auth

package
v1.0.0-feature-modules... Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 8, 2026 License: MIT Imports: 7 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// ContextKeyClaims is the gin context key for storing validated claims.
	ContextKeyClaims = "ws_claims"
)

Variables

This section is empty.

Functions

func ExtractTokenFromQuery

func ExtractTokenFromQuery(rawURL string) string

ExtractTokenFromQuery extracts a "token" query parameter from a URL.

func Middleware

func Middleware(jwtSecret string, authRequired bool) gin.HandlerFunc

Middleware returns a Gin handler that validates JWT tokens for WebSocket upgrade requests. It checks the Authorization header first, then falls back to the "token" query parameter. Verification is HS256-only, via ValidateToken(token, jwtSecret) — hosts whose own tokens are signed RS256 (or need any other verification scheme) should use MiddlewareWithResolver instead.

func MiddlewareWithResolver

func MiddlewareWithResolver(resolve ClaimsResolverFunc, authRequired bool) gin.HandlerFunc

MiddlewareWithResolver is Middleware, generalized to accept any ClaimsResolverFunc instead of assuming HS256 + a shared secret.

func ValidateOrigin

func ValidateOrigin(origin string, allowedOrigins []string) bool

ValidateOrigin checks if a request origin is in the allowed origins list. An empty allowlist permits all origins.

Types

type Claims

type Claims struct {
	UserID   string
	TenantID string
	OrgID    string
	Raw      jwt.MapClaims
}

Claims holds the validated user claims from a JWT.

func GetClaims

func GetClaims(c *gin.Context) *Claims

GetClaims extracts the validated claims from the gin context.

func ValidateToken

func ValidateToken(token, secret string) (*Claims, error)

ValidateToken parses and validates a JWT, extracting userID, tenantID, and orgID.

type ClaimsResolverFunc

type ClaimsResolverFunc func(token string) (*Claims, error)

ClaimsResolverFunc validates a raw bearer/query token and returns its claims — a pluggable alternative to Middleware's fixed HS256-shared- secret verification, for hosts (e.g. mori-backend, RS256) whose own TokenIssuer already knows how to validate its own tokens.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL