Documentation
¶
Overview ¶
Package auth contains operator API-key generation and authentication helpers.
Index ¶
Constants ¶
This section is empty.
Variables ¶
View Source
var ErrInvalidCredentials = errors.New("invalid API credentials")
Functions ¶
func GenerateAPIKey ¶
GenerateAPIKey creates a raw API key and its SHA-256 hash. Only the caller should ever receive the raw value; the hash is what belongs in persistence.
func HashAPIKey ¶
HashAPIKey returns the deterministic storage hash for a raw API key.
Types ¶
type APIKeyStore ¶
APIKeyStore is the persistence seam required to authenticate API keys.
type Principal ¶
type Principal struct {
KeyID model.APIKeyID
Role model.APIKeyRole
}
Principal identifies the API key that authenticated a request.
func Authenticate ¶
func Authenticate(ctx context.Context, keys APIKeyStore, raw string, now time.Time) (Principal, error)
Authenticate validates a raw bearer credential against persisted key metadata. Expired, revoked, malformed, and unknown keys are indistinguishable to callers so the API does not reveal which key records exist.
Click to show internal directories.
Click to hide internal directories.