Documentation
¶
Index ¶
- Constants
- func ExtractTokenFromQuery(rawURL string) string
- func Middleware(jwtSecret string, authRequired bool) gin.HandlerFunc
- func MiddlewareWithResolver(resolve ClaimsResolverFunc, authRequired bool) gin.HandlerFunc
- func ValidateOrigin(origin string, allowedOrigins []string) bool
- type Claims
- type ClaimsResolverFunc
Constants ¶
const (
// ContextKeyClaims is the gin context key for storing validated claims.
ContextKeyClaims = "ws_claims"
)
Variables ¶
This section is empty.
Functions ¶
func ExtractTokenFromQuery ¶
ExtractTokenFromQuery extracts a "token" query parameter from a URL.
func Middleware ¶
func Middleware(jwtSecret string, authRequired bool) gin.HandlerFunc
Middleware returns a Gin handler that validates JWT tokens for WebSocket upgrade requests. It checks the Authorization header first, then falls back to the "token" query parameter. Verification is HS256-only, via ValidateToken(token, jwtSecret) — hosts whose own tokens are signed RS256 (or need any other verification scheme) should use MiddlewareWithResolver instead.
func MiddlewareWithResolver ¶
func MiddlewareWithResolver(resolve ClaimsResolverFunc, authRequired bool) gin.HandlerFunc
MiddlewareWithResolver is Middleware, generalized to accept any ClaimsResolverFunc instead of assuming HS256 + a shared secret.
func ValidateOrigin ¶
ValidateOrigin checks if a request origin is in the allowed origins list. An empty allowlist permits all origins.
Types ¶
type Claims ¶
Claims holds the validated user claims from a JWT.
func ValidateToken ¶
ValidateToken parses and validates a JWT, extracting userID, tenantID, and orgID.
type ClaimsResolverFunc ¶
ClaimsResolverFunc validates a raw bearer/query token and returns its claims — a pluggable alternative to Middleware's fixed HS256-shared- secret verification, for hosts (e.g. mori-backend, RS256) whose own TokenIssuer already knows how to validate its own tokens.