auth

package module
v0.6.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 10, 2026 License: Apache-2.0 Imports: 29 Imported by: 2

Documentation

Overview

Package auth offers the account commands of a program whose accounts live in gouncer's Postgres store.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Authorize added in v0.2.0

func Authorize(cfg Config) func(ctx context.Context, call gonsole.Call, capability string) error

Authorize returns the check that refuses an acting account that may not run a command naming capability.

func Commands

func Commands(cfg Config) []gonsole.Command

Commands returns every account command over cfg, in the order they are declared.

func CreateAdmin

func CreateAdmin(cfg Config) gonsole.Command

CreateAdmin returns account:create-admin, which creates one account under a known role.

func Disable

func Disable(cfg Config) gonsole.Command

Disable returns account:disable, which disables one account.

func Enable

func Enable(cfg Config) gonsole.Command

Enable returns account:enable, which enables one disabled account.

func EnsureAccounts

func EnsureAccounts(ctx context.Context, store gouncer.Store, accounts []Account, w io.Writer) error

EnsureAccounts creates each account unless its address is taken and writes one line per account.

func GrantRole

func GrantRole(cfg Config) gonsole.Command

GrantRole returns account:grant-role, which gives a known role to every account holding none.

func List

func List(cfg Config) gonsole.Command

List returns account:list, which lists every account with its role and standing.

func Migration

func Migration() gonsole.Step

Migration returns the step that applies gouncer's schema.

func Record added in v0.2.0

func Record(cfg Config) func(ctx context.Context, call gonsole.Call, command string) error

Record returns the hook that stores one row naming the acting account and the command it applied.

func RecordMigration added in v0.2.0

func RecordMigration() gonsole.Step

RecordMigration returns the step that applies the schema keeping the command records.

func Records added in v0.2.0

func Records(cfg Config) gonsole.Command

Records returns account:records, which lists the latest command records.

func SetRole

func SetRole(cfg Config) gonsole.Command

SetRole returns account:role, which sets one account's role.

Types

type Account

type Account struct {
	// Email is the account's address.
	Email string
	// Name is the account's display name.
	Name string
	// Password is the account's demo password.
	Password string
	// Role is the role the account stands under.
	Role string
}

Account is one demo account a seed step ensures.

type Accounts added in v0.6.0

type Accounts interface {
	authkit.AdminStore

	// GrantRoleToRoleless gives role to every account holding none and returns how many it changed.
	GrantRoleToRoleless(ctx context.Context, role string) (int64, error)
}

Accounts is the account store the account commands and Authorize run on.

type Config

type Config struct {
	// Roles returns the program's role vocabulary.
	Roles func(ctx context.Context, call gonsole.Call) (Roles, error)
	// Capability names the capability every account write requires, empty for none.
	Capability string
	// RecordTimeout bounds storing one record when the COMMAND_RECORD_TIMEOUT setting is empty.
	RecordTimeout time.Duration
	// RecordsLimit is how many records account:records lists when the COMMAND_RECORDS_LIMIT setting is empty.
	RecordsLimit int
	// Stores builds a call's stores and the release of what it opened, if any, nil for PostgreSQL at the database setting.
	Stores func(ctx context.Context, call gonsole.Call) (Stores, func(context.Context) error, error)
}

Config is what a program hands its account commands.

func (Config) Validate added in v0.2.0

func (c Config) Validate(env gonsole.Env) error

Validate reads every setting the account hooks and account:records read.

type Entry added in v0.6.0

type Entry struct {
	// ID is the entry's UUIDv7, which the document of account:records leaves out.
	ID string `json:"-"`
	// AppliedAt is when the command applied.
	AppliedAt time.Time `json:"applied_at"`
	// Actor is the address of the acting account.
	Actor string `json:"actor"`
	// AccountID is the id of the account at the actor's address, nil when none held it.
	AccountID *string `json:"account_id"`
	// Command is the full name of the command.
	Command string `json:"command"`
	// Args are the command's positional arguments.
	Args []string `json:"args"`
	// Flags maps each of the command's own flags the line set to its value.
	Flags map[string]string `json:"flags"`
}

Entry is one applied guarded command as account:records answers it.

type RecordStore added in v0.6.0

type RecordStore interface {
	// Held reports whether the database holds the table the records go to.
	Held(ctx context.Context) (bool, error)
	// Insert stores entry, finding the account its actor names.
	Insert(ctx context.Context, entry Entry) error
	// Latest returns the newest entries first, at most limit of them.
	Latest(ctx context.Context, limit int) ([]Entry, error)
}

RecordStore is the store of the command records Record writes and account:records lists.

func PostgresRecords added in v0.6.0

func PostgresRecords(pool *pgxpool.Pool) RecordStore

PostgresRecords returns the record store of the PostgreSQL database behind pool.

type Roles

type Roles struct {
	// Known lists every role an account may hold.
	Known []string
	// Privileged lists the roles one enabled account must always keep.
	Privileged gouncer.Roles
	// Capabilities maps each role onto the capabilities it carries, a role left out carrying none.
	Capabilities map[string][]string
}

Roles is one program's role vocabulary.

func RolesFrom added in v0.5.0

func RolesFrom(registry interface {
	Roles() []string
	CapabilitiesOf(role string) []string
}, privileged gouncer.Roles) Roles

RolesFrom returns the role vocabulary a registry holds, with the privileged roles the program names.

type Stores added in v0.6.0

type Stores struct {
	// Accounts holds the accounts.
	Accounts Accounts
	// Records holds the command records.
	Records RecordStore
}

Stores is the account store and the record store one call runs on.

Directories

Path Synopsis
Package recordstest is the contract every record store of gonsole/auth keeps, run as one test suite.
Package recordstest is the contract every record store of gonsole/auth keeps, run as one test suite.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL