Documentation
¶
Overview ¶
Package authfile stores local platform login credentials for the mcp-runtime CLI (API base URL, token, optional registry host). It is the foundation for user-facing flows that do not use kubeconfig.
Index ¶
- Constants
- Variables
- func ConfigDir() (string, error)
- func CurrentRegistryHost() string
- func FilePath() (string, error)
- func MaskToken(s string) string
- func NormalizeProfileName(raw string) string
- func Remove(path string) error
- func ResolveToken() (token, apiBase, source string, err error)
- func Save(path string, c *Credentials) error
- func SaveProfile(path, profile string, account CredentialAccount) error
- func SelectProfile(path, profile string) error
- type CredentialAccount
- type Credentials
Constants ¶
const EnvAPIProfile = "MCP_PLATFORM_API_PROFILE"
EnvAPIProfile selects a saved platform API profile from the MCP Runtime config file.
const EnvAPIToken = "MCP_PLATFORM_API_TOKEN"
EnvAPIToken is the environment variable for a platform API token without using a saved file. #nosec G101 -- environment variable name only; no secret value is embedded.
const EnvAPIURL = "MCP_PLATFORM_API_URL"
EnvAPIURL is the default platform API base URL (e.g. https://platform.example.com).
Variables ¶
var ErrInvalid = errors.New("saved credentials are invalid")
ErrInvalid is returned when a credentials file exists but is malformed.
var ErrNotFound = errors.New("not logged in: no saved credentials")
ErrNotFound is returned when no credentials file exists or it is empty.
Functions ¶
func CurrentRegistryHost ¶
func CurrentRegistryHost() string
CurrentRegistryHost returns the registry host saved with the active platform login.
func NormalizeProfileName ¶
NormalizeProfileName converts a user-facing profile label to a stable key.
func ResolveToken ¶
ResolveToken returns a token and API base URL: first from the environment, then the default credentials file. If apiBase is empty, callers may still have a token from EnvAPIToken only.
func Save ¶
func Save(path string, c *Credentials) error
Save writes credentials to path with restrictive permissions (0600).
func SaveProfile ¶
func SaveProfile(path, profile string, account CredentialAccount) error
SaveProfile saves one named identity and marks it as current.
func SelectProfile ¶
SelectProfile marks a saved identity as current.
Types ¶
type CredentialAccount ¶
type CredentialAccount struct {
APIBaseURL string `json:"api_url"`
Token string `json:"token"`
Role string `json:"role,omitempty"`
RegistryHost string `json:"registry_host,omitempty"`
Username string `json:"username,omitempty"`
UpdatedAt time.Time `json:"updated_at,omitempty"`
}
CredentialAccount is one saved platform identity.
type Credentials ¶
type Credentials struct {
Current string `json:"current,omitempty"`
Accounts map[string]CredentialAccount `json:"accounts,omitempty"`
APIBaseURL string `json:"api_url,omitempty"`
Token string `json:"token,omitempty"`
Role string `json:"role,omitempty"`
RegistryHost string `json:"registry_host,omitempty"`
UpdatedAt time.Time `json:"updated_at"`
}
Credentials holds platform API identities saved after `mcp-runtime auth login`.
func Load ¶
func Load(path string) (*Credentials, error)
Load reads credentials from path. If the file is missing, returns ErrNotFound.
func (*Credentials) ProfileNames ¶
func (c *Credentials) ProfileNames() []string
ProfileNames returns saved profile names in stable order.
func (*Credentials) SelectedAccount ¶
func (c *Credentials) SelectedAccount(profile string) (CredentialAccount, string, error)
SelectedAccount returns the requested saved identity, or the current identity when profile is empty.