Documentation
¶
Overview ¶
Package authn contains bounded security primitives shared by contrib authentication protocols. Protocol-specific algorithm and key policy does not belong in this package.
Index ¶
- Constants
- Variables
- func DecodeBase64URL(value string, maxEncodedBytes, maxDecodedBytes int) ([]byte, error)
- func EqualSecret(left, right string) bool
- func GeneratePKCEVerifier(random io.Reader) (string, error)
- func GenerateSecret(random io.Reader, byteCount int) (string, error)
- func PKCEChallengeS256(verifier string) (string, error)
- func RequireUnexpired(now, expiresAt time.Time) error
- func ValidateJSON(data []byte, options JSONOptions) error
- func ValidatePKCEVerifier(verifier string) error
- type JSONOptions
Constants ¶
const MaxEncodedSecretBytes = ((MaxSecretBytes + 2) / 3) * 4
MaxEncodedSecretBytes is the largest unpadded Base64url representation of MaxSecretBytes.
const MaxSecretBytes = 1024
Variables ¶
var ( ErrInvalidSize = errors.New("authn: invalid size") ErrInvalidEncoding = errors.New("authn: invalid encoding") ErrLimitExceeded = errors.New("authn: limit exceeded") ErrExpired = errors.New("authn: value expired") ErrInvalidVerifier = errors.New("authn: invalid PKCE verifier") )
var ( ErrMalformedJSON = errors.New("authn: malformed JSON") ErrDuplicateJSON = errors.New("authn: duplicate JSON member") )
Functions ¶
func DecodeBase64URL ¶
DecodeBase64URL strictly decodes canonical, unpadded Base64url.
func EqualSecret ¶
EqualSecret compares two bounded secrets without leaking their contents. Authentication protocols should generate fixed-length values.
func GeneratePKCEVerifier ¶
GeneratePKCEVerifier returns a 43-character verifier with 256 random bits.
func GenerateSecret ¶
GenerateSecret returns an unpadded Base64url value containing exactly byteCount bytes of cryptographic randomness.
func PKCEChallengeS256 ¶
func RequireUnexpired ¶
func ValidateJSON ¶
func ValidateJSON(data []byte, options JSONOptions) error
ValidateJSON validates exactly one JSON value and rejects duplicate object members at every nesting level.