Documentation
¶
Index ¶
- func DB(ctx context.Context) (*sqlx.DB, error)
- func Migrate(ctx context.Context, db *sqlx.DB, schema fs.FS) error
- type PasskeyStorage
- func (s *PasskeyStorage) Create(ctx context.Context, passkey *model.UserPasskey) (*model.UserPasskey, error)
- func (s *PasskeyStorage) Delete(ctx context.Context, id string) error
- func (s *PasskeyStorage) GetByCredentialID(ctx context.Context, credentialID []byte) (*model.UserPasskey, error)
- func (s *PasskeyStorage) ListByUser(ctx context.Context, userID string) ([]model.UserPasskey, error)
- func (s *PasskeyStorage) UpdateSignCount(ctx context.Context, id string, signCount int64) error
- type RevokedTokenStorage
- type SessionStorage
- type UserStorage
- func (s *UserStorage) Activate(ctx context.Context, token string) (*model.User, error)
- func (s *UserStorage) Authenticate(ctx context.Context, userAuth model.UserAuth) (*model.User, error)
- func (s *UserStorage) Create(ctx context.Context, req *model.UserCreateRequest) (*model.User, error)
- func (s *UserStorage) CreatePending(ctx context.Context, req *model.UserCreateRequest) (*model.User, error)
- func (s *UserStorage) Get(ctx context.Context, id string) (*model.User, error)
- func (s *UserStorage) GetByStub(ctx context.Context, slug string) (*model.User, error)
- func (s *UserStorage) GetByUsername(ctx context.Context, username string) (*model.User, error)
- func (s *UserStorage) GetGroups(ctx context.Context, userID string) ([]model.UserGroup, error)
- func (s *UserStorage) IsActivated(ctx context.Context, userID string) (bool, error)
- func (s *UserStorage) List(ctx context.Context) ([]model.User, error)
- func (s *UserStorage) ResetActivation(ctx context.Context, email string) error
- func (s *UserStorage) Update(ctx context.Context, u *model.User) (*model.User, error)
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
Types ¶
type PasskeyStorage ¶
type PasskeyStorage struct {
// contains filtered or unexported fields
}
PasskeyStorage implements passkey persistence using the database.
func NewPasskeyStorage ¶
func NewPasskeyStorage(db *sqlx.DB) *PasskeyStorage
NewPasskeyStorage creates a new PasskeyStorage.
func (*PasskeyStorage) Create ¶
func (s *PasskeyStorage) Create(ctx context.Context, passkey *model.UserPasskey) (*model.UserPasskey, error)
Create inserts a new passkey record.
func (*PasskeyStorage) Delete ¶
func (s *PasskeyStorage) Delete(ctx context.Context, id string) error
Delete removes a passkey by ID.
func (*PasskeyStorage) GetByCredentialID ¶
func (s *PasskeyStorage) GetByCredentialID(ctx context.Context, credentialID []byte) (*model.UserPasskey, error)
GetByCredentialID finds a passkey by its WebAuthn credential ID.
func (*PasskeyStorage) ListByUser ¶
func (s *PasskeyStorage) ListByUser(ctx context.Context, userID string) ([]model.UserPasskey, error)
ListByUser returns all passkeys for a given user.
func (*PasskeyStorage) UpdateSignCount ¶
UpdateSignCount updates the sign count for a passkey.
type RevokedTokenStorage ¶
type RevokedTokenStorage struct {
// contains filtered or unexported fields
}
RevokedTokenStorage records JWT IDs (jti) that have been explicitly revoked before their natural expiry. It is consulted by the auth middleware and the refresh-token endpoint.
func NewRevokedTokenStorage ¶
func NewRevokedTokenStorage(db *sqlx.DB) *RevokedTokenStorage
NewRevokedTokenStorage returns a new RevokedTokenStorage.
func (*RevokedTokenStorage) IsRevoked ¶
IsRevoked reports whether the given jti has been revoked. An empty jti is treated as not revoked so tokens issued before JTI rollout continue to validate.
func (*RevokedTokenStorage) PurgeExpired ¶
func (s *RevokedTokenStorage) PurgeExpired(ctx context.Context) (int64, error)
PurgeExpired deletes revocation rows whose stored exp has already passed. Such rows can be removed because the underlying JWT can no longer validate regardless of revocation state.
func (*RevokedTokenStorage) Revoke ¶
func (s *RevokedTokenStorage) Revoke(ctx context.Context, jti, userID string, expiresAt time.Time) error
Revoke marks the given jti as revoked. expiresAt is the JWT's original `exp` claim and is stored so expired rows can be cleaned up. Calling Revoke on an already-revoked jti is a no-op.
type SessionStorage ¶
type SessionStorage struct {
// contains filtered or unexported fields
}
SessionStorage implements session persistence using MySQL.
func NewSessionStorage ¶
func NewSessionStorage(db *sqlx.DB) *SessionStorage
NewSessionStorage creates a new SessionStorage.
func (*SessionStorage) Create ¶
func (s *SessionStorage) Create(ctx context.Context, userID string) (*model.UserSession, error)
Create inserts a new session for the given userID.
func (*SessionStorage) Delete ¶
func (s *SessionStorage) Delete(ctx context.Context, sessionID string) error
Delete removes a session by sessionID.
func (*SessionStorage) Get ¶
func (s *SessionStorage) Get(ctx context.Context, sessionID string) (*model.UserSession, error)
Get retrieves a session by sessionID. Returns model.ErrSessionExpired if the session has expired.
type UserStorage ¶
type UserStorage struct {
// contains filtered or unexported fields
}
UserStorage implements the model.Storage interface using MySQL via sqlx.
func NewUserStorage ¶
func NewUserStorage(handle *sqlx.DB) *UserStorage
NewUserStorage returns a new UserStorage backed by the given sqlx.DB.
func NewUserStorageErr ¶
func NewUserStorageErr(ctx context.Context) (*UserStorage, error)
NewUserStorageErr returns a user storage and any error creating the database.
func (*UserStorage) Activate ¶
Activate exchanges an activation token for an activated user. The token is single-use: once consumed it is cleared from the row so re-presenting it yields ErrInvalidActivationToken.
func (*UserStorage) Authenticate ¶
func (s *UserStorage) Authenticate(ctx context.Context, userAuth model.UserAuth) (*model.User, error)
Authenticate verifies a user's credentials using bcrypt and returns the user.
func (*UserStorage) Create ¶
func (s *UserStorage) Create(ctx context.Context, req *model.UserCreateRequest) (*model.User, error)
Create inserts a new user and their authentication credentials. Returns an error if authentication information is missing.
func (*UserStorage) CreatePending ¶
func (s *UserStorage) CreatePending(ctx context.Context, req *model.UserCreateRequest) (*model.User, error)
CreatePending behaves like Create but leaves the new user un-activated and assigns an activation token that the caller is expected to deliver to the user (typically by email). The user cannot pass the activation gate (see IsActivated, Activate) until the token is exchanged.
func (*UserStorage) GetByUsername ¶
GetByUsername retrieves a user by their username.
func (*UserStorage) IsActivated ¶
IsActivated reports whether the given user has cleared the email activation gate. Returns true when the user exists and has a non-null activated_at. The pre-feature backfill in user_activation.up.sql means every user created before activation was introduced reads as activated.
func (*UserStorage) ResetActivation ¶
func (s *UserStorage) ResetActivation(ctx context.Context, email string) error
ResetActivation issues a fresh activation token for the user with the given email. Returns the new token. Errors with sql.ErrNoRows if no such user exists, and ErrUserAlreadyActivated if the user has already activated (callers should not resend in that case).