Documentation
¶
Index ¶
- func CSRFCookieName() string
- func CSRFTokenFromContext(ctx context.Context) string
- func CSRFTokenFromRequest(r *http.Request) string
- func ClearSessionCookie(w http.ResponseWriter)
- func GenerateCSRFToken() (string, error)
- func InjectCSRF(next http.Handler) http.Handler
- func IsAdmin(username string) bool
- func IsSecure() bool
- func RequireAPIToken(db *sql.DB) func(http.Handler) http.Handler
- func RequireAdmin(db *sql.DB) func(http.Handler) http.Handler
- func RequireAnyAuth(db *sql.DB) func(http.Handler) http.Handler
- func RequireAuth(db *sql.DB, loginURL string) func(http.Handler) http.Handler
- func SessionCookieName() string
- func SetCSRFCookie(w http.ResponseWriter, token, path string)
- func SetSessionCookie(w http.ResponseWriter, token string, maxAge int)
- func TenantFromContext(ctx context.Context) *tenant.Tenant
- func ValidateCSRF(next http.Handler) http.Handler
- func WithTenantContext(ctx context.Context, tn *tenant.Tenant) context.Context
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func CSRFCookieName ¶
func CSRFCookieName() string
CSRFCookieName returns the CSRF cookie name for the current environment.
func CSRFTokenFromContext ¶
CSRFTokenFromContext returns the CSRF token stored by InjectCSRF middleware.
func CSRFTokenFromRequest ¶
CSRFTokenFromRequest reads the CSRF token from the cookie.
func ClearSessionCookie ¶
func ClearSessionCookie(w http.ResponseWriter)
func GenerateCSRFToken ¶
GenerateCSRFToken returns a cryptographically random hex-encoded token.
func InjectCSRF ¶
InjectCSRF ensures a CSRF token cookie exists at Path="/" and stores it in the request context. Apply to all authenticated GET routes so that POST forms (sign-out, TOS accept, etc.) have a valid token. Client-side JS reads the cookie and injects hidden csrf_token fields.
Reuses an existing valid cookie rather than regenerating on every GET. Regeneration would invalidate any form rendered by an earlier page-load: a form rendered with token T1 stays in the DOM, while a subsequent GET in another tab rotates the cookie to T2; submitting the now-stale form fails with a token mismatch. Reuse keeps tokens stable for the session and matches the standard double-submit pattern (security comes from SameSite=Strict, not rotation).
func IsSecure ¶
func IsSecure() bool
IsSecure returns true when the deployment uses HTTPS (derived from BASE_URL).
func RequireAPIToken ¶
RequireAPIToken validates Authorization: Bearer header. For API routes. Returns 401 JSON on failure.
func RequireAdmin ¶
RequireAdmin validates the session and checks the admin user list. Returns 404 for unauthenticated users and non-admins (hides route existence).
func RequireAnyAuth ¶
RequireAnyAuth tries API token first, then session cookie. If neither is present, allows through as unauthenticated (tenant will be nil in context). The handler checks TenantFromContext and adjusts response accordingly.
func RequireAuth ¶
RequireAuth validates session cookie, redirects to loginURL on failure. For UI routes.
func SessionCookieName ¶
func SessionCookieName() string
func SetCSRFCookie ¶
func SetCSRFCookie(w http.ResponseWriter, token, path string)
SetCSRFCookie writes the CSRF token cookie to the response. The path parameter scopes the cookie to the given URL prefix (e.g. "/admin", "/").
HttpOnly is intentionally false — the double-submit CSRF pattern requires JavaScript to read the cookie value to inject it as a hidden form field. SameSite=Strict provides the security boundary instead of HttpOnly.
func SetSessionCookie ¶
func SetSessionCookie(w http.ResponseWriter, token string, maxAge int)
func ValidateCSRF ¶
ValidateCSRF is middleware that rejects POST requests where the form field csrf_token does not match the csrf cookie (double-submit cookie pattern). GET/HEAD/OPTIONS requests pass through unchanged.
Types ¶
This section is empty.