Documentation
¶
Index ¶
- Constants
- func AuditIdentityLabel(p Principal) string
- func AuditSource(r *http.Request, p Principal) string
- func RequestIP(r *http.Request) string
- func RequestSource(r *http.Request) string
- func RequiredAudiences() []string
- func Sign(secret []byte, p Principal, ttl time.Duration, audiences []string) (string, error)
- func WithPrincipal(ctx context.Context, p Principal) context.Context
- type Authenticator
- type Claims
- type HTTPUserKeyResolver
- type OIDCVerifier
- type Principal
- type PrincipalTeam
- type TeamClaim
- type UserKeyResolver
Constants ¶
View Source
const ( AudiencePlatform = "platform-api" AudienceRuntime = "runtime-api" AudienceAnalytics = "analytics-api" )
View Source
const ( RoleAdmin = "admin" RoleUser = "user" )
View Source
const Issuer = "github.com/mcp-runtime/mcp-runtime"
View Source
const UnknownRequestIP = "unknown"
Variables ¶
This section is empty.
Functions ¶
func AuditIdentityLabel ¶
func RequestSource ¶
func RequiredAudiences ¶
func RequiredAudiences() []string
Types ¶
type Authenticator ¶
type Authenticator struct {
Secret []byte
Audience string
ServiceAPIKeys map[string]struct{}
AdminAPIKeys map[string]struct{}
UserKeyResolver UserKeyResolver
OIDC OIDCVerifier
PublicFallback func(*http.Request) (Principal, bool)
}
func (Authenticator) AuthenticateRequest ¶
func (Authenticator) Middleware ¶
func (a Authenticator) Middleware(next http.Handler) http.Handler
func (Authenticator) RequireRole ¶
type Claims ¶
type Claims struct {
jwt.RegisteredClaims
Email string `json:"email,omitempty"`
Role string `json:"role,omitempty"`
Namespace string `json:"namespace,omitempty"`
Teams []TeamClaim `json:"teams,omitempty"`
AllowedNamespaces []string `json:"allowed_namespaces,omitempty"`
APIKeyID string `json:"api_key_id,omitempty"`
AuthType string `json:"auth_type,omitempty"`
IsService bool `json:"is_service,omitempty"`
}
func ClaimsFromPrincipal ¶
type HTTPUserKeyResolver ¶
type HTTPUserKeyResolver struct {
BaseURL string
Token string
Client *http.Client
CacheTTL time.Duration
// contains filtered or unexported fields
}
func (*HTTPUserKeyResolver) ResolveAPIKey ¶
type OIDCVerifier ¶
type Principal ¶
type Principal struct {
Role string `json:"role"`
Subject string `json:"subject,omitempty"`
Email string `json:"email,omitempty"`
Namespace string `json:"namespace,omitempty"`
AllowedNamespaces []string `json:"allowed_namespaces,omitempty"`
Teams []PrincipalTeam `json:"teams,omitempty"`
AuthType string `json:"auth_type,omitempty"`
APIKeyID string `json:"api_key_id,omitempty"`
IsService bool `json:"is_service,omitempty"`
}
func ToPrincipal ¶
func (Principal) HasNamespace ¶
func (Principal) TeamForNamespace ¶
func (p Principal) TeamForNamespace(namespace string) (PrincipalTeam, bool)
type PrincipalTeam ¶
type PrincipalTeam = TeamClaim
type UserKeyResolver ¶
func ChainUserKeyResolvers ¶
func ChainUserKeyResolvers(resolvers ...UserKeyResolver) UserKeyResolver
ChainUserKeyResolvers tries resolvers in order until one recognizes the API key.
Click to show internal directories.
Click to hide internal directories.