Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type CSRFManager ¶
type CSRFManager struct {
// contains filtered or unexported fields
}
CSRFManager handles CSRF token generation and validation. Tokens are produced as HMAC-SHA256(secret, timestamp) + "." + timestamp, where timestamp is the Unix epoch in seconds. Tokens older than one hour are rejected during validation.
func NewCSRFManager ¶
func NewCSRFManager() *CSRFManager
NewCSRFManager creates a new CSRF manager with a cryptographically random secret.
func (*CSRFManager) GenerateToken ¶
func (m *CSRFManager) GenerateToken() string
GenerateToken creates a new CSRF token. The token encodes the current timestamp and an HMAC signature so that it can be verified later without server-side storage.
Token format: hex(HMAC-SHA256(secret, timestamp)) + "." + timestamp.
func (*CSRFManager) ValidateToken ¶
func (m *CSRFManager) ValidateToken(token string) bool
ValidateToken validates a CSRF token. A token is valid when:
- It is well-formed (contains exactly one separator).
- The HMAC signature matches the recomputed value.
- The embedded timestamp is no older than csrfMaxAge (1 hour).
Click to show internal directories.
Click to hide internal directories.