authn

package
v1.2.6 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 19, 2026 License: Apache-2.0 Imports: 11 Imported by: 0

Documentation

Overview

Package authn contains bounded security primitives shared by contrib authentication protocols. Protocol-specific algorithm and key policy does not belong in this package.

Index

Constants

View Source
const MaxEncodedSecretBytes = ((MaxSecretBytes + 2) / 3) * 4

MaxEncodedSecretBytes is the largest unpadded Base64url representation of MaxSecretBytes.

View Source
const MaxSecretBytes = 1024

Variables

View Source
var (
	ErrInvalidSize     = errors.New("authn: invalid size")
	ErrInvalidEncoding = errors.New("authn: invalid encoding")
	ErrLimitExceeded   = errors.New("authn: limit exceeded")
	ErrExpired         = errors.New("authn: value expired")
	ErrInvalidVerifier = errors.New("authn: invalid PKCE verifier")
)
View Source
var (
	ErrMalformedJSON = errors.New("authn: malformed JSON")
	ErrDuplicateJSON = errors.New("authn: duplicate JSON member")
)

Functions

func DecodeBase64URL

func DecodeBase64URL(value string, maxEncodedBytes, maxDecodedBytes int) ([]byte, error)

DecodeBase64URL strictly decodes canonical, unpadded Base64url.

func EqualSecret

func EqualSecret(left, right string) bool

EqualSecret compares two bounded secrets without leaking their contents. Authentication protocols should generate fixed-length values.

func GeneratePKCEVerifier

func GeneratePKCEVerifier(random io.Reader) (string, error)

GeneratePKCEVerifier returns a 43-character verifier with 256 random bits.

func GenerateSecret

func GenerateSecret(random io.Reader, byteCount int) (string, error)

GenerateSecret returns an unpadded Base64url value containing exactly byteCount bytes of cryptographic randomness.

func PKCEChallengeS256

func PKCEChallengeS256(verifier string) (string, error)

func RequireUnexpired

func RequireUnexpired(now, expiresAt time.Time) error

func ValidateJSON

func ValidateJSON(data []byte, options JSONOptions) error

ValidateJSON validates exactly one JSON value and rejects duplicate object members at every nesting level.

func ValidatePKCEVerifier

func ValidatePKCEVerifier(verifier string) error

Types

type JSONOptions

type JSONOptions struct {
	MaxBytes   int
	MaxDepth   int
	MaxMembers int
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL