Documentation
¶
Overview ¶
Package secretstore holds the secrets a request references by placeholder (#2051): the record an administrator writes, the rules it is held to, its PostgreSQL store with the value encrypted, and the lookup the api gateway fills a placeholder through.
The value is write-only. No method returns it except the lookup, which the gateway calls as it sends a request, and the lookup reads it from the database on every call, so a rotated value is used from the next call on.
Index ¶
- Constants
- Variables
- func Allowed(sec Secret, connection, persona string) error
- func Validate(w Write, creating bool) error
- type Encryptor
- type Secret
- type Source
- type Store
- func (s *Store) Delete(ctx context.Context, name string) error
- func (s *Store) Get(ctx context.Context, name string) (Secret, error)
- func (s *Store) List(ctx context.Context) ([]Secret, error)
- func (s *Store) Lookup(ctx context.Context, connection, persona string) secretref.Lookup
- func (s *Store) Put(ctx context.Context, w Write) (Secret, bool, error)
- func (s *Store) WithAdmin(persona string) *Store
- type Write
Constants ¶
const ( MaxValueBytes = 64 * 1024 MaxDescriptionBytes = 1000 )
Limits on what a write may carry.
Variables ¶
var ErrInvalid = errors.New("invalid secret")
ErrInvalid is wrapped by every refusal of a write.
var ErrNotFound = errors.New("secret not found")
ErrNotFound is returned for a name no secret is stored under.
Functions ¶
Types ¶
type Encryptor ¶
type Encryptor interface {
Encrypt(plaintext string) (string, error)
Decrypt(ciphertext string) (string, error)
}
Encryptor encrypts and decrypts one value. fieldcrypt.RestFieldEncryptor satisfies it; a nil one stores values as written.
type Secret ¶
type Secret struct {
Name string `json:"name"`
Description string `json:"description"`
AllowConnections []string `json:"allow_connections"`
AllowPersonas []string `json:"allow_personas"`
CreatedBy string `json:"created_by"`
UpdatedBy string `json:"updated_by"`
CreatedAt time.Time `json:"created_at"`
UpdatedAt time.Time `json:"updated_at"`
}
Secret is a stored secret as every reader but the gateway sees it: what it is for and where it may go, never its value.
type Store ¶
type Store struct {
// contains filtered or unexported fields
}
Store persists secrets in gateway_secrets.
func (*Store) Lookup ¶
Lookup returns the lookup one call fills its placeholders through: a secret is answered only when connection is in its allow_connections and, when it names personas, persona is one of them or the administrator persona. allow_connections holds for every caller: it is where the value may go, not who may ask. Every refusal names the secret and says what would allow it. A name is read once per call however many placeholders name it.