platformauth

package
v0.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Index

Constants

View Source
const (
	AudiencePlatform  = "platform-api"
	AudienceRuntime   = "runtime-api"
	AudienceAnalytics = "analytics-api"
)
View Source
const (
	RoleAdmin = "admin"
	RoleUser  = "user"
)
View Source
const Issuer = "github.com/mcp-runtime/mcp-runtime"
View Source
const UnknownRequestIP = "unknown"

Variables

This section is empty.

Functions

func AuditIdentityLabel

func AuditIdentityLabel(p Principal) string

func AuditSource

func AuditSource(r *http.Request, p Principal) string

func RequestIP

func RequestIP(r *http.Request) string

func RequestSource

func RequestSource(r *http.Request) string

func RequiredAudiences

func RequiredAudiences() []string

func Sign

func Sign(secret []byte, p Principal, ttl time.Duration, audiences []string) (string, error)

func WithPrincipal

func WithPrincipal(ctx context.Context, p Principal) context.Context

Types

type Authenticator

type Authenticator struct {
	Secret          []byte
	Audience        string
	ServiceAPIKeys  map[string]struct{}
	AdminAPIKeys    map[string]struct{}
	UserKeyResolver UserKeyResolver
	OIDC            OIDCVerifier
	PublicFallback  func(*http.Request) (Principal, bool)
}

func (Authenticator) AuthenticateRequest

func (a Authenticator) AuthenticateRequest(r *http.Request) (Principal, bool, error)

func (Authenticator) Middleware

func (a Authenticator) Middleware(next http.Handler) http.Handler

func (Authenticator) RequireRole

func (a Authenticator) RequireRole(role string, next http.Handler) http.Handler

type Claims

type Claims struct {
	jwt.RegisteredClaims
	Email             string      `json:"email,omitempty"`
	Role              string      `json:"role,omitempty"`
	Namespace         string      `json:"namespace,omitempty"`
	Teams             []TeamClaim `json:"teams,omitempty"`
	AllowedNamespaces []string    `json:"allowed_namespaces,omitempty"`
	APIKeyID          string      `json:"api_key_id,omitempty"`
	AuthType          string      `json:"auth_type,omitempty"`
	IsService         bool        `json:"is_service,omitempty"`
}

func ClaimsFromPrincipal

func ClaimsFromPrincipal(p Principal) Claims

func Verify

func Verify(secret []byte, token, expectedAudience string) (Claims, error)

type HTTPUserKeyResolver

type HTTPUserKeyResolver struct {
	BaseURL  string
	Token    string
	Client   *http.Client
	CacheTTL time.Duration
	// contains filtered or unexported fields
}

func (*HTTPUserKeyResolver) ResolveAPIKey

func (r *HTTPUserKeyResolver) ResolveAPIKey(ctx context.Context, rawKey string) (Principal, bool, error)

type OIDCVerifier

type OIDCVerifier interface {
	Verify(context.Context, string) (Principal, bool, error)
}

type Principal

type Principal struct {
	Role              string          `json:"role"`
	Subject           string          `json:"subject,omitempty"`
	Email             string          `json:"email,omitempty"`
	Namespace         string          `json:"namespace,omitempty"`
	AllowedNamespaces []string        `json:"allowed_namespaces,omitempty"`
	Teams             []PrincipalTeam `json:"teams,omitempty"`
	AuthType          string          `json:"auth_type,omitempty"`
	APIKeyID          string          `json:"api_key_id,omitempty"`
	IsService         bool            `json:"is_service,omitempty"`
}

func FromContext

func FromContext(ctx context.Context) (Principal, bool)

func ToPrincipal

func ToPrincipal(claims Claims) Principal

func (Principal) HasNamespace

func (p Principal) HasNamespace(namespace string) bool

func (Principal) TeamForNamespace

func (p Principal) TeamForNamespace(namespace string) (PrincipalTeam, bool)

func (Principal) TeamRole

func (p Principal) TeamRole(slug string) string

func (Principal) UserID

func (p Principal) UserID() string

type PrincipalTeam

type PrincipalTeam = TeamClaim

type TeamClaim

type TeamClaim struct {
	ID        string `json:"id"`
	Slug      string `json:"slug"`
	Name      string `json:"name"`
	Namespace string `json:"namespace"`
	Role      string `json:"role"`
}

type UserKeyResolver

type UserKeyResolver interface {
	ResolveAPIKey(context.Context, string) (Principal, bool, error)
}

func ChainUserKeyResolvers

func ChainUserKeyResolvers(resolvers ...UserKeyResolver) UserKeyResolver

ChainUserKeyResolvers tries resolvers in order until one recognizes the API key.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL