Documentation
¶
Index ¶
- Constants
- func AuthorizerOptions(timeout time.Duration) []biscuit.AuthorizerOption
- func MintBiscuitToken(signingKey ed25519.PrivateKey, claims jwt.MapClaims, token *oidc.IDToken, ...) ([]byte, []string, error)
- func MintBootstrapBiscuitToken(signingKey ed25519.PrivateKey, remotePeer peer.ID, role string, ...) ([]byte, error)
- func VerifyAndExtractPeerID(trustedPublicKeys []ed25519.PublicKey, biscuitData []byte, ...) (peer.ID, error)
- func VerifyBiscuit(biscuitData []byte, expectedPeer peer.ID, ...) (*biscuit.Biscuit, error)
- func VerifyBiscuitAndGetKey(biscuitData []byte, expectedPeer peer.ID, ...) (*biscuit.Biscuit, ed25519.PublicKey, error)
- func VerifyBiscuitRole(biscuitData []byte, controlPlanePubKey ed25519.PublicKey, expectedRole string, ...) error
- func VerifyJWT(ctx context.Context, jwtStr string, allowedAudiences []string, ...) (jwt.MapClaims, *oidc.IDToken, error)
Constants ¶
const DefaultAuthorizerTimeout = 1 * time.Second
DefaultAuthorizerTimeout bounds Datalog evaluation when no timeout is configured. biscuit-go defaults to 2ms of wall-clock time, of which a single authorization of a realistic token already spends ~0.14ms (~1.1ms under -race), so ordinary scheduling noise turns into a spurious denial. The amount of work is bounded by the fact and iteration limits; this deadline only caps how long the caller waits.
Variables ¶
This section is empty.
Functions ¶
func AuthorizerOptions ¶
func AuthorizerOptions(timeout time.Duration) []biscuit.AuthorizerOption
AuthorizerOptions returns the authorizer options enforcing a Datalog evaluation budget. A non-positive timeout falls back to DefaultAuthorizerTimeout.
func MintBiscuitToken ¶
func MintBiscuitToken(signingKey ed25519.PrivateKey, claims jwt.MapClaims, token *oidc.IDToken, remotePeer peer.ID, biscuitExpiry time.Time, roles []string, policyRoles []*api.PolicyRole, labels map[string]string) ([]byte, []string, error)
MintBiscuitToken generates a signed Biscuit token for a peer with policy rules based on JWT claims. labels are control-plane-attested key=value claims (canonical, pre-validated); empty means no claims.
func MintBootstrapBiscuitToken ¶
func MintBootstrapBiscuitToken(signingKey ed25519.PrivateKey, remotePeer peer.ID, role string, expiration time.Time, policyRoles []*api.PolicyRole, labels map[string]string) ([]byte, error)
MintBootstrapBiscuitToken generates a signed Biscuit token for a peer using a bootstrap role. labels are control-plane-attested key=value claims (canonical, pre-validated); empty means no claims.
func VerifyAndExtractPeerID ¶
func VerifyAndExtractPeerID(trustedPublicKeys []ed25519.PublicKey, biscuitData []byte, timeout time.Duration) (peer.ID, error)
VerifyAndExtractPeerID checks that the biscuit is signed by one of the trusted keys and returns the peer ID. This function does NOT perform time checks, making it suitable for token refresh flows.
func VerifyBiscuit ¶
func VerifyBiscuit(biscuitData []byte, expectedPeer peer.ID, trustedPublicKeys []ed25519.PublicKey, timeout time.Duration) (*biscuit.Biscuit, error)
VerifyBiscuit verifies the validity of a Biscuit token. It ensures that: 1. The token is cryptographically signed by one of the trustedPublicKeys. 2. The token is not expired. 3. The token is securely bound to the expected remotePeer.
func VerifyBiscuitAndGetKey ¶
Types ¶
This section is empty.