authn

package
v1.3.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 29, 2026 License: Apache-2.0 Imports: 7 Imported by: 0

Documentation

Overview

Package authn contains the bounded parsing primitives the jwt package shares. Protocol-specific algorithm and key policy does not belong in this package.

Index

Constants

This section is empty.

Variables

View Source
var (
	ErrInvalidSize     = errors.New("authn: invalid size")
	ErrInvalidEncoding = errors.New("authn: invalid encoding")
	ErrLimitExceeded   = errors.New("authn: limit exceeded")
)
View Source
var (
	ErrMalformedJSON = errors.New("authn: malformed JSON")
	ErrDuplicateJSON = errors.New("authn: duplicate JSON member")
)

Functions

func DecodeBase64URL

func DecodeBase64URL(value string, maxEncodedBytes, maxDecodedBytes int) ([]byte, error)

DecodeBase64URL strictly decodes canonical, unpadded Base64url.

Canonicality used to be checked by re-encoding the result and comparing, which copied every segment twice more. DecodeString already rejects padding, wrong lengths, and bytes outside the alphabet, with two exceptions this function closes itself: it skips \r and \n instead of failing, and it accepts a final quantum whose unused low bits are not zero. The exhaustive test in this package holds the sum of these checks equal to the re-encoding oracle.

func ValidateJSON

func ValidateJSON(data []byte, options JSONOptions) error

ValidateJSON validates exactly one JSON value and rejects duplicate object members at every nesting level.

Types

type JSONOptions

type JSONOptions struct {
	MaxBytes   int
	MaxDepth   int
	MaxMembers int
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL