config

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 15, 2026 License: MIT Imports: 2 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

View Source
var (
	ErrMissingJWTSecret          = fmt.Errorf("JWT secret is required")
	ErrMissingJWTKeyPair         = fmt.Errorf("JWT private/public key pair is required when algorithm is RS256")
	ErrMissingRefreshTokenSecret = fmt.Errorf("JWT refresh token secret is required")
	ErrInvalidJWTExpiry          = fmt.Errorf("invalid JWT expiry time")
	ErrInvalidRefreshExpiry      = fmt.Errorf("invalid refresh token expiry time")
	ErrInvalidPasswordLength     = fmt.Errorf("minimum password length must be at least 8 characters")
	ErrInvalidAPIKeyLength       = fmt.Errorf("API key length must be at least 16 characters")
	ErrInvalidClerkConfig        = fmt.Errorf("clerk API endpoint is required when API key is provided")

	ErrInvalidAuthorizationSource     = fmt.Errorf(`authorization source must be "database" or "file"`)
	ErrMissingAuthorizationPolicyPath = fmt.Errorf(`authorization policyPath is required when source is "file"`)
)

Configuration errors

Functions

This section is empty.

Types

type APIKeyConfig

type APIKeyConfig struct {
	Length     int             `yaml:"length"`
	ExpiryTime time.Duration   `yaml:"expiryTime"`
	AllowedIPs []string        `yaml:"allowedIPs"`
	RateLimit  RateLimitConfig `yaml:"rateLimit"`
}

APIKeyConfig represents API key configuration

type AuthorizationConfig

type AuthorizationConfig struct {
	// Source selects where casbin policy (p) and grouping (g) rows live:
	// "database" (gorm-adapter, reading/writing through the host app's own
	// DB — the historical default behavior, kept as the zero-value default
	// for full backward compatibility) or "file" (casbin's built-in
	// file-adapter, reading/writing PolicyPath).
	Source string `yaml:"source" validate:"omitempty,oneof=database file"`

	// ModelPath, if set, loads the casbin RBAC model from this file instead
	// of the package's embedded default (rbacModelConf). Most hosts should
	// leave this empty.
	ModelPath string `yaml:"modelPath"`

	// PolicyPath is the casbin policy CSV path, required only when
	// Source == "file".
	PolicyPath string `yaml:"policyPath" validate:"required_if=Source file"`

	// MiddlewareEnabled preserves the old no-op-if-disabled behavior of
	// AuthMiddleware.RequireRole/RequirePermission — when false (the
	// default), those two middlewares are no-ops regardless of what's in
	// the enforcer, exactly like the old MiddlewareConfig.AuthorizationEnabled
	// flag. The enforcer itself is always constructed now (AuthorizationManager
	// needs it unconditionally for role/permission management), so this only
	// gates the two HTTP middlewares, not enforcer construction.
	MiddlewareEnabled bool `yaml:"middlewareEnabled"`

	// ExposeManagementAPI opts a host app into registering the generic
	// /auth/roles, /auth/roles/:name/permissions, etc. HTTP routes (see
	// handlers.NewAuthorizationHandler). Default false — this is a
	// privileged CRUD surface over roles/permissions, not every host wants
	// it registered by default.
	ExposeManagementAPI bool `yaml:"exposeManagementAPI"`
}

AuthorizationConfig configures the module's single shared casbin enforcer, used both by AuthorizationManager (role/permission CRUD and Enforce calls made by consuming-app code) and by AuthMiddleware (HTTP-level RequireRole/RequirePermission gating) — see authorization.NewAuthorizationManager, which owns constructing the enforcer from this config, and middleware.NewAuthMiddleware, which now receives that same manager instead of building a second, independent enforcer (as it did previously).

type ClerkConfig

type ClerkConfig struct {
	APIKey      string `yaml:"apiKey"`
	APIEndpoint string `yaml:"apiEndpoint"`
	FrontendAPI string `yaml:"frontendAPI"`
}

ClerkConfig represents Clerk.com configuration

type Config

type Config struct {
	JWT                     JWTConfig                    `yaml:"jwt"`
	Backends                []string                     `yaml:"backends" validate:"required"`
	PasswordPolicy          PasswordPolicyConfig         `yaml:"passwordPolicy"`
	APIKey                  APIKeyConfig                 `yaml:"apiKey"`
	Social                  SocialConfig                 `yaml:"social"`
	Clerk                   ClerkConfig                  `yaml:"clerk"`
	Authorization           AuthorizationConfig          `yaml:"authorization"`
	Providers               map[string]map[string]string `yaml:"providers"`
	UserMigrationScriptPath string                       `yaml:"userMigrationScriptPath"`

	// EventsTopic is the Kafka topic auth lifecycle events (login,
	// password reset/changed, user created/updated/deleted — see
	// emitter.AuthEventData.EventType for the specific values) are
	// published to. Left empty, EmitAuthEvent is a no-op: the same
	// "not configured yet" posture other optional Kafka producers in
	// this codebase use, rather than publishing to a topic named after
	// the event type itself (which no broker provisions and fails with
	// "topic or partition does not exist").
	EventsTopic string `yaml:"eventsTopic"`
}

Config represents the authentication module configuration

func Default

func Default() *Config

Default returns the default configuration

func (*Config) Key

func (c *Config) Key() string

func (*Config) Validate

func (c *Config) Validate() error

Validate validates the configuration

type ErrInvalidSocialConfig

type ErrInvalidSocialConfig struct {
	Provider string
}

ErrInvalidSocialConfig represents an error with social provider configuration

func (ErrInvalidSocialConfig) Error

func (e ErrInvalidSocialConfig) Error() string

type JWTConfig

type JWTConfig struct {
	Algorithm          string        `yaml:"algorithm"`
	AccessTokenSecret  string        `yaml:"accessTokenSecret"`
	RefreshTokenSecret string        `yaml:"refreshTokenSecret"`
	PrivateKeyPEM      string        `yaml:"privateKeyPEM"`
	PublicKeyPEM       string        `yaml:"publicKeyPEM"`
	KeyID              string        `yaml:"keyId"`
	AccessTokenExpiry  time.Duration `yaml:"accessTokenExpiry"`
	RefreshTokenExpiry time.Duration `yaml:"refreshTokenExpiry"`
}

JWTConfig represents JWT configuration.

Algorithm controls how *access* tokens are signed: "HS256" (default, a shared secret only this service knows) or "RS256" (an RSA keypair, whose public half can be published via a JWKS endpoint so other services — e.g. Veda, per D6 in the mori platform plan — can verify tokens independently without ever holding a secret that could mint them). Refresh tokens always stay HS256/AccessTokenSecret-adjacent (RefreshTokenSecret): they're exchanged directly with this service and never need third-party verification, so there's no reason to widen their blast radius.

func (JWTConfig) IsRS256

func (c JWTConfig) IsRS256() bool

IsRS256 reports whether access tokens should be RSA-signed.

type PasswordPolicyConfig

type PasswordPolicyConfig struct {
	MinLength      int  `yaml:"minLength"`
	RequireUpper   bool `yaml:"requireUpper"`
	RequireLower   bool `yaml:"requireLower"`
	RequireNumber  bool `yaml:"requireNumber"`
	RequireSpecial bool `yaml:"requireSpecial"`
}

PasswordPolicyConfig represents password policy configuration

type RateLimitConfig

type RateLimitConfig struct {
	Enabled  bool          `yaml:"enabled"`
	Requests int           `yaml:"requests"`
	Period   time.Duration `yaml:"period"`
}

RateLimitConfig represents rate limiting configuration

type SocialConfig

type SocialConfig struct {
	Enabled   bool                            `yaml:"enabled"`
	Providers map[string]SocialProviderConfig `yaml:"providers" validate:"omit_empty,dive"`
}

SocialConfig represents social login configuration

type SocialProviderConfig

type SocialProviderConfig struct {
	ClientID     string   `yaml:"clientID" validate:"required"`
	ClientSecret string   `yaml:"clientSecret" validate:"required"`
	RedirectURL  string   `yaml:"redirectURL" validate:"required"`
	Scopes       []string `yaml:"scopes" validate:"required"`
}

SocialProviderConfig represents configuration for a social login provider

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL