auth

package
v0.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Index

Constants

View Source
const (
	APILoginLockoutBase       = 15 * time.Second
	APILoginLockoutMax        = 5 * time.Minute
	APILoginAttemptIdleTTL    = 30 * time.Minute
	APILoginAttemptMaxEntries = 4096
)
View Source
const (
	DefaultDevUserEmail     = "test@mcpruntime.org"
	DefaultDevUserPassword  = "test@123"
	DefaultDevAdminEmail    = "admin@mcpruntime.org"
	DefaultDevAdminPassword = "admin@123"
)
View Source
const (
	PlatformSignupRequestMaxBytes        int64 = 4 * 1024
	PlatformPasswordLoginRequestMaxBytes int64 = 4 * 1024
	PlatformOIDCLoginRequestMaxBytes     int64 = 8 * 1024
)
View Source
const PlatformAccessTokenTTL = 15 * time.Minute

Variables

This section is empty.

Functions

func HandleOIDCLogin

func HandleOIDCLogin(
	w http.ResponseWriter,
	r *http.Request,
	backend PasswordLoginBackend,
	authenticateRequest func(*http.Request) (platformstore.Principal, bool, error),
	hook func(context.Context, string) (platformstore.User, error),
	unauthorizedErr error,
	requestIP RequestIPFunc,
	requestSource RequestSourceFunc,
	writeJSON JSONWriterFunc,
	writeBodyDecodeError BodyDecodeErrorFunc,
	tokenTTL time.Duration,
	maxBodyBytes int64,
	oidcIssuer string,
	oidcAudience string,
)

func HandlePasswordLogin

func HandlePasswordLogin(
	w http.ResponseWriter,
	r *http.Request,
	backend PasswordLoginBackend,
	tracker *LoginAttemptTracker,
	requestIP RequestIPFunc,
	requestSource RequestSourceFunc,
	writeJSON JSONWriterFunc,
	writeBodyDecodeError BodyDecodeErrorFunc,
	tokenTTL time.Duration,
	maxBodyBytes int64,
)

func JWTSecretFromEnv

func JWTSecretFromEnv() ([]byte, error)

func OIDCAuditResource

func OIDCAuditResource(idToken string) string

func PlatformDSNFromEnv

func PlatformDSNFromEnv() string

func ResolveOIDCLoginUser

func ResolveOIDCLoginUser(
	ctx context.Context,
	idToken string,
	authenticateRequest func(*http.Request) (platformstore.Principal, bool, error),
	unauthorizedErr error,
) (platformstore.User, error)

func RunPlatformAdminBootstrap

func RunPlatformAdminBootstrap(ctx context.Context, opener func(context.Context, string, []byte) (PasswordUserEnsurer, error)) error

func SeedPlatformAdminFromEnv

func SeedPlatformAdminFromEnv(ctx context.Context, store PasswordUserEnsurer) error

func SeedPlatformDevUsersFromEnv

func SeedPlatformDevUsersFromEnv(ctx context.Context, store PasswordUserEnsurer, boolEnv func(string) (bool, bool), envOr func(string, string) string) error

Types

type BodyDecodeErrorFunc

type BodyDecodeErrorFunc func(http.ResponseWriter, error)

type JSONWriterFunc

type JSONWriterFunc func(http.ResponseWriter, int, any)

type LoginAttempt

type LoginAttempt struct {
	Failures    int
	LockedUntil time.Time
	LastSeen    time.Time
}

type LoginAttemptTracker

type LoginAttemptTracker struct {
	// contains filtered or unexported fields
}

func NewLoginAttemptTracker

func NewLoginAttemptTracker(nowFn func() time.Time) *LoginAttemptTracker

func (*LoginAttemptTracker) Allow

func (t *LoginAttemptTracker) Allow(key string) bool

func (*LoginAttemptTracker) RecordFailure

func (t *LoginAttemptTracker) RecordFailure(key string) int

func (*LoginAttemptTracker) RecordSuccess

func (t *LoginAttemptTracker) RecordSuccess(key string) int

type OIDCRequestAuthenticator

type OIDCRequestAuthenticator interface {
	AuthenticateRequest(*http.Request) (platformstore.Principal, bool, error)
}

type PasswordLoginBackend

type PasswordLoginBackend interface {
	AuthenticatePassword(ctx context.Context, email, password string) (platformstore.User, bool, error)
	CreateAccessToken(user platformstore.User, ttl time.Duration) (string, error)
	WriteAudit(ctx context.Context, ev platformstore.AuditEvent)
}

type PasswordUserEnsurer

type PasswordUserEnsurer interface {
	EnsurePasswordUser(ctx context.Context, email, password string, role string) (platformstore.User, error)
}

type RequestIPFunc

type RequestIPFunc func(*http.Request) string

type RequestSourceFunc

type RequestSourceFunc func(*http.Request) string

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL