middleware

package
v0.51.54 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: May 4, 2026 License: Apache-2.0 Imports: 12 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func AdminAuditLog added in v0.50.0

func AdminAuditLog(ctx context.Context, action, path, remoteAddr, detail string)

AdminAuditLog logs an admin action with structured fields.

func ClearSessionCookie

func ClearSessionCookie(w http.ResponseWriter)

ClearSessionCookie removes the session cookie.

func GenerateCSRFToken added in v0.50.0

func GenerateCSRFToken() string

GenerateCSRFToken produces a 32-byte random token encoded as base64url.

func IsAdmin added in v0.50.0

func IsAdmin(username string) bool

IsAdmin checks whether username is in the DEVPULSE_ADMIN_USERS env var (comma-separated, whitespace-trimmed). Comparison is case-insensitive because GitHub usernames are case-insensitive.

func IsSecure added in v0.51.3

func IsSecure() bool

IsSecure returns true when the BASE_URL uses HTTPS.

func OAuthStateCookieName added in v0.51.3

func OAuthStateCookieName() string

OAuthStateCookieName returns the OAuth state cookie name, using the __Host- prefix in HTTPS mode for consistency with the session cookie.

func Recovery added in v0.41.0

func Recovery(next http.Handler) http.Handler

Recovery returns middleware that recovers from panics, logs the stack trace, and returns HTTP 500 to the client instead of crashing the server.

func RequireAdmin added in v0.50.0

func RequireAdmin(db *sql.DB) func(http.Handler) http.Handler

RequireAdmin validates the session cookie and checks the username against the DEVPULSE_ADMIN_USERS whitelist. Returns 404 (not 403) to hide route existence from non-admins.

func RequireAuth

func RequireAuth(db *sql.DB, loginURL string) func(http.Handler) http.Handler

RequireAuth validates the session cookie and injects the tenant into context. Redirects to loginURL if no valid session is found.

func SessionCookieName

func SessionCookieName() string

SessionCookieName returns the session cookie name based on the BASE_URL scheme.

func SetCSRFCookie added in v0.51.3

func SetCSRFCookie(w http.ResponseWriter, token string)

SetCSRFCookie writes the CSRF token cookie for the double-submit pattern. The form value is injected server-side into a hidden field.

func SetSessionCookie

func SetSessionCookie(w http.ResponseWriter, token string, maxAge int)

SetSessionCookie sets the session cookie with security attributes.

func TenantFromContext

func TenantFromContext(ctx context.Context) *tenant.Tenant

TenantFromContext extracts the tenant from the request context.

func ValidateCSRF added in v0.50.0

func ValidateCSRF(expected, actual string) bool

ValidateCSRF performs constant-time comparison of CSRF tokens. Returns false if either string is empty.

func ValidateCSRFFromRequest added in v0.51.3

func ValidateCSRFFromRequest(r *http.Request) bool

ValidateCSRFFromRequest compares the csrf_token form field against the csrf_token cookie (double-submit pattern). Returns true if they match.

func WithTenantContext added in v0.26.2

func WithTenantContext(ctx context.Context, tn *tenant.Tenant) context.Context

WithTenantContext injects a tenant into the context. Intended for tests.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL