Documentation
¶
Index ¶
- type JWTTokenIssuer
- func (t *JWTTokenIssuer) IssueToken(user interfaces.User) (*responses.TokenResponse, error)
- func (t *JWTTokenIssuer) JWKS() (map[string]any, error)
- func (t *JWTTokenIssuer) RefreshToken(tokenString string) (*responses.TokenResponse, error)
- func (t *JWTTokenIssuer) RevokeToken(tokenString string) error
- func (t *JWTTokenIssuer) SetOrgLister(ol interfaces.OrgLister)
- func (t *JWTTokenIssuer) SetRoleLister(rl interfaces.RoleLister)
- func (t *JWTTokenIssuer) ValidateToken(tokenString string) (map[string]any, error)
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type JWTTokenIssuer ¶
type JWTTokenIssuer struct {
// contains filtered or unexported fields
}
func NewJWTTokenIssuer ¶
func NewJWTTokenIssuer(cfg config.JWTConfig) (*JWTTokenIssuer, error)
NewJWTTokenIssuer constructs a token issuer. When cfg.Algorithm is "RS256", the configured PEM key pair is parsed up front so a misconfiguration fails at startup rather than on the first login.
func (*JWTTokenIssuer) IssueToken ¶
func (t *JWTTokenIssuer) IssueToken(user interfaces.User) (*responses.TokenResponse, error)
func (*JWTTokenIssuer) JWKS ¶
func (t *JWTTokenIssuer) JWKS() (map[string]any, error)
JWKS returns the access-token public key as a standard JSON Web Key Set (RFC 7517), for publishing at a well-known endpoint so other services (e.g. Veda, per D6 in the mori platform plan) can verify access tokens without ever holding a secret capable of minting them. Only meaningful when configured for RS256 — HS256 has no public half to publish.
func (*JWTTokenIssuer) RefreshToken ¶
func (t *JWTTokenIssuer) RefreshToken(tokenString string) (*responses.TokenResponse, error)
func (*JWTTokenIssuer) RevokeToken ¶
func (t *JWTTokenIssuer) RevokeToken(tokenString string) error
func (*JWTTokenIssuer) SetOrgLister ¶
func (t *JWTTokenIssuer) SetOrgLister(ol interfaces.OrgLister)
SetOrgLister wires in an optional org source, mirroring SetRoleLister (see interfaces.OrgListerSetter's doc comment). Safe to call with nil to disable — IssueToken simply omits the "org_id" claim then.
func (*JWTTokenIssuer) SetRoleLister ¶
func (t *JWTTokenIssuer) SetRoleLister(rl interfaces.RoleLister)
SetRoleLister wires in an optional roles source (see interfaces.RoleListerSetter's doc comment for why this is a post-construction setter rather than a constructor param). Safe to call with nil to disable — IssueToken simply omits the "roles" claim then, same as if this were never called.
func (*JWTTokenIssuer) ValidateToken ¶
func (t *JWTTokenIssuer) ValidateToken(tokenString string) (map[string]any, error)
ValidateToken validates an access token using whichever algorithm is configured.