security

package
v1.12.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 2, 2026 License: Apache-2.0 Imports: 9 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type CSRFManager

type CSRFManager struct {
	// contains filtered or unexported fields
}

CSRFManager handles CSRF token generation and validation. Tokens are produced as HMAC-SHA256(secret, timestamp) + "." + timestamp, where timestamp is the Unix epoch in seconds. Tokens older than one hour are rejected during validation.

func NewCSRFManager

func NewCSRFManager() *CSRFManager

NewCSRFManager creates a new CSRF manager with a cryptographically random secret.

func (*CSRFManager) GenerateToken

func (m *CSRFManager) GenerateToken() string

GenerateToken creates a new CSRF token. The token encodes the current timestamp and an HMAC signature so that it can be verified later without server-side storage.

Token format: hex(HMAC-SHA256(secret, timestamp)) + "." + timestamp.

func (*CSRFManager) ValidateToken

func (m *CSRFManager) ValidateToken(token string) bool

ValidateToken validates a CSRF token. A token is valid when:

  1. It is well-formed (contains exactly one separator).
  2. The HMAC signature matches the recomputed value.
  3. The embedded timestamp is no older than csrfMaxAge (1 hour).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL