authfile

package
v0.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Overview

Package authfile stores local platform login credentials for the mcp-runtime CLI (API base URL, token, optional registry host). It is the foundation for user-facing flows that do not use kubeconfig.

Index

Constants

View Source
const EnvAPIProfile = "MCP_PLATFORM_API_PROFILE"

EnvAPIProfile selects a saved platform API profile from the MCP Runtime config file.

View Source
const EnvAPIToken = "MCP_PLATFORM_API_TOKEN"

EnvAPIToken is the environment variable for a platform API token without using a saved file. #nosec G101 -- environment variable name only; no secret value is embedded.

View Source
const EnvAPIURL = "MCP_PLATFORM_API_URL"

EnvAPIURL is the default platform API base URL (e.g. https://platform.example.com).

Variables

View Source
var ErrInvalid = errors.New("saved credentials are invalid")

ErrInvalid is returned when a credentials file exists but is malformed.

View Source
var ErrNotFound = errors.New("not logged in: no saved credentials")

ErrNotFound is returned when no credentials file exists or it is empty.

Functions

func ConfigDir

func ConfigDir() (string, error)

ConfigDir is the per-user MCP Runtime configuration directory.

func CurrentRegistryHost

func CurrentRegistryHost() string

CurrentRegistryHost returns the registry host saved with the active platform login.

func FilePath

func FilePath() (string, error)

FilePath returns the default path to the MCP Runtime config file.

func MaskToken

func MaskToken(s string) string

MaskToken returns a non-reversible display form (last 4 runes, if any).

func NormalizeProfileName

func NormalizeProfileName(raw string) string

NormalizeProfileName converts a user-facing profile label to a stable key.

func Remove

func Remove(path string) error

Remove deletes the credentials file at path if it exists.

func ResolveToken

func ResolveToken() (token, apiBase, source string, err error)

ResolveToken returns a token and API base URL: first from the environment, then the default credentials file. If apiBase is empty, callers may still have a token from EnvAPIToken only.

func Save

func Save(path string, c *Credentials) error

Save writes credentials to path with restrictive permissions (0600).

func SaveProfile

func SaveProfile(path, profile string, account CredentialAccount) error

SaveProfile saves one named identity and marks it as current.

func SelectProfile

func SelectProfile(path, profile string) error

SelectProfile marks a saved identity as current.

Types

type CredentialAccount

type CredentialAccount struct {
	APIBaseURL   string    `json:"api_url"`
	Token        string    `json:"token"`
	Role         string    `json:"role,omitempty"`
	RegistryHost string    `json:"registry_host,omitempty"`
	Username     string    `json:"username,omitempty"`
	UpdatedAt    time.Time `json:"updated_at,omitempty"`
}

CredentialAccount is one saved platform identity.

type Credentials

type Credentials struct {
	Current      string                       `json:"current,omitempty"`
	Accounts     map[string]CredentialAccount `json:"accounts,omitempty"`
	APIBaseURL   string                       `json:"api_url,omitempty"`
	Token        string                       `json:"token,omitempty"`
	Role         string                       `json:"role,omitempty"`
	RegistryHost string                       `json:"registry_host,omitempty"`
	UpdatedAt    time.Time                    `json:"updated_at"`
}

Credentials holds platform API identities saved after `mcp-runtime auth login`.

func Load

func Load(path string) (*Credentials, error)

Load reads credentials from path. If the file is missing, returns ErrNotFound.

func (*Credentials) ProfileNames

func (c *Credentials) ProfileNames() []string

ProfileNames returns saved profile names in stable order.

func (*Credentials) SelectedAccount

func (c *Credentials) SelectedAccount(profile string) (CredentialAccount, string, error)

SelectedAccount returns the requested saved identity, or the current identity when profile is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL