authority

package
v0.3.5 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 11, 2026 License: MIT Imports: 12 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Module

type Module struct {
	// contains filtered or unexported fields
}

Module is the user/auth/rbac handle. All backend operations are methods on this type. Created exclusively via New().

func New

func New(db *orm.DB, cfg user.Config) (*Module, error)

New initializes the schema, warms the session cache, and wires the default session strategy (an opaque cookie over this Module's own session table). Call SetStrategy/Enable afterward to customize.

func (*Module) Add

func (m *Module) Add() []any

Add returns all admin-managed CRUDP handlers for registration. Usage: cp.RegisterHandlers(m.Add()...)

func (*Module) AssignLANIP

func (m *Module) AssignLANIP(userID, ip, label string) error

func (*Module) AssignPermission

func (m *Module) AssignPermission(roleID, permissionID string) error

func (*Module) AssignRole

func (m *Module) AssignRole(userID, roleID string) error

func (*Module) Authenticate

func (m *Module) Authenticate() router.Middleware

Authenticate returns a router.Middleware that asks the active SessionStrategy to identify the caller. If valid, sets UserId in the context via ctx.SetUserID(id). If invalid, UserId remains empty (anonymous).

func (*Module) Bootstrap

func (m *Module) Bootstrap(s Seed) error

Bootstrap seeds the first user and their initial permissions. NO-OP if the users table is already populated. It does not invent roles or wildcards: it only persists what the Seed declares.

func (*Module) Can

func (m *Module) Can(userID string, resource model.Resource, action model.Action) bool

Can checks if the userID has permission for the resource/action, notifying on failure — unchanged from before.

func (*Module) ConsumeState added in v0.2.0

func (m *Module) ConsumeState(state, provider string) error

func (*Module) CreatePermission

func (m *Module) CreatePermission(id, name string, resource model.Resource, action model.Action) error

func (*Module) CreateRole

func (m *Module) CreateRole(id string, code model.RoleCode, name, description string) error

func (*Module) CreateSession

func (m *Module) CreateSession(userID, ip, userAgent string) (user.Session, error)

func (*Module) CreateState added in v0.2.0

func (m *Module) CreateState(provider string) (string, error)

func (*Module) CreateUser added in v0.2.0

func (m *Module) CreateUser(email, name, phone string) (user.User, error)

func (*Module) DeletePermission

func (m *Module) DeletePermission(id string) error

func (*Module) DeleteRole

func (m *Module) DeleteRole(id string) error

func (*Module) DeleteSession

func (m *Module) DeleteSession(id string) error

func (*Module) Enable added in v0.2.0

func (m *Module) Enable(auths ...user.Authenticator)

Enable registers the authentication modes this app supports — 1 or N. authority never constructs a mode itself: the consumer builds each one (injecting whichever ports of m it needs) and hands it here.

func (*Module) GetLANIPs

func (m *Module) GetLANIPs(userID string) ([]user.LANIP, error)

func (*Module) GetPermission

func (m *Module) GetPermission(id string) (*user.Permission, error)

func (*Module) GetRole

func (m *Module) GetRole(id string) (*user.Role, error)

func (*Module) GetRoleByCode

func (m *Module) GetRoleByCode(code model.RoleCode) (*user.Role, error)

func (*Module) GetSession

func (m *Module) GetSession(id string) (user.Session, error)

func (*Module) GetUser

func (m *Module) GetUser(id string) (user.User, error)

func (*Module) GetUserByEmail

func (m *Module) GetUserByEmail(email string) (user.User, error)

func (*Module) GetUserIdentities

func (m *Module) GetUserIdentities(userID string) ([]user.Identity, error)

func (*Module) GetUserRoles

func (m *Module) GetUserRoles(userID string) ([]user.Role, error)

func (*Module) HasPermission

func (m *Module) HasPermission(userID string, resource model.Resource, action model.Action) (bool, error)

func (*Module) IdentityByProvider added in v0.2.0

func (m *Module) IdentityByProvider(provider, providerID string) (user.Identity, error)

func (*Module) IdentityFor added in v0.2.0

func (m *Module) IdentityFor(userID, provider string) (user.Identity, error)

func (*Module) IsTrustedIP added in v0.2.0

func (m *Module) IsTrustedIP(userID, ip string) bool

func (*Module) IssueSession added in v0.2.0

func (m *Module) IssueSession(ctx router.Context, userID string) error

func (*Module) Login

func (m *Module) Login(email, password string) (user.User, error)

Login verifies email+password directly (no HTTP) — used by email_password/credentials tests and any admin flow that needs to verify a user's password without going through the mounted route.

func (*Module) LoginLAN

func (m *Module) LoginLAN(rut string, ctx router.Context) (user.User, error)

LoginLAN verifies a RUT + the caller's IP directly (no HTTP) — used by tests and any admin flow. Mirrors exactly what trusted_ip's Mount handler does, using the same ValidateRUT algorithm — see §7's doc comment on ValidateRUT.

func (*Module) ModelName

func (m *Module) ModelName() string

func (*Module) MountAPI

func (m *Module) MountAPI(r router.Router)

MountAPI mounts the one session-termination endpoint centrally — logout ends a session the same way no matter which mode started it (strategy.Revoke) — then lets every enabled Authenticator mount its own login route. authority never inspects what a mode mounts.

func (*Module) MountOps added in v0.1.0

func (m *Module) MountOps(reg router.OpRegistry)

func (*Module) Notify added in v0.1.0

func (m *Module) Notify(e user.SecurityEvent)

func (*Module) PurgeExpiredOAuthStates

func (m *Module) PurgeExpiredOAuthStates() error

PurgeExpiredOAuthStates is maintenance, not part of any port — call it periodically from a cron-like task in the consuming app.

func (*Module) PurgeExpiredSessions

func (m *Module) PurgeExpiredSessions() error

func (*Module) PurgeSessionsByUser

func (m *Module) PurgeSessionsByUser(userID string) error

PurgeSessionsByUser deletes all sessions belonging to userID from cache and DB.

func (*Module) ReactivateUser

func (m *Module) ReactivateUser(id string) error

ReactivateUser sets Status = "active". Evicts user from cache.

func (*Module) Register

func (m *Module) Register(handlers ...RBACObject) error

func (*Module) RegisterLAN

func (m *Module) RegisterLAN(userID, rut string) error

RegisterLAN links a RUT to userID as their trusted_ip identity.

func (*Module) RevokeLANIP

func (m *Module) RevokeLANIP(userID, ip string) error

func (*Module) RevokeRole

func (m *Module) RevokeRole(userID, roleID string) error

func (*Module) RotateSession

func (m *Module) RotateSession(oldID, ip, userAgent string) (user.Session, error)

RotateSession atomically deletes the old session and creates a new one with the same userID, updated IP/UserAgent, and a fresh TTL. Prevents session fixation attacks when called post-login.

func (*Module) SetLog

func (m *Module) SetLog(fn func(...any))

SetLog configures optional logging. Call immediately after New(). Default: no-op.

func (*Module) SetPassword

func (m *Module) SetPassword(userID, password string) error

SetPassword hashes and stores password as userID's email_password credential.

func (*Module) SetStrategy added in v0.2.0

func (m *Module) SetStrategy(s user.SessionStrategy)

SetStrategy overrides how sessions are carried. Call before mounting. A nil argument is ignored — the default set by New is already production-ready; this exists to opt into session/jwt or a custom strategy, never to unset it.

func (*Module) SuspendUser

func (m *Module) SuspendUser(id string) error

SuspendUser sets Status = "suspended". Evicts user from cache.

func (*Module) UnlinkIdentity

func (m *Module) UnlinkIdentity(userID, provider string) error

func (*Module) UnregisterLAN

func (m *Module) UnregisterLAN(userID string) error

UnregisterLAN removes userID's trusted_ip identity and all their allowed IPs.

func (*Module) UpdateUserAvatar added in v0.3.0

func (m *Module) UpdateUserAvatar(userID, avatar string) error

func (*Module) UpsertIdentity added in v0.2.0

func (m *Module) UpsertIdentity(userID, provider, providerID, email string) error

func (*Module) UserByEmail added in v0.2.0

func (m *Module) UserByEmail(email string) (user.User, error)

func (*Module) UserByID added in v0.2.0

func (m *Module) UserByID(id string) (user.User, error)

func (*Module) VerifyPassword

func (m *Module) VerifyPassword(userID, password string) error

VerifyPassword checks password against userID's stored email_password hash.

type RBACObject

type RBACObject interface {
	HandlerName() string
	AllowedRoles(action model.Action) []model.RoleCode
}

type Seed

type Seed struct {
	Email    string
	Password string
	Name     string
	Role     model.RoleCode
	Grants   []model.Grant
}

Seed is the INITIAL security policy of the app: declared by the consumer. This library only persists it with hashing and invariants.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL