secretstore

package
v1.141.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 8, 2026 License: Apache-2.0 Imports: 9 Imported by: 0

Documentation

Overview

Package secretstore holds the secrets a request references by placeholder (#2051): the record an administrator writes, the rules it is held to, its PostgreSQL store with the value encrypted, and the lookup the api gateway fills a placeholder through.

The value is write-only. No method returns it except the lookup, which the gateway calls as it sends a request, and the lookup reads it from the database on every call, so a rotated value is used from the next call on.

Index

Constants

View Source
const (
	MaxValueBytes       = 64 * 1024
	MaxDescriptionBytes = 1000
)

Limits on what a write may carry.

Variables

View Source
var ErrInvalid = errors.New("invalid secret")

ErrInvalid is wrapped by every refusal of a write.

View Source
var ErrNotFound = errors.New("secret not found")

ErrNotFound is returned for a name no secret is stored under.

Functions

func Allowed

func Allowed(sec Secret, connection, persona string) error

Allowed refuses a use of sec outside its scope.

func Validate

func Validate(w Write, creating bool) error

Validate refuses a write the store would hold wrongly. creating says whether no secret is stored under the name yet, in which case a value is required.

Types

type Encryptor

type Encryptor interface {
	Encrypt(plaintext string) (string, error)
	Decrypt(ciphertext string) (string, error)
}

Encryptor encrypts and decrypts one value. fieldcrypt.RestFieldEncryptor satisfies it; a nil one stores values as written.

type Secret

type Secret struct {
	Name             string    `json:"name"`
	Description      string    `json:"description"`
	AllowConnections []string  `json:"allow_connections"`
	AllowPersonas    []string  `json:"allow_personas"`
	CreatedBy        string    `json:"created_by"`
	UpdatedBy        string    `json:"updated_by"`
	CreatedAt        time.Time `json:"created_at"`
	UpdatedAt        time.Time `json:"updated_at"`
}

Secret is a stored secret as every reader but the gateway sees it: what it is for and where it may go, never its value.

type Source

type Source interface {
	Lookup(ctx context.Context, connection, persona string) secretref.Lookup
}

Source is what the gateway fills placeholders from: the store, or a fake in a test.

type Store

type Store struct {
	// contains filtered or unexported fields
}

Store persists secrets in gateway_secrets.

func NewStore

func NewStore(db *sql.DB, enc Encryptor) *Store

NewStore creates a store. enc may be nil.

func (*Store) Delete

func (s *Store) Delete(ctx context.Context, name string) error

Delete removes a secret, or returns ErrNotFound.

func (*Store) Get

func (s *Store) Get(ctx context.Context, name string) (Secret, error)

Get returns one secret without its value, or ErrNotFound.

func (*Store) List

func (s *Store) List(ctx context.Context) ([]Secret, error)

List returns every secret in name order, without values.

func (*Store) Lookup

func (s *Store) Lookup(ctx context.Context, connection, persona string) secretref.Lookup

Lookup returns the lookup one call fills its placeholders through: a secret is answered only when connection is in its allow_connections and, when it names personas, persona is one of them or the administrator persona. allow_connections holds for every caller: it is where the value may go, not who may ask. Every refusal names the secret and says what would allow it. A name is read once per call however many placeholders name it.

func (*Store) Put

func (s *Store) Put(ctx context.Context, w Write) (Secret, bool, error)

Put creates or updates a secret and returns it as stored, and whether it was created.

func (*Store) WithAdmin

func (s *Store) WithAdmin(persona string) *Store

WithAdmin names the administrator persona the lookup lets through allow_personas, and returns the store.

type Write

type Write struct {
	Name             string
	Description      string
	Value            *string
	AllowConnections []string
	AllowPersonas    []string
	Actor            string
}

Write is one create or update. Value nil on an update keeps the stored value, so an administrator can rescope a secret without retyping it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL