oidc

package module
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 23, 2026 License: Apache-2.0 Imports: 9 Imported by: 0

Documentation

Overview

Package oidc verifies OIDC bearer tokens and projects their already-verified claims into the engine's narrow caller identity.

Index

Constants

This section is empty.

Variables

View Source
var ErrIdentityUnavailable = errors.New("oidc: identity unavailable")

ErrIdentityUnavailable identifies a transient inability to obtain trusted key material from the identity provider.

View Source
var ErrInvalidConfig = errors.New("oidc: invalid configuration")

ErrInvalidConfig identifies configuration that cannot construct a validator. The wrapped error deliberately does not expose ToolHive error types.

View Source
var ErrInvalidToken = errors.New("oidc: invalid token")

ErrInvalidToken identifies a malformed, invalid, or otherwise inadmissible bearer credential.

Functions

This section is empty.

Types

type Config

type Config struct {
	// Issuer is the exact OIDC issuer accepted in the token's iss claim.
	Issuer string
	// JWKSURI pins the signing-key endpoint; empty uses OIDC discovery.
	JWKSURI string
	// Audience is the single service audience accepted in the token's aud claim.
	Audience string
	// AllowAnyAudience permits an empty Audience for resource clients whose
	// authorization server does not bind access tokens to an audience.
	AllowAnyAudience bool
	// MaxJWKSStaleness bounds cached-key use during an identity-provider outage;
	// zero disables the upper bound.
	MaxJWKSStaleness time.Duration
	// InsecureAllowPrivateIssuer permits HTTP and private issuer/JWKS addresses.
	// Deprecated: use AllowPrivateHTTPSIssuer with TrustedCAFile for a private
	// HTTPS issuer. This legacy escape hatch remains for isolated tests that need
	// both HTTP and private-address access.
	InsecureAllowPrivateIssuer bool
	// AllowPrivateHTTPSIssuer permits only the configured issuer and optional
	// JWKS host's resolved private addresses. Its internal scoped transport
	// re-validates addresses on every dial, bounds keep-alives, refuses redirects,
	// and retains HTTPS and TLS hostname verification.
	// TrustedCAFile is required when this mode is enabled.
	AllowPrivateHTTPSIssuer bool
	// TrustedCAFile is the PEM CA bundle path. It is required (non-empty) when
	// AllowPrivateHTTPSIssuer is enabled, and is also passed through to the
	// underlying validator's own default-client CA loading for the legacy
	// InsecureAllowPrivateIssuer path. This package never reads it itself: see
	// TrustedCAPEM.
	TrustedCAFile string
	// TrustedCAPEM is the CA bundle's PEM-encoded bytes, used by
	// AllowPrivateHTTPSIssuer's scoped transport to validate the issuer
	// certificate. The caller is responsible for reading TrustedCAFile from
	// disk; this package must not touch the host filesystem (ADR 0206).
	TrustedCAPEM []byte
	// HTTPClient optionally supplies trusted roots and transport policy. Nil uses
	// the validator's hardened client. When set, the caller is responsible for
	// preserving equivalent redirect and private-address protections.
	HTTPClient *http.Client
}

Config is the trusted issuer, audience, and key-fetch policy for a Validator.

type Validator

type Validator struct {
	// contains filtered or unexported fields
}

Validator owns token verification and its background JWKS refresh. Call Close when it is no longer needed.

func NewValidator

func NewValidator(ctx context.Context, cfg Config) (*Validator, error)

NewValidator constructs a fail-closed OIDC validator. Issuer must be non-empty; Audience must also be non-empty unless AllowAnyAudience is explicitly enabled. Secure issuer/JWKS transport remains enabled.

func (*Validator) Close

func (v *Validator) Close() error

Close stops background JWKS refresh.

func (*Validator) Validate

func (v *Validator) Validate(ctx context.Context, bearer string) (*session.Principal, error)

Validate verifies bearer and returns its caller identity. A successfully verified claim set without a usable issuer and subject is rejected.

Directories

Path Synopsis
Package scopedhttps constructs HTTPS clients confined to explicitly approved private-network endpoints.
Package scopedhttps constructs HTTPS clients confined to explicitly approved private-network endpoints.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL