identity

package
v0.1.0-alpha.6 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 14, 2026 License: Apache-2.0 Imports: 14 Imported by: 0

Documentation

Index

Constants

View Source
const DefaultAuthorizerTimeout = 1 * time.Second

DefaultAuthorizerTimeout bounds Datalog evaluation when no timeout is configured. biscuit-go defaults to 2ms of wall-clock time, of which a single authorization of a realistic token already spends ~0.14ms (~1.1ms under -race), so ordinary scheduling noise turns into a spurious denial. The amount of work is bounded by the fact and iteration limits; this deadline only caps how long the caller waits.

Variables

This section is empty.

Functions

func AuthorizerOptions

func AuthorizerOptions(timeout time.Duration) []biscuit.AuthorizerOption

AuthorizerOptions returns the authorizer options enforcing a Datalog evaluation budget. A non-positive timeout falls back to DefaultAuthorizerTimeout.

func MintBiscuitToken

func MintBiscuitToken(signingKey ed25519.PrivateKey, claims jwt.MapClaims, token *oidc.IDToken, remotePeer peer.ID, biscuitExpiry time.Time, roles []string, policyRoles []*api.PolicyRole, labels map[string]string) ([]byte, []string, error)

MintBiscuitToken generates a signed Biscuit token for a peer with policy rules based on JWT claims. labels are control-plane-attested key=value claims (canonical, pre-validated); empty means no claims.

func MintBootstrapBiscuitToken

func MintBootstrapBiscuitToken(signingKey ed25519.PrivateKey, remotePeer peer.ID, role string, expiration time.Time, policyRoles []*api.PolicyRole, labels map[string]string) ([]byte, error)

MintBootstrapBiscuitToken generates a signed Biscuit token for a peer using a bootstrap role. labels are control-plane-attested key=value claims (canonical, pre-validated); empty means no claims.

func VerifyAndExtractPeerID

func VerifyAndExtractPeerID(trustedPublicKeys []ed25519.PublicKey, biscuitData []byte, timeout time.Duration) (peer.ID, error)

VerifyAndExtractPeerID checks that the biscuit is signed by one of the trusted keys and returns the peer ID. This function does NOT perform time checks, making it suitable for token refresh flows.

func VerifyBiscuit

func VerifyBiscuit(biscuitData []byte, expectedPeer peer.ID, trustedPublicKeys []ed25519.PublicKey, timeout time.Duration) (*biscuit.Biscuit, error)

VerifyBiscuit verifies the validity of a Biscuit token. It ensures that: 1. The token is cryptographically signed by one of the trustedPublicKeys. 2. The token is not expired. 3. The token is securely bound to the expected remotePeer.

func VerifyBiscuitAndGetKey

func VerifyBiscuitAndGetKey(biscuitData []byte, expectedPeer peer.ID, trustedPublicKeys []ed25519.PublicKey, timeout time.Duration) (*biscuit.Biscuit, ed25519.PublicKey, error)

func VerifyBiscuitRole

func VerifyBiscuitRole(biscuitData []byte, controlPlanePubKey ed25519.PublicKey, expectedRole string, timeout time.Duration) error

VerifyBiscuitRole checks that the biscuit is signed by the control plane's public key and contains the specified role fact.

func VerifyJWT

func VerifyJWT(ctx context.Context, jwtStr string, allowedAudiences []string, providers map[string]*oidc.Provider) (jwt.MapClaims, *oidc.IDToken, error)

VerifyJWT parses and cryptographically validates a JWT token against a list of allowed audiences and resolved OIDC providers.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL