Documentation
¶
Overview ¶
Package forges fetches public SSH keys from code-hosting platforms other than GitHub and produces SHA-256 fingerprints for cross-platform identity matching. v1 covers GitLab, Codeberg, and Sourcehut — the forges that publish keys at well-known unauthenticated endpoints.
Bitbucket is intentionally out of scope: it has no public `.keys` endpoint as of this implementation. Adding it would require either API authentication or HTML scraping, both of which are higher-cost than the cryptographic signal warrants for v1.
GPG fingerprint matching is also deferred. The `.gpg` endpoints exist on most forges but parsing OpenPGP packets requires a heavier library; SSH fingerprints alone produce the same T1 confidence signal for the (much larger) population of contributors who use SSH for git operations.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ErrNotFound = errors.New("forges: user not found")
ErrNotFound indicates the forge has no user with the requested handle (404, or 302 redirect to login on GitLab when the user doesn't exist). Distinguishes "user genuinely absent" from a transport error so callers can cache the empty result.
Functions ¶
func ProfileURL ¶
ProfileURL returns the human-facing profile URL for the given forge and username. Used by the UI to link out to the matched forge profile.
Types ¶
type Client ¶
type Client struct {
// contains filtered or unexported fields
}
Client fetches public keys from the supported forges.
func NewClient ¶
NewClient returns a Client with the given timeout. A zero or negative timeout falls back to a sane default.
func (*Client) FetchSSHFingerprints ¶
func (c *Client) FetchSSHFingerprints(ctx context.Context, forge Forge, username string) ([]string, error)
FetchSSHFingerprints returns the SHA-256 fingerprints of every public SSH key the user has published on the given forge. Each fingerprint is OpenSSH-formatted: "SHA256:<base64-no-padding>".
Returns ErrNotFound on 404 or any 3xx response (see CheckRedirect note in NewClient). Empty result with nil error means the user exists but has published no keys — a real and meaningful state.
type Forge ¶
type Forge string
Forge identifies a supported code-hosting platform. The constants double as JSON tags surfaced in the API response and as label strings in the UI; keep them stable across releases.
func SupportedForges ¶
func SupportedForges() []Forge
SupportedForges returns the non-GitHub forges the cross-VCS matcher walks. GitHub is the anchor (we always fetch its keys to compare against), so it is excluded from this list.