dashauth

package
v1.12.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 2, 2026 License: Apache-2.0 Imports: 5 Imported by: 1

Documentation

Overview

Package dashauth provides authentication and authorization abstractions for the dashboard extension. It is intentionally decoupled from the auth extension so the dashboard has no hard dependency on any specific auth provider.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func ForgeMiddleware

func ForgeMiddleware(checker AuthChecker) forge.Middleware

ForgeMiddleware returns forge.Middleware that runs the AuthChecker and stores the resulting UserInfo in the request context. The dashboard attaches it to the contract routes, so the dispatcher and the principal endpoint see the caller.

It does NOT block unauthenticated requests — it only populates the context. Access is enforced per intent by the contract's Requires predicate, and the principal endpoint reports 401 when auth is on and nobody is signed in.

func HasTenantInContext added in v1.2.0

func HasTenantInContext(ctx context.Context) bool

HasTenantInContext returns true if the context contains a tenant with a non-empty ID.

func IsAuthenticated

func IsAuthenticated(ctx context.Context) bool

IsAuthenticated returns true if the context contains an authenticated user.

func RequestFromContext added in v1.6.4

func RequestFromContext(ctx context.Context) *http.Request

RequestFromContext returns the Request previously stashed by WithHTTP, or nil outside an HTTP-served dispatch.

func ResponseWriterFromContext added in v1.6.4

func ResponseWriterFromContext(ctx context.Context) http.ResponseWriter

ResponseWriterFromContext returns the ResponseWriter previously stashed by WithHTTP, or nil when called outside an HTTP-served dispatch (background jobs, tests).

func TenantMiddleware added in v1.2.0

func TenantMiddleware(resolver TenantResolver) forge.Middleware

TenantMiddleware returns forge.Middleware that runs the TenantResolver and stores the resulting TenantInfo in the request context. Like ForgeMiddleware for auth, it does NOT block requests without a tenant — it only populates the context so downstream handlers can access tenant info.

func WithHTTP added in v1.6.4

WithHTTP stashes the live ResponseWriter and Request on ctx so contract command handlers that legitimately need to touch HTTP — e.g. the auth extension's auth.login handler that issues a Set-Cookie — can reach them. The contract transport calls this before dispatching commands.

Most contract handlers are pure data and should NOT pull these out; reaching for the response writer is an escape hatch for the small set of concerns where the cookie/header IS the contract (auth, downloads).

func WithTenant added in v1.2.0

func WithTenant(ctx context.Context, tenant *TenantInfo) context.Context

WithTenant stores a TenantInfo in the context.

func WithUser

func WithUser(ctx context.Context, user *UserInfo) context.Context

WithUser stores a UserInfo in the context.

Types

type AuthChecker

type AuthChecker interface {
	// CheckAuth inspects the request and returns a UserInfo if authenticated.
	// Returns nil (not an error) when the request is unauthenticated.
	// Returns an error only for infrastructure failures (e.g. token validation
	// service unreachable).
	CheckAuth(ctx context.Context, r *http.Request) (*UserInfo, error)
}

AuthChecker validates authentication state from HTTP requests. It is the primary abstraction the dashboard uses to check whether a request is authenticated. Implementations typically delegate to an auth extension's registry or a custom authentication mechanism.

type AuthCheckerFunc

type AuthCheckerFunc func(ctx context.Context, r *http.Request) (*UserInfo, error)

AuthCheckerFunc is a function adapter for AuthChecker.

func (AuthCheckerFunc) CheckAuth

func (f AuthCheckerFunc) CheckAuth(ctx context.Context, r *http.Request) (*UserInfo, error)

CheckAuth implements AuthChecker.

type ScopeTenantResolver added in v1.2.0

type ScopeTenantResolver struct{}

ScopeTenantResolver is a default TenantResolver that reads forge.Scope from the request context and converts it to TenantInfo. This works out of the box when forge's scope middleware is in the chain.

func (ScopeTenantResolver) ResolveTenant added in v1.2.0

func (s ScopeTenantResolver) ResolveTenant(ctx context.Context, _ *http.Request) (*TenantInfo, error)

ResolveTenant reads forge.Scope from context and converts to TenantInfo.

type TenantInfo added in v1.2.0

type TenantInfo struct {
	// ID is the tenant identifier (AppID or OrgID depending on Type).
	ID string

	// Name is the human-readable display name for this tenant.
	Name string

	// Type indicates whether this is an app-level or org-level tenant.
	Type TenantType

	// AppID is always present — the application identifier.
	AppID string

	// OrgID is present only for org-level tenants.
	OrgID string

	// LogoURL is an optional URL for the tenant's logo/branding.
	LogoURL string

	// Metadata holds additional tenant-specific data.
	Metadata map[string]any
}

TenantInfo represents the current tenant context for the dashboard. It bridges forge.Scope into a richer dashboard-specific type with display metadata.

func TenantFromContext added in v1.2.0

func TenantFromContext(ctx context.Context) *TenantInfo

TenantFromContext retrieves the TenantInfo from the context. Returns nil if no tenant is stored.

func (*TenantInfo) HasTenant added in v1.2.0

func (t *TenantInfo) HasTenant() bool

HasTenant returns true if the tenant info is non-nil and has a non-empty ID.

func (*TenantInfo) IsApp added in v1.2.0

func (t *TenantInfo) IsApp() bool

IsApp returns true if this is an app-level tenant.

func (*TenantInfo) IsOrg added in v1.2.0

func (t *TenantInfo) IsOrg() bool

IsOrg returns true if this is an organization-level tenant.

type TenantResolver added in v1.2.0

type TenantResolver interface {
	ResolveTenant(ctx context.Context, r *http.Request) (*TenantInfo, error)
}

TenantResolver resolves the current tenant from a request context. Implementations typically read forge.Scope from context and enrich it with display name, logo, etc.

type TenantResolverFunc added in v1.2.0

type TenantResolverFunc func(ctx context.Context, r *http.Request) (*TenantInfo, error)

TenantResolverFunc is a function adapter for TenantResolver.

func (TenantResolverFunc) ResolveTenant added in v1.2.0

func (f TenantResolverFunc) ResolveTenant(ctx context.Context, r *http.Request) (*TenantInfo, error)

ResolveTenant implements TenantResolver.

type TenantType added in v1.2.0

type TenantType string

TenantType identifies the type of tenant scope.

const (
	// TenantTypeApp indicates an application-level tenant.
	TenantTypeApp TenantType = "app"
	// TenantTypeOrg indicates an organization-level tenant.
	TenantTypeOrg TenantType = "org"
)

type UserInfo

type UserInfo struct {
	// Subject is the unique user identifier (e.g. user ID, email, or sub claim).
	Subject string

	// DisplayName is the user's display name.
	DisplayName string

	// Email is the user's email address.
	Email string

	// AvatarURL is the URL of the user's avatar image.
	AvatarURL string

	// Roles holds the user's roles (e.g. "admin", "editor").
	Roles []string

	// Scopes holds the user's OAuth2 scopes or permission strings.
	Scopes []string

	// ProviderName identifies which auth provider authenticated this user.
	ProviderName string

	// Claims holds additional authentication claims.
	Claims map[string]any

	// Metadata holds provider-specific metadata.
	Metadata map[string]any
}

UserInfo represents an authenticated dashboard user. This type is decoupled from any specific auth provider — adapters convert provider-specific auth contexts into UserInfo.

func UserFromContext

func UserFromContext(ctx context.Context) *UserInfo

UserFromContext retrieves the UserInfo from the context. Returns nil if no user is stored (i.e. unauthenticated request).

func (*UserInfo) Authenticated

func (u *UserInfo) Authenticated() bool

Authenticated returns true if the user has a non-empty Subject.

func (*UserInfo) GetClaim

func (u *UserInfo) GetClaim(key string) (any, bool)

GetClaim retrieves a claim by key.

func (*UserInfo) HasAnyRole

func (u *UserInfo) HasAnyRole(roles ...string) bool

HasAnyRole checks if the user has any of the specified roles.

func (*UserInfo) HasRole

func (u *UserInfo) HasRole(role string) bool

HasRole checks if the user has a specific role.

func (*UserInfo) HasScope

func (u *UserInfo) HasScope(scope string) bool

HasScope checks if the user has a specific scope.

func (*UserInfo) Initials

func (u *UserInfo) Initials() string

Initials returns the user's initials (up to 2 characters) for avatar fallback.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL