Documentation
¶
Overview ¶
Package oidc verifies OIDC bearer tokens and projects their already-verified claims into the engine's narrow caller identity.
Index ¶
Constants ¶
This section is empty.
Variables ¶
ErrIdentityUnavailable identifies a transient inability to obtain trusted key material from the identity provider.
var ErrInvalidConfig = errors.New("oidc: invalid configuration")
ErrInvalidConfig identifies configuration that cannot construct a validator. The wrapped error deliberately does not expose ToolHive error types.
var ErrInvalidToken = errors.New("oidc: invalid token")
ErrInvalidToken identifies a malformed, invalid, or otherwise inadmissible bearer credential.
Functions ¶
This section is empty.
Types ¶
type Config ¶
type Config struct {
// Issuer is the exact OIDC issuer accepted in the token's iss claim.
Issuer string
// JWKSURI pins the signing-key endpoint; empty uses OIDC discovery.
JWKSURI string
// Audience is the single service audience accepted in the token's aud claim.
Audience string
// AllowAnyAudience permits an empty Audience for resource clients whose
// authorization server does not bind access tokens to an audience.
AllowAnyAudience bool
// MaxJWKSStaleness bounds cached-key use during an identity-provider outage;
// zero disables the upper bound.
MaxJWKSStaleness time.Duration
// InsecureAllowPrivateIssuer permits HTTP and private issuer/JWKS addresses.
// Deprecated: use AllowPrivateHTTPSIssuer with TrustedCAFile for a private
// HTTPS issuer. This legacy escape hatch remains for isolated tests that need
// both HTTP and private-address access.
InsecureAllowPrivateIssuer bool
// AllowPrivateHTTPSIssuer permits only the configured issuer and optional
// JWKS host's resolved private addresses. Its internal scoped transport
// re-validates addresses on every dial, bounds keep-alives, refuses redirects,
// and retains HTTPS and TLS hostname verification.
// TrustedCAFile is required when this mode is enabled.
AllowPrivateHTTPSIssuer bool
// TrustedCAFile is the PEM CA bundle path. It is required (non-empty) when
// AllowPrivateHTTPSIssuer is enabled, and is also passed through to the
// underlying validator's own default-client CA loading for the legacy
// InsecureAllowPrivateIssuer path. This package never reads it itself: see
// TrustedCAPEM.
TrustedCAFile string
// TrustedCAPEM is the CA bundle's PEM-encoded bytes, used by
// AllowPrivateHTTPSIssuer's scoped transport to validate the issuer
// certificate. The caller is responsible for reading TrustedCAFile from
// disk; this package must not touch the host filesystem (ADR 0206).
TrustedCAPEM []byte
// HTTPClient optionally supplies trusted roots and transport policy. Nil uses
// the validator's hardened client. When set, the caller is responsible for
// preserving equivalent redirect and private-address protections.
HTTPClient *http.Client
}
Config is the trusted issuer, audience, and key-fetch policy for a Validator.
type Validator ¶
type Validator struct {
// contains filtered or unexported fields
}
Validator owns token verification and its background JWKS refresh. Call Close when it is no longer needed.
func NewValidator ¶
NewValidator constructs a fail-closed OIDC validator. Issuer must be non-empty; Audience must also be non-empty unless AllowAnyAudience is explicitly enabled. Secure issuer/JWKS transport remains enabled.
Directories
¶
| Path | Synopsis |
|---|---|
|
Package scopedhttps constructs HTTPS clients confined to explicitly approved private-network endpoints.
|
Package scopedhttps constructs HTTPS clients confined to explicitly approved private-network endpoints. |