Documentation
¶
Overview ¶
Package connsecretref is the save-time half of a connection configuration that names a stored secret as {{secret:<name>}} (#2066): which fields the platform fills as the connection sends a request, and the check the admin API runs before it stores such a configuration. The send-time half, the fill itself, is internal/upstreamauth's and pkg/toolkits/gateway's; the configuration keys named here are theirs, and a test holds the two lists to the keys those packages read.
Index ¶
- func Allowed(kind string, cfg map[string]any, path string) bool
- func Check(ctx context.Context, scopes Scopes, kind, name string, cfg map[string]any) error
- func DropCarriedSessionSecret(cfg map[string]any, redacted string)
- func Fields(kind string) string
- func NamesStoredSecret(v any) bool
- type Scopes
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func Allowed ¶
Allowed reports whether a value at path (a top-level key, or "<map key>.<entry>" for a map of headers) in a connection of kind may name a stored secret: whether the platform fills it as the connection sends a request. A reference anywhere else would be sent as written. The OAuth client's id and secret are filled for the client_credentials grant, whose token exchange the platform makes on every refresh; the authorization_code grant's exchange is made by the admin flow, which reads them as stored.
func Check ¶
Check refuses a connection configuration that names a stored secret as {{secret:<name>}} where the platform would not fill it, in a malformed placeholder, as a one-time code, or naming a secret that does not exist or that the connection may not use. The configuration is stored with the placeholder as written and the value read each time the connection sends a request, so this is the refusal an administrator sees at save rather than at the connection's first call. scopes nil refuses any reference.
func DropCarriedSessionSecret ¶
DropCarriedSessionSecret removes a session_login_secret the portal sent back as redacted from a sign-in body that no longer has anywhere to write it, because the body now names a stored secret as {{secret:<name>}}. Kept, the stored value would be merged back in and the save refused for a secret the body does not use; a new value the operator typed is left for validation to refuse.
func Fields ¶
Fields names, for an operator reading a refusal, where a connection of kind may name a stored secret.
func NamesStoredSecret ¶
NamesStoredSecret reports whether a sensitive value is exactly one {{secret:<name>}} reference. It holds no secret, only the name of one, so the admin API reads it back as written rather than redacted: an administrator sees which secret a credential comes from, and a portal that sends it back saves it unchanged.