"`
DeviceUID string `json:"device_uid" validate:"required"`
Username string `json:"username" validate:"required"`
IPAddress string `json:"ip_address" validate:"required"`
Type string `json:"type" validate:"required"`
Term string `json:"term" validate:""`
Web bool `json:"web" validate:""`
// UserID is the ShellHub account that authorized the session via browser
// approval. Empty for password/public-key and web-terminal sessions.
UserID string `json:"user_id" validate:""`
}
SessionCreate is the structure to represent the request data for create session endpoint.
type SessionEditRecordStatus ¶
type SessionEditRecordStatus struct {
TenantParam
SessionRecord bool `json:"session_record"`
}
SessionEditRecordStatus is the structure to represent the request data for edit session record status endpoint.
type SessionEvent ¶ added in v0.18.0
type SessionFinish ¶
type SessionFinish struct {
SessionIDParam
}
SessionFinish is the structure to represent the request data for finish session endpoint.
type SessionGet ¶
type SessionGet struct {
SessionIDParam
}
SessionGet is the structure to represent the request data for get session endpoint.
type SessionIDParam ¶
type SessionIDParam struct {
// UID is the session's UID.
UID string `param:"uid" validate:"required"`
}
SessionIDParam is a structure to represent and validate a session UID as path param.
type SessionKeepAlive ¶
type SessionKeepAlive struct {
SessionIDParam
}
SessionFinish is the structure to represent the request data for keep alive session endpoint.
type SessionSeat ¶ added in v0.19.0
type SessionSeat struct {
SessionIDParam
ID int `json:"id"`
}
type SessionUpdate ¶ added in v0.16.0
type SessionUpdate struct {
SessionIDParam
Recorded *bool `json:"recorded"`
Authenticated *bool `json:"authenticated"`
Type *string `json:"type"`
}
type Setup ¶
type Setup struct {
Email string `json:"email" validate:"required,email"`
Name string `json:"name" validate:"required,name"`
Username string `json:"username" validate:"required,username"`
Password string `json:"password" validate:"required,password"`
Namespace string `json:"namespace" validate:"required,hostname_rfc1123,excludes=."`
}
type SystemInstallScript ¶
type SystemInstallScript struct {
Host string `header:"X-Forwarded-Host"`
Scheme string `header:"X-Forwarded-Proto"`
ForwardedPort string `header:"X-Forwarded-Port"`
TenantID string `query:"tenant_id"`
PreferredHostname string `query:"preferred_hostname"`
PreferredIdentity string `query:"preferred_identity"`
}
type TagBody ¶
type TagBody struct {
Tag string `json:"tag" validate:"required,min=3,max=255,alphanum,ascii,excludes=/@&:"`
}
TagBody is a structure to represent and validate a tag as json request body.
type TagDelete ¶
type TagDelete struct {
TagParam
}
TagDelete is the structure to represent the request data for delete tag endpoint.
type TagParam ¶
type TagParam struct {
Tag string `param:"tag" validate:"required,min=3,max=255,alphanum,ascii,excludes=/@&:"`
}
TagParam is a structure to represent and validate a tag as path param.
type TagRename ¶
type TagRename struct {
TagParam
NewTag string `json:"tag" validate:"required,min=3,max=255,alphanum,ascii,excludes=/@&:"`
}
TagRename is the structure to represent the request data for rename tag endpoint.
type TenantParam ¶
type TenantParam struct {
Tenant string `param:"tenant" validate:"required,uuid"`
}
TenantParam is a structure to represent and validate a namespace tenant as path param.
type UpdateAPIKey ¶ added in v0.16.0
type UpdateAPIKey struct {
UserID string `header:"X-ID"`
TenantID string `header:"X-Tenant-ID"`
// CurrentName is the current stored name. It is different from [UpdateAPIKey.Name], which is used
// to handle the new target name (optional).
CurrentName string `param:"name" validate:"required"`
Name string `json:"name" validate:"omitempty,api-key_name"`
Role authorizer.Role `json:"role" validate:"omitempty,member_role"`
}
type UpdateInstallKey ¶
type UpdateInstallKey struct {
UserID string `header:"X-ID"`
TenantID string `header:"X-Tenant-ID"`
// CurrentName is the current stored name (path param). It differs from [UpdateInstallKey.Name],
// which is the optional new target name.
CurrentName string `param:"name" validate:"required"`
Name string `json:"name" validate:"omitempty,api-key_name"`
// Mode changes the enrollment policy. Nil leaves it unchanged. Mode-specific fields are validated
// in the service against the resulting key state.
Mode *string `json:"mode" validate:"omitempty,oneof=automatic manual webhook allowlist"`
// WebhookURL/WebhookSecret update the webhook config; nil leaves each unchanged. AllowedMACs
// replaces the allowlist when non-nil.
WebhookURL *string `json:"webhook_url" validate:"omitempty,url"`
WebhookSecret *string `json:"webhook_secret"`
AllowedMACs []string `json:"allowed_macs" validate:"omitempty,dive,required"`
// WebhookTimeout/WebhookCallbackTTL update the webhook tuning; nil leaves each unchanged.
WebhookTimeout *int `json:"webhook_timeout" validate:"omitempty,min=0,max=15"`
WebhookCallbackTTL *int `json:"webhook_callback_ttl" validate:"omitempty,min=0,max=86400"`
// Revoked toggles revocation. Only a false->true transition is honored; un-revoking is rejected.
Revoked *bool `json:"revoked"`
// Disabled toggles the reversible pause. Both true and false are honored, so a disabled key can
// be re-enabled (unlike Revoked).
Disabled *bool `json:"disabled"`
// ExpiresAt sets a new absolute expiration date (must be in the future). Omitted leaves the
// current expiry unchanged; null makes the key never expire (RFC 7396 semantics).
ExpiresAt OptionalTime `json:"expires_at"`
// UsageLimit sets a new enrollment cap (0 unlimited, 1 single-use, N devices). Nil leaves it
// untouched. Reusability is re-derived from it.
UsageLimit *int `json:"usage_limit" validate:"omitempty,min=0"`
Tags []string `json:"tags" validate:"omitempty,dive,required"`
// Ephemeral toggles whether devices enrolled with the key are auto-removed after staying offline
// past the timeout; nil leaves it unchanged. EphemeralTimeout (1-10 minutes) is only honored when
// Ephemeral is true.
Ephemeral *bool `json:"ephemeral"`
EphemeralTimeout *int `json:"ephemeral_timeout" validate:"omitempty,min=1,max=10"`
}
type UpdateTag ¶ added in v0.21.0
type UpdateTag struct {
TenantID string `param:"tenant" header:"X-Tenant-ID" validate:"required,uuid"`
Name string `param:"name" validate:"required"`
// Similar to [UpdateTag.Name], but is used to update the tag's name instead of retrieve the tag.
NewName string `json:"name" validate:"omitempty,min=3,max=255,alphanum,ascii,excludes=/@&:"`
}
type UpdateUser ¶ added in v0.16.0
type UpdateUser struct {
UserID string `header:"X-ID" validate:"required"`
Name string `json:"name" validate:"omitempty,name"`
Username string `json:"username" validate:"omitempty,username"`
Email string `json:"email" validate:"omitempty,email"`
RecoveryEmail string `json:"recovery_email" validate:"omitempty,email"`
// Password is the new password. If not empty, [UserDataUpdate.CurrentPassword] must be the current user's password.
Password string `json:"password" validate:"omitempty,password"`
CurrentPassword string `json:"current_password"`
}
UpdateUser is the structure to represent the request body of the update user data endpoint.
type UserPasswordUpdate ¶
type UserPasswordUpdate struct {
UserParam
CurrentPassword string `json:"current_password" validate:"required,min=5,max=32,nefield=NewPassword"`
NewPassword string `json:"new_password" validate:"required,password,nefield=CurrentPassword"`
}
UserPasswordUpdate is the structure to represent the request body for the update user password endpoint.
type WebReauthVerify ¶
type WebReauthVerify struct {
TenantID string `json:"-"`
UserID string `json:"-"`
Password string `json:"password"`
Code string `json:"code"`
// Fingerprint is the SSH identity being re-authenticated. Its freshness is
// stamped on that identity's last_reauth_at, and it must belong to the caller.
Fingerprint string `json:"fingerprint" validate:"required"`
// ApprovalCode is the login waiting on this step-up. Present when a held login
// should be released by the same call that proves the factor, so verifying and
// releasing cannot drift apart. Distinct from Code, which is the TOTP.
ApprovalCode string `json:"approval_code"`
}
WebReauthVerify is the step-up payload for an SSH login's require_reauth gate. TenantID/UserID are set server-side from the gateway-injected headers, never the body. Community validates Password; the enterprise overlay validates Code (TOTP) when the user has MFA.