auth

package
v0.1.39 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 14, 2026 License: Apache-2.0 Imports: 10 Imported by: 0

Documentation

Overview

Package auth contains operator API-key generation and authentication helpers.

Index

Constants

This section is empty.

Variables

View Source
var ErrInvalidCredentials = errors.New("invalid API credentials")

Functions

func GenerateAPIKey

func GenerateAPIKey() (raw, hash string, err error)

GenerateAPIKey creates a raw API key and its SHA-256 hash. Only the caller should ever receive the raw value; the hash is what belongs in persistence.

func HashAPIKey

func HashAPIKey(raw string) string

HashAPIKey returns the deterministic storage hash for a raw API key.

Types

type APIKeyStore

type APIKeyStore interface {
	ListAPIKeys(ctx context.Context) ([]model.APIKey, error)
}

APIKeyStore is the persistence seam required to authenticate API keys.

type Principal

type Principal struct {
	KeyID model.APIKeyID
	Role  model.APIKeyRole
}

Principal identifies the API key that authenticated a request.

func Authenticate

func Authenticate(ctx context.Context, keys APIKeyStore, raw string, now time.Time) (Principal, error)

Authenticate validates a raw bearer credential against persisted key metadata. Expired, revoked, malformed, and unknown keys are indistinguishable to callers so the API does not reveal which key records exist.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL