Documentation
¶
Index ¶
- Constants
- type APIError
- type BackupCodesResponse
- type CreateOIDCProviderRequest
- type CreateRoleRequest
- type CreateUserRequest
- type CreateUserResponse
- type DeleteOIDCProviderRequest
- type DeleteRoleRequest
- type DirectPermission
- type DirectPermissionsResponse
- type DisableMFARequest
- type EffectivePermission
- type EnableMFARequest
- type ErrorResponse
- type ForgotPasswordRequest
- type ForgotPasswordResponse
- type GRPCClient
- type GRPCClientOption
- type GetDirectPermissionsRequest
- type GetOIDCProviderRequest
- type GetRolePermissionsRequest
- type GetRoleRequest
- type GetUserRolesRequest
- type HTTPClient
- func (c *HTTPClient) CreateOIDCProvider(ctx context.Context, req CreateOIDCProviderRequest) (*OIDCProvider, error)
- func (c *HTTPClient) CreateRole(ctx context.Context, req CreateRoleRequest) (*Role, error)
- func (c *HTTPClient) CreateUser(ctx context.Context, req CreateUserRequest) (*CreateUserResponse, error)
- func (c *HTTPClient) DeleteOIDCProvider(ctx context.Context, req DeleteOIDCProviderRequest) error
- func (c *HTTPClient) DeleteRole(ctx context.Context, req DeleteRoleRequest) error
- func (c *HTTPClient) DisableMFA(ctx context.Context, req DisableMFARequest) error
- func (c *HTTPClient) EnableMFA(ctx context.Context, req EnableMFARequest) error
- func (c *HTTPClient) ForgotPassword(ctx context.Context, req ForgotPasswordRequest) (*ForgotPasswordResponse, error)
- func (c *HTTPClient) GetDirectPermissions(ctx context.Context, req GetDirectPermissionsRequest) (*DirectPermissionsResponse, error)
- func (c *HTTPClient) GetMFAStatus(ctx context.Context) (*MFAStatus, error)
- func (c *HTTPClient) GetMe(ctx context.Context) (*User, error)
- func (c *HTTPClient) GetOIDCProvider(ctx context.Context, req GetOIDCProviderRequest) (*OIDCProvider, error)
- func (c *HTTPClient) GetRole(ctx context.Context, req GetRoleRequest) (*Role, error)
- func (c *HTTPClient) GetRolePermissions(ctx context.Context, req GetRolePermissionsRequest) (*PermissionsResponse, error)
- func (c *HTTPClient) GetUserRoles(ctx context.Context, req GetUserRolesRequest) (*RolesResponse, error)
- func (c *HTTPClient) Health(ctx context.Context) error
- func (c *HTTPClient) ListOIDCProviders(ctx context.Context) (*OIDCProvidersResponse, error)
- func (c *HTTPClient) ListPermissions(ctx context.Context) (*PermissionsResponse, error)
- func (c *HTTPClient) ListRoles(ctx context.Context) (*RolesResponse, error)
- func (c *HTTPClient) ListSessions(ctx context.Context) (*SessionsResponse, error)
- func (c *HTTPClient) ListSupportedProviders(ctx context.Context) (*OIDCProviderTypesResponse, error)
- func (c *HTTPClient) Login(ctx context.Context, req LoginRequest) (*LoginResponse, error)
- func (c *HTTPClient) Logout(ctx context.Context) (*LogoutResponse, error)
- func (c *HTTPClient) OAuthLogin(ctx context.Context, req OIDCLoginRequest) (*OIDCAuthResponse, error)
- func (c *HTTPClient) RefreshToken(ctx context.Context) (*LoginResponse, error)
- func (c *HTTPClient) RegenerateBackupCodes(ctx context.Context, req RegenerateBackupCodesRequest) (*BackupCodesResponse, error)
- func (c *HTTPClient) Register(ctx context.Context, req RegisterRequest) (*RegisterResponse, error)
- func (c *HTTPClient) RequiredMFAEnable(ctx context.Context, req RequiredMFAEnableRequest) (*LoginResponse, error)
- func (c *HTTPClient) RequiredMFASetup(ctx context.Context, req RequiredMFASetupRequest) (*MFASetupResponse, error)
- func (c *HTTPClient) ResetPassword(ctx context.Context, req ResetPasswordRequest) (*ResetPasswordResponse, error)
- func (c *HTTPClient) RevokeAllSessions(ctx context.Context) error
- func (c *HTTPClient) RevokeSession(ctx context.Context, req RevokeSessionRequest) error
- func (c *HTTPClient) SSOLogin(ctx context.Context, req SSOLoginRequest) (*OIDCAuthResponse, error)
- func (c *HTTPClient) SetDirectPermissions(ctx context.Context, req SetDirectPermissionsRequest) error
- func (c *HTTPClient) SetRolePermissions(ctx context.Context, req SetRolePermissionsRequest) error
- func (c *HTTPClient) SetUserRoles(ctx context.Context, req SetUserRolesRequest) error
- func (c *HTTPClient) SetupMFA(ctx context.Context) (*MFASetupResponse, error)
- func (c *HTTPClient) UpdateOIDCProvider(ctx context.Context, req UpdateOIDCProviderRequest) (*OIDCProvider, error)
- func (c *HTTPClient) UpdateRole(ctx context.Context, req UpdateRoleRequest) (*Role, error)
- func (c *HTTPClient) VerifyEmail(ctx context.Context, req VerifyEmailRequest) (*LoginResponse, error)
- func (c *HTTPClient) VerifyMFACode(ctx context.Context, req VerifyMFACodeRequest) (*LoginResponse, error)
- type HealthResponse
- type LoginRequest
- type LoginResponse
- type LogoutResponse
- type MFASetupResponse
- type MFAStatus
- type OIDCAuthResponse
- type OIDCLoginRequest
- type OIDCProvider
- type OIDCProviderType
- type OIDCProviderTypeInfo
- type OIDCProviderTypesResponse
- type OIDCProvidersResponse
- type OIDCRegistrationMethod
- type Option
- type Permission
- type PermissionEffect
- type PermissionsResponse
- type RegenerateBackupCodesRequest
- type RegisterRequest
- type RegisterResponse
- type RequiredMFAEnableRequest
- type RequiredMFASetupRequest
- type ResetPasswordRequest
- type ResetPasswordResponse
- type RevokeSessionRequest
- type Role
- type RolesResponse
- type SSOLoginRequest
- type Session
- type SessionsResponse
- type SetDirectPermissionsRequest
- type SetRolePermissionsRequest
- type SetUserRolesRequest
- type UpdateOIDCProviderRequest
- type UpdateRoleRequest
- type User
- type VerifyEmailRequest
- type VerifyMFACodeRequest
Constants ¶
const ( // Not /healthz: Cloud Run answers that path itself and never forwards it to us. RouteHealth = "/health" // Authentication endpoints RouteV1Login = "/v1/login" RouteV1Refresh = "/v1/refresh" RouteV1Register = "/v1/register" RouteV1VerifyEmail = "/v1/verify-email" RouteV1ForgotPassword = "/v1/forgot-password" RouteV1ResetPassword = "/v1/reset-password" // OAuth/SSO endpoints RouteV1OAuthLogin = "/v1/oauth/login" // Individual OAuth (Google, GitHub, etc.) RouteV1SSOLogin = "/v1/sso/login" // Corporate SSO (domain-based routing) RouteV1OAuthCallback = "/v1/oauth/callback" // OAuth callback handler // OAuth provider configuration (authenticated) RouteV1OAuthProviders = "/v1/oauth/providers" RouteV1OAuthProvider = "/v1/oauth/providers/{providerID}" RouteV1OAuthSupportedTypes = "/v1/oauth/supported-types" // Public endpoint // RBAC endpoints (authenticated) RouteV1Permissions = "/v1/permissions" // List all system permissions // Role management RouteV1Roles = "/v1/roles" RouteV1Role = "/v1/roles/{roleID}" // Role permissions RouteV1RolePermissions = "/v1/roles/{roleID}/permissions" RouteV1RolePermission = "/v1/roles/{roleID}/permissions/{permissionID}" // User endpoints RouteV1Users = "/v1/users" RouteV1Me = "/v1/users/me" // User roles RouteV1UserRoles = "/v1/users/{userID}/roles" RouteV1UserRole = "/v1/users/{userID}/roles/{roleID}" // User direct permissions RouteV1UserPermissions = "/v1/users/{userID}/permissions" RouteV1UserPermission = "/v1/users/{userID}/permissions/{permissionID}" // MFA endpoints RouteV1MFASetup = "/v1/mfa/setup" // Start MFA setup (authenticated) RouteV1MFAEnable = "/v1/mfa/enable" // Verify and enable MFA (authenticated) RouteV1MFAVerify = "/v1/mfa/verify" // Verify MFA code during login RouteV1MFADisable = "/v1/mfa/disable" // Disable MFA (authenticated) RouteV1MFAStatus = "/v1/mfa/status" // Get MFA status (authenticated) RouteV1MFARegenerateCodes = "/v1/mfa/backup-codes/regenerate" // Regenerate backup codes (authenticated) // Required MFA setup endpoints (unauthenticated, uses setup token) RouteV1MFARequiredSetup = "/v1/mfa/required-setup" // Start MFA setup when role requires it RouteV1MFARequiredEnable = "/v1/mfa/required-enable" // Enable MFA and complete login // Session management endpoints (authenticated) RouteV1Sessions = "/v1/sessions" // List active sessions, revoke all RouteV1SessionByID = "/v1/sessions/{sessionID}" // Revoke specific session )
API route constants shared between server and SDK clients
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type BackupCodesResponse ¶
type BackupCodesResponse struct {
BackupCodes []string `json:"backup_codes"`
}
BackupCodesResponse contains new backup codes
type CreateOIDCProviderRequest ¶
type CreateOIDCProviderRequest struct {
ProviderName string `json:"provider_name"`
IssuerURL string `json:"issuer_url"`
ClientID string `json:"client_id,omitempty"` // Optional: for manual registration
ClientSecret string `json:"client_secret,omitempty"` // Optional: for manual registration
AccessToken string `json:"access_token,omitempty"` // Optional: for authenticated dynamic registration
Scopes []string `json:"scopes,omitempty"`
Enabled bool `json:"enabled"`
AllowedDomains []string `json:"allowed_domains"`
AutoCreateUsers bool `json:"auto_create_users"`
RequireEmailVerification bool `json:"require_email_verification"`
}
type CreateRoleRequest ¶
type CreateUserRequest ¶
type CreateUserRequest struct {
Email string `json:"email"`
RoleIDs []uuid.UUID `json:"role_ids,omitempty"` // Optional list of role IDs to assign
}
CreateUserRequest creates a user. The tenant is not a field: it is the caller's own, read from gRPC metadata or a bearer token, so a caller cannot name one it does not hold.
type CreateUserResponse ¶
type DeleteRoleRequest ¶
type DirectPermission ¶
type DirectPermission struct {
PermissionID uuid.UUID `json:"permission_id"`
Effect PermissionEffect `json:"effect"`
}
DirectPermission is one entry in a replacement set of a user's direct permissions.
type DirectPermissionsResponse ¶
type DirectPermissionsResponse struct {
Permissions []EffectivePermission `json:"permissions"`
}
type DisableMFARequest ¶
type DisableMFARequest struct {
Password string `json:"password"`
Code string `json:"code"` // TOTP code or backup code
}
DisableMFARequest disables MFA
type EffectivePermission ¶
type EffectivePermission struct {
Permission Permission `json:"permission"`
Effect PermissionEffect `json:"effect"`
}
EffectivePermission is a permission assigned to a user directly, bypassing roles.
type EnableMFARequest ¶
type EnableMFARequest struct {
Code string `json:"code"`
}
EnableMFARequest verifies TOTP code during setup
type ErrorResponse ¶
type ErrorResponse struct {
Error string `json:"error"`
}
type ForgotPasswordRequest ¶
type ForgotPasswordRequest struct {
Email string `json:"email"`
}
type ForgotPasswordResponse ¶
type ForgotPasswordResponse struct {
Message string `json:"message"`
}
type GRPCClient ¶
type GRPCClient struct {
// contains filtered or unexported fields
}
GRPCClient is a gRPC client for the heimdall API
func NewGRPCClient ¶
func NewGRPCClient(address string, opts ...GRPCClientOption) (*GRPCClient, error)
NewGRPCClient creates a new gRPC client for the heimdall API address should be in the format "host:port" (e.g., "localhost:9090")
func (*GRPCClient) CreateUser ¶
func (c *GRPCClient) CreateUser(ctx context.Context, req CreateUserRequest) (*CreateUserResponse, error)
CreateUser creates a new user for a tenant Note: tenant_id is extracted from context and sent via gRPC metadata by the client interceptor
type GRPCClientOption ¶
type GRPCClientOption func(*grpcClientConfig)
GRPCClientOption is a functional option for configuring the gRPC client
func WithDialOptions ¶
func WithDialOptions(opts ...grpc.DialOption) GRPCClientOption
WithDialOptions allows setting custom gRPC dial options
func WithTimeout ¶
func WithTimeout(timeout time.Duration) GRPCClientOption
WithTimeout sets the default timeout for gRPC calls
type GetOIDCProviderRequest ¶
type GetRoleRequest ¶
type GetUserRolesRequest ¶
type HTTPClient ¶
type HTTPClient struct {
*http.Client // Embedded for direct access to http.Client methods
// contains filtered or unexported fields
}
HTTPClient is an HTTP client for the heimdall API
func NewHTTPClient ¶
func NewHTTPClient(baseURL string, opts ...Option) (*HTTPClient, error)
NewHTTPClient creates a new heimdall API client The client automatically handles cookies for refresh token management
func (*HTTPClient) CreateOIDCProvider ¶
func (c *HTTPClient) CreateOIDCProvider(ctx context.Context, req CreateOIDCProviderRequest) (*OIDCProvider, error)
CreateOIDCProvider creates a new OIDC provider configuration for corporate SSO
func (*HTTPClient) CreateRole ¶
func (c *HTTPClient) CreateRole(ctx context.Context, req CreateRoleRequest) (*Role, error)
CreateRole creates a new role
func (*HTTPClient) CreateUser ¶ added in v0.5.0
func (c *HTTPClient) CreateUser(ctx context.Context, req CreateUserRequest) (*CreateUserResponse, error)
CreateUser creates a user in the caller's own tenant and returns the verification token for it, which is the only copy: nothing is emailed.
func (*HTTPClient) DeleteOIDCProvider ¶
func (c *HTTPClient) DeleteOIDCProvider(ctx context.Context, req DeleteOIDCProviderRequest) error
DeleteOIDCProvider deletes an OIDC provider
func (*HTTPClient) DeleteRole ¶
func (c *HTTPClient) DeleteRole(ctx context.Context, req DeleteRoleRequest) error
DeleteRole deletes a role
func (*HTTPClient) DisableMFA ¶
func (c *HTTPClient) DisableMFA(ctx context.Context, req DisableMFARequest) error
DisableMFA disables MFA for the authenticated user
func (*HTTPClient) EnableMFA ¶
func (c *HTTPClient) EnableMFA(ctx context.Context, req EnableMFARequest) error
EnableMFA validates TOTP code and enables MFA
func (*HTTPClient) ForgotPassword ¶
func (c *HTTPClient) ForgotPassword(ctx context.Context, req ForgotPasswordRequest) (*ForgotPasswordResponse, error)
ForgotPassword initiates the password reset process
func (*HTTPClient) GetDirectPermissions ¶
func (c *HTTPClient) GetDirectPermissions(ctx context.Context, req GetDirectPermissionsRequest) (*DirectPermissionsResponse, error)
GetDirectPermissions retrieves direct permissions assigned to a user
func (*HTTPClient) GetMFAStatus ¶
func (c *HTTPClient) GetMFAStatus(ctx context.Context) (*MFAStatus, error)
GetMFAStatus retrieves MFA status for the authenticated user
func (*HTTPClient) GetMe ¶
func (c *HTTPClient) GetMe(ctx context.Context) (*User, error)
GetMe retrieves the current authenticated user's profile
func (*HTTPClient) GetOIDCProvider ¶
func (c *HTTPClient) GetOIDCProvider(ctx context.Context, req GetOIDCProviderRequest) (*OIDCProvider, error)
GetOIDCProvider retrieves an OIDC provider by ID
func (*HTTPClient) GetRole ¶
func (c *HTTPClient) GetRole(ctx context.Context, req GetRoleRequest) (*Role, error)
GetRole retrieves a role by ID
func (*HTTPClient) GetRolePermissions ¶
func (c *HTTPClient) GetRolePermissions(ctx context.Context, req GetRolePermissionsRequest) (*PermissionsResponse, error)
GetRolePermissions retrieves all permissions for a role
func (*HTTPClient) GetUserRoles ¶
func (c *HTTPClient) GetUserRoles(ctx context.Context, req GetUserRolesRequest) (*RolesResponse, error)
GetUserRoles retrieves all roles for a user
func (*HTTPClient) Health ¶
func (c *HTTPClient) Health(ctx context.Context) error
Health checks the health of the heimdall API. Returns nil if healthy, error if unhealthy or unreachable.
func (*HTTPClient) ListOIDCProviders ¶
func (c *HTTPClient) ListOIDCProviders(ctx context.Context) (*OIDCProvidersResponse, error)
ListOIDCProviders lists all OIDC providers for the tenant
func (*HTTPClient) ListPermissions ¶
func (c *HTTPClient) ListPermissions(ctx context.Context) (*PermissionsResponse, error)
ListPermissions retrieves all system permissions
func (*HTTPClient) ListRoles ¶
func (c *HTTPClient) ListRoles(ctx context.Context) (*RolesResponse, error)
ListRoles retrieves all roles for the tenant
func (*HTTPClient) ListSessions ¶
func (c *HTTPClient) ListSessions(ctx context.Context) (*SessionsResponse, error)
ListSessions retrieves all active sessions for the authenticated user
func (*HTTPClient) ListSupportedProviders ¶
func (c *HTTPClient) ListSupportedProviders(ctx context.Context) (*OIDCProviderTypesResponse, error)
ListSupportedProviders returns the list of OAuth providers available for individual login
func (*HTTPClient) Login ¶
func (c *HTTPClient) Login(ctx context.Context, req LoginRequest) (*LoginResponse, error)
Login authenticates a user and returns an access token The access token is automatically set on the client for subsequent authenticated requests The refresh token is automatically stored in the client's cookie jar If MFA is required, returns MFAChallengeToken or MFASetupToken instead of AccessToken
func (*HTTPClient) Logout ¶
func (c *HTTPClient) Logout(ctx context.Context) (*LogoutResponse, error)
Logout logs out the current user by revoking the refresh token
func (*HTTPClient) OAuthLogin ¶
func (c *HTTPClient) OAuthLogin(ctx context.Context, req OIDCLoginRequest) (*OIDCAuthResponse, error)
OAuthLogin initiates an OAuth login flow Returns the authorization URL that the user should be redirected to
func (*HTTPClient) RefreshToken ¶
func (c *HTTPClient) RefreshToken(ctx context.Context) (*LoginResponse, error)
RefreshToken refreshes the access token using the refresh token cookie The access token is automatically set on the client for subsequent authenticated requests The refresh token cookie must have been set by a previous Login call
func (*HTTPClient) RegenerateBackupCodes ¶
func (c *HTTPClient) RegenerateBackupCodes(ctx context.Context, req RegenerateBackupCodesRequest) (*BackupCodesResponse, error)
RegenerateBackupCodes generates new backup codes (requires password)
func (*HTTPClient) Register ¶
func (c *HTTPClient) Register(ctx context.Context, req RegisterRequest) (*RegisterResponse, error)
Register registers a new user account
func (*HTTPClient) RequiredMFAEnable ¶
func (c *HTTPClient) RequiredMFAEnable(ctx context.Context, req RequiredMFAEnableRequest) (*LoginResponse, error)
RequiredMFAEnable enables MFA after required setup and issues an MFA challenge token After this succeeds, call VerifyMFACode to complete the login flow
func (*HTTPClient) RequiredMFASetup ¶
func (c *HTTPClient) RequiredMFASetup(ctx context.Context, req RequiredMFASetupRequest) (*MFASetupResponse, error)
RequiredMFASetup initiates MFA setup when a user's role requires MFA but they haven't set it up Returns the TOTP secret, QR code, and backup codes
func (*HTTPClient) ResetPassword ¶
func (c *HTTPClient) ResetPassword(ctx context.Context, req ResetPasswordRequest) (*ResetPasswordResponse, error)
ResetPassword resets a user's password using the reset token
func (*HTTPClient) RevokeAllSessions ¶
func (c *HTTPClient) RevokeAllSessions(ctx context.Context) error
RevokeAllSessions revokes all sessions for the authenticated user (sign out everywhere)
func (*HTTPClient) RevokeSession ¶
func (c *HTTPClient) RevokeSession(ctx context.Context, req RevokeSessionRequest) error
RevokeSession revokes a specific session by ID
func (*HTTPClient) SSOLogin ¶
func (c *HTTPClient) SSOLogin(ctx context.Context, req SSOLoginRequest) (*OIDCAuthResponse, error)
SSOLogin initiates a corporate SSO login flow Returns the authorization URL that the user should be redirected to
func (*HTTPClient) SetDirectPermissions ¶
func (c *HTTPClient) SetDirectPermissions(ctx context.Context, req SetDirectPermissionsRequest) error
SetDirectPermissions sets all permissions for a user
func (*HTTPClient) SetRolePermissions ¶
func (c *HTTPClient) SetRolePermissions(ctx context.Context, req SetRolePermissionsRequest) error
SetRolePermissions sets all permissions for a role (bulk update)
func (*HTTPClient) SetUserRoles ¶
func (c *HTTPClient) SetUserRoles(ctx context.Context, req SetUserRolesRequest) error
SetUserRoles sets all roles for a user
func (*HTTPClient) SetupMFA ¶
func (c *HTTPClient) SetupMFA(ctx context.Context) (*MFASetupResponse, error)
SetupMFA initiates MFA setup by generating TOTP secret, QR code, and backup codes
func (*HTTPClient) UpdateOIDCProvider ¶
func (c *HTTPClient) UpdateOIDCProvider(ctx context.Context, req UpdateOIDCProviderRequest) (*OIDCProvider, error)
UpdateOIDCProvider updates an OIDC provider configuration
func (*HTTPClient) UpdateRole ¶
func (c *HTTPClient) UpdateRole(ctx context.Context, req UpdateRoleRequest) (*Role, error)
UpdateRole updates a role
func (*HTTPClient) VerifyEmail ¶
func (c *HTTPClient) VerifyEmail(ctx context.Context, req VerifyEmailRequest) (*LoginResponse, error)
VerifyEmail verifies a user's email address using the verification token The access token is automatically set on the client for subsequent authenticated requests Returns a LoginResponse with access token on successful verification May return MFAChallengeToken or MFASetupToken if user's role requires MFA
func (*HTTPClient) VerifyMFACode ¶
func (c *HTTPClient) VerifyMFACode(ctx context.Context, req VerifyMFACodeRequest) (*LoginResponse, error)
VerifyMFACode verifies MFA code during login and completes authentication The access token is automatically set on the client for subsequent authenticated requests
type HealthResponse ¶ added in v0.4.0
type HealthResponse struct {
Status string `json:"status"`
}
type LoginRequest ¶
type LoginResponse ¶
type LoginResponse struct {
AccessToken string `json:"access_token,omitempty"` // Set when login is complete
MFAChallengeToken string `json:"mfa_challenge_token,omitempty"` // Set when MFA verification is required
MFASetupToken string `json:"mfa_setup_token,omitempty"` // Set when role requires MFA but user hasn't set it up
TokenType string `json:"token_type,omitempty"` // "Bearer" for access tokens, omitted for challenge/setup tokens
ExpiresIn int `json:"expires_in"` // Seconds until access token expires (OAuth 2.0 standard)
RefreshExpiresIn int `json:"refresh_expires_in,omitempty"` // Seconds until refresh token expires (extension to standard)
}
LoginResponse carries whichever the sign-in reached: an access token, or the challenge that has to be answered first. The refresh token is not in the body — it is set as an HTTP-only cookie, so script on the page cannot read it.
type LogoutResponse ¶
type LogoutResponse struct {
Message string `json:"message"`
}
type MFASetupResponse ¶
type MFASetupResponse struct {
Secret string `json:"secret"`
QRCode string `json:"qr_code"`
BackupCodes []string `json:"backup_codes"`
}
MFASetupResponse contains secret, QR code, and backup codes for MFA setup
type MFAStatus ¶
type MFAStatus struct {
VerifiedAt *time.Time `json:"verified_at,omitempty"`
BackupCodesRemaining int `json:"backup_codes_remaining"`
}
MFAStatus is a user's MFA state and how many backup codes they have left.
type OIDCAuthResponse ¶
type OIDCAuthResponse struct {
AuthorizationURL string `json:"authorization_url"`
}
OIDCAuthResponse is where to send the browser to begin the flow.
type OIDCLoginRequest ¶
type OIDCLoginRequest struct {
ProviderType OIDCProviderType `json:"provider_type"`
}
OIDCLoginRequest signs in through a personal account (Google, GitHub), not corporate SSO.
type OIDCProvider ¶
type OIDCProvider struct {
ID uuid.UUID `json:"id"`
ProviderName string `json:"provider_name"`
IssuerURL string `json:"issuer_url"`
ClientID string `json:"client_id"`
Scopes []string `json:"scopes"`
Enabled bool `json:"enabled"`
AllowedDomains []string `json:"allowed_domains"`
AutoCreateUsers bool `json:"auto_create_users"`
RequireEmailVerification bool `json:"require_email_verification"`
RegistrationMethod OIDCRegistrationMethod `json:"registration_method"`
ClientIDIssuedAt *time.Time `json:"client_id_issued_at,omitempty"`
ClientSecretExpiresAt *time.Time `json:"client_secret_expires_at,omitempty"`
}
OIDCProvider is a provider configuration including its client secret, so it is only ever returned to a caller holding an OIDC read scope.
type OIDCProviderType ¶
type OIDCProviderType string
const ( OIDCProviderTypeGoogle OIDCProviderType = "google" OIDCProviderTypeMicrosoft OIDCProviderType = "microsoft" OIDCProviderTypeGitHub OIDCProviderType = "github" OIDCProviderTypeOkta OIDCProviderType = "okta" )
func (OIDCProviderType) DisplayName ¶
func (p OIDCProviderType) DisplayName() string
DisplayName returns a human-readable name for the provider
func (OIDCProviderType) IsValid ¶
func (p OIDCProviderType) IsValid() bool
IsValid checks if the provider type is one of the defined valid types
func (OIDCProviderType) String ¶
func (p OIDCProviderType) String() string
String returns the string representation of the provider type
type OIDCProviderTypeInfo ¶
type OIDCProviderTypeInfo struct {
Type OIDCProviderType `json:"type"`
DisplayName string `json:"display_name"`
}
type OIDCProviderTypesResponse ¶
type OIDCProviderTypesResponse struct {
Providers []OIDCProviderTypeInfo `json:"providers"`
}
type OIDCProvidersResponse ¶
type OIDCProvidersResponse struct {
Providers []OIDCProvider `json:"providers"`
}
type OIDCRegistrationMethod ¶
type OIDCRegistrationMethod string
OIDCRegistrationMethod is whether a provider was registered by hand or discovered.
const ( OIDCRegistrationMethodManual OIDCRegistrationMethod = "manual" OIDCRegistrationMethodDynamic OIDCRegistrationMethod = "dynamic" )
type Option ¶
type Option func(*HTTPClient)
Option is a functional option for configuring the HTTPClient
func WithCookieJar ¶
WithCookieJar configures the client with a specific cookie jar. Useful for tests that need to inspect cookies (e.g., capturing refresh tokens).
func WithHTTPClient ¶
WithHTTPClient allows setting a custom http.Client Note: If you provide a custom client for refresh token support, ensure it has a cookie jar configured
func WithInsecureSkipVerify ¶
func WithInsecureSkipVerify() Option
WithInsecureSkipVerify configures the client to skip TLS certificate verification This is useful for development with self-signed certificates
type Permission ¶
type PermissionEffect ¶
type PermissionEffect string
PermissionEffect is whether a permission allows or denies.
const ( PermissionAllow PermissionEffect = "allow" PermissionDeny PermissionEffect = "deny" )
type PermissionsResponse ¶
type PermissionsResponse struct {
Permissions []Permission `json:"permissions"`
}
type RegenerateBackupCodesRequest ¶
type RegenerateBackupCodesRequest struct {
Password string `json:"password"`
}
RegenerateBackupCodesRequest regenerates backup codes
type RegisterRequest ¶
type RegisterRequest struct {
Email string `json:"email"`
FirstName string `json:"first_name"`
LastName string `json:"last_name"`
}
RegisterRequest starts a registration. No password: one is set by following the emailed link, which is the step that proves the address belongs to whoever typed it.
type RegisterResponse ¶
type RequiredMFAEnableRequest ¶
type RequiredMFAEnableRequest struct {
SetupToken string `json:"setup_token"` // Setup token from login response
Code string `json:"code"` // TOTP code to verify setup
}
RequiredMFAEnableRequest enables MFA after required setup
type RequiredMFASetupRequest ¶
type RequiredMFASetupRequest struct {
SetupToken string `json:"setup_token"` // Setup token from login response
}
RequiredMFASetupRequest initiates MFA setup when role requires it
type ResetPasswordRequest ¶
type ResetPasswordResponse ¶
type ResetPasswordResponse struct {
Message string `json:"message"`
}
type RevokeSessionRequest ¶
type RolesResponse ¶
type RolesResponse struct {
Roles []Role `json:"roles"`
}
type SSOLoginRequest ¶
type SSOLoginRequest struct {
Email string `json:"email"`
}
SSOLoginRequest signs in through the provider configured for the address's domain. The address is a hint for choosing that provider; the identity comes from the provider.
type Session ¶
type Session struct {
ID uuid.UUID `json:"id"`
UserAgent string `json:"user_agent"`
IPAddress string `json:"ip_address"`
CreatedAt time.Time `json:"created_at"`
LastUsedAt time.Time `json:"last_used_at"`
}
Session is one live sign-in: where it was started and when it was last used.
type SessionsResponse ¶
type SessionsResponse struct {
Sessions []Session `json:"sessions"`
}
type SetDirectPermissionsRequest ¶
type SetDirectPermissionsRequest struct {
UserID uuid.UUID `json:"-"`
Permissions []DirectPermission `json:"permissions"`
}
type SetRolePermissionsRequest ¶
type SetUserRolesRequest ¶
type UpdateOIDCProviderRequest ¶
type UpdateOIDCProviderRequest struct {
ProviderID uuid.UUID `json:"-"` // From URL parameter, not JSON body
ProviderName *string `json:"provider_name,omitempty"` // Optional: update display name
ClientSecret *string `json:"client_secret,omitempty"` // Optional: rotate secret
Scopes []string `json:"scopes,omitempty"` // Optional: nil = keep, [] = clear, non-empty = update
Enabled *bool `json:"enabled,omitempty"` // Optional: update enabled status
AllowedDomains []string `json:"allowed_domains,omitempty"` // Optional: nil = keep, non-nil = update
AutoCreateUsers *bool `json:"auto_create_users,omitempty"` // Optional: update auto-create users flag
RequireEmailVerification *bool `json:"require_email_verification,omitempty"` // Optional: update email verification requirement
}
All fields are optional pointers to support partial updates
type UpdateRoleRequest ¶
type UpdateRoleRequest struct {
RoleID uuid.UUID `json:"-"`
Name *string `json:"name,omitempty"`
Description *string `json:"description,omitempty"`
MFARequired *bool `json:"mfa_required,omitempty"`
}
UpdateRoleRequest updates a role. An omitted field keeps its stored value.
type VerifyEmailRequest ¶
VerifyEmailRequest completes a registration: it proves the address and sets the first password together.
type VerifyMFACodeRequest ¶
type VerifyMFACodeRequest struct {
ChallengeToken string `json:"challenge_token"` // Challenge token from initial login
Code string `json:"code"` // TOTP code (6 digits) or backup code (8 digits)
TrustDevice bool `json:"trust_device"` // Optional: trust this device for 30 days (skip MFA on next login)
}
VerifyMFACodeRequest verifies MFA code