identity

package
v0.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Overview

Package identity provides shared SPIFFE session identity parsing and formatting used by the gateway, platform API, and adapter clients.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func CertificateHasURI

func CertificateHasURI(cert *x509.Certificate, want string) bool

CertificateHasURI reports whether cert carries want as a URI SAN.

func FirstClientSPIFFEURI

func FirstClientSPIFFEURI(cert *x509.Certificate, trustDomain string) string

FirstClientSPIFFEURI returns the first spiffe:// URI SAN on cert whose trust domain matches trustDomain when trustDomain is non-empty. Returns "" when no matching URI is present.

func ParseSessionSPIFFE

func ParseSessionSPIFFE(raw, trustDomain string) (namespace, sessionID string, ok bool)

ParseSessionSPIFFE parses a session-bound SPIFFE ID of the form spiffe://<trustDomain>/ns/<namespace>/session/<sessionID>. It is deliberately strict and fails closed on any deviation (wrong scheme, trust domain, or path).

func SessionSPIFFEID

func SessionSPIFFEID(trustDomain, namespace, session string) string

SessionSPIFFEID returns the canonical session-bound SPIFFE URI: spiffe://<trustDomain>/ns/<namespace>/session/<session>.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL