Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ( ErrMissingJWTSecret = fmt.Errorf("JWT secret is required") ErrMissingJWTKeyPair = fmt.Errorf("JWT private/public key pair is required when algorithm is RS256") ErrMissingRefreshTokenSecret = fmt.Errorf("JWT refresh token secret is required") ErrInvalidJWTExpiry = fmt.Errorf("invalid JWT expiry time") ErrInvalidRefreshExpiry = fmt.Errorf("invalid refresh token expiry time") ErrInvalidPasswordLength = fmt.Errorf("minimum password length must be at least 8 characters") ErrInvalidAPIKeyLength = fmt.Errorf("API key length must be at least 16 characters") ErrInvalidClerkConfig = fmt.Errorf("clerk API endpoint is required when API key is provided") ErrInvalidAuthorizationSource = fmt.Errorf(`authorization source must be "database" or "file"`) ErrMissingAuthorizationPolicyPath = fmt.Errorf(`authorization policyPath is required when source is "file"`) )
Configuration errors
Functions ¶
This section is empty.
Types ¶
type APIKeyConfig ¶
type APIKeyConfig struct {
Length int `yaml:"length"`
ExpiryTime time.Duration `yaml:"expiryTime"`
AllowedIPs []string `yaml:"allowedIPs"`
RateLimit RateLimitConfig `yaml:"rateLimit"`
}
APIKeyConfig represents API key configuration
type AuthorizationConfig ¶
type AuthorizationConfig struct {
// Source selects where casbin policy (p) and grouping (g) rows live:
// "database" (gorm-adapter, reading/writing through the host app's own
// DB — the historical default behavior, kept as the zero-value default
// for full backward compatibility) or "file" (casbin's built-in
// file-adapter, reading/writing PolicyPath).
Source string `yaml:"source" validate:"omitempty,oneof=database file"`
// ModelPath, if set, loads the casbin RBAC model from this file instead
// of the package's embedded default (rbacModelConf). Most hosts should
// leave this empty.
ModelPath string `yaml:"modelPath"`
// PolicyPath is the casbin policy CSV path, required only when
// Source == "file".
PolicyPath string `yaml:"policyPath" validate:"required_if=Source file"`
// MiddlewareEnabled preserves the old no-op-if-disabled behavior of
// AuthMiddleware.RequireRole/RequirePermission — when false (the
// default), those two middlewares are no-ops regardless of what's in
// the enforcer, exactly like the old MiddlewareConfig.AuthorizationEnabled
// flag. The enforcer itself is always constructed now (AuthorizationManager
// needs it unconditionally for role/permission management), so this only
// gates the two HTTP middlewares, not enforcer construction.
MiddlewareEnabled bool `yaml:"middlewareEnabled"`
// ExposeManagementAPI opts a host app into registering the generic
// /auth/roles, /auth/roles/:name/permissions, etc. HTTP routes (see
// handlers.NewAuthorizationHandler). Default false — this is a
// privileged CRUD surface over roles/permissions, not every host wants
// it registered by default.
ExposeManagementAPI bool `yaml:"exposeManagementAPI"`
}
AuthorizationConfig configures the module's single shared casbin enforcer, used both by AuthorizationManager (role/permission CRUD and Enforce calls made by consuming-app code) and by AuthMiddleware (HTTP-level RequireRole/RequirePermission gating) — see authorization.NewAuthorizationManager, which owns constructing the enforcer from this config, and middleware.NewAuthMiddleware, which now receives that same manager instead of building a second, independent enforcer (as it did previously).
type ClerkConfig ¶
type ClerkConfig struct {
APIKey string `yaml:"apiKey"`
APIEndpoint string `yaml:"apiEndpoint"`
FrontendAPI string `yaml:"frontendAPI"`
}
ClerkConfig represents Clerk.com configuration
type Config ¶
type Config struct {
JWT JWTConfig `yaml:"jwt"`
Backends []string `yaml:"backends" validate:"required"`
PasswordPolicy PasswordPolicyConfig `yaml:"passwordPolicy"`
APIKey APIKeyConfig `yaml:"apiKey"`
Social SocialConfig `yaml:"social"`
Clerk ClerkConfig `yaml:"clerk"`
Authorization AuthorizationConfig `yaml:"authorization"`
Providers map[string]map[string]string `yaml:"providers"`
UserMigrationScriptPath string `yaml:"userMigrationScriptPath"`
// EventsTopic is the Kafka topic auth lifecycle events (login,
// password reset/changed, user created/updated/deleted — see
// emitter.AuthEventData.EventType for the specific values) are
// published to. Left empty, EmitAuthEvent is a no-op: the same
// "not configured yet" posture other optional Kafka producers in
// this codebase use, rather than publishing to a topic named after
// the event type itself (which no broker provisions and fails with
// "topic or partition does not exist").
EventsTopic string `yaml:"eventsTopic"`
}
Config represents the authentication module configuration
type ErrInvalidSocialConfig ¶
type ErrInvalidSocialConfig struct {
Provider string
}
ErrInvalidSocialConfig represents an error with social provider configuration
func (ErrInvalidSocialConfig) Error ¶
func (e ErrInvalidSocialConfig) Error() string
type JWTConfig ¶
type JWTConfig struct {
Algorithm string `yaml:"algorithm"`
AccessTokenSecret string `yaml:"accessTokenSecret"`
RefreshTokenSecret string `yaml:"refreshTokenSecret"`
PrivateKeyPEM string `yaml:"privateKeyPEM"`
PublicKeyPEM string `yaml:"publicKeyPEM"`
KeyID string `yaml:"keyId"`
AccessTokenExpiry time.Duration `yaml:"accessTokenExpiry"`
RefreshTokenExpiry time.Duration `yaml:"refreshTokenExpiry"`
}
JWTConfig represents JWT configuration.
Algorithm controls how *access* tokens are signed: "HS256" (default, a shared secret only this service knows) or "RS256" (an RSA keypair, whose public half can be published via a JWKS endpoint so other services — e.g. Veda, per D6 in the mori platform plan — can verify tokens independently without ever holding a secret that could mint them). Refresh tokens always stay HS256/AccessTokenSecret-adjacent (RefreshTokenSecret): they're exchanged directly with this service and never need third-party verification, so there's no reason to widen their blast radius.
type PasswordPolicyConfig ¶
type PasswordPolicyConfig struct {
MinLength int `yaml:"minLength"`
RequireUpper bool `yaml:"requireUpper"`
RequireLower bool `yaml:"requireLower"`
RequireNumber bool `yaml:"requireNumber"`
RequireSpecial bool `yaml:"requireSpecial"`
}
PasswordPolicyConfig represents password policy configuration
type RateLimitConfig ¶
type RateLimitConfig struct {
Enabled bool `yaml:"enabled"`
Requests int `yaml:"requests"`
Period time.Duration `yaml:"period"`
}
RateLimitConfig represents rate limiting configuration
type SocialConfig ¶
type SocialConfig struct {
Enabled bool `yaml:"enabled"`
Providers map[string]SocialProviderConfig `yaml:"providers" validate:"omit_empty,dive"`
}
SocialConfig represents social login configuration
type SocialProviderConfig ¶
type SocialProviderConfig struct {
ClientID string `yaml:"clientID" validate:"required"`
ClientSecret string `yaml:"clientSecret" validate:"required"`
RedirectURL string `yaml:"redirectURL" validate:"required"`
Scopes []string `yaml:"scopes" validate:"required"`
}
SocialProviderConfig represents configuration for a social login provider