Documentation
¶
Overview ¶
Package auth offers the account commands of a program whose accounts live in gouncer's Postgres store.
Index ¶
- func Authorize(cfg Config) func(ctx context.Context, call gonsole.Call, capability string) error
- func Commands(cfg Config) []gonsole.Command
- func CreateAdmin(cfg Config) gonsole.Command
- func Disable(cfg Config) gonsole.Command
- func Enable(cfg Config) gonsole.Command
- func EnsureAccounts(ctx context.Context, store gouncer.Store, accounts []Account, w io.Writer) error
- func GrantRole(cfg Config) gonsole.Command
- func List(cfg Config) gonsole.Command
- func Migration() gonsole.Step
- func Record(cfg Config) func(ctx context.Context, call gonsole.Call, command string) error
- func RecordMigration() gonsole.Step
- func Records(cfg Config) gonsole.Command
- func SetRole(cfg Config) gonsole.Command
- type Account
- type Accounts
- type Config
- type Entry
- type RecordStore
- type Roles
- type Stores
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func Authorize ¶ added in v0.2.0
Authorize returns the check that refuses an acting account that may not run a command naming capability.
func CreateAdmin ¶
CreateAdmin returns account:create-admin, which creates one account under a known role.
func EnsureAccounts ¶
func EnsureAccounts(ctx context.Context, store gouncer.Store, accounts []Account, w io.Writer) error
EnsureAccounts creates each account unless its address is taken and writes one line per account.
func GrantRole ¶
GrantRole returns account:grant-role, which gives a known role to every account holding none.
func Record ¶ added in v0.2.0
Record returns the hook that stores one row naming the acting account and the command it applied.
func RecordMigration ¶ added in v0.2.0
RecordMigration returns the step that applies the schema keeping the command records.
Types ¶
type Account ¶
type Account struct {
// Email is the account's address.
Email string
// Name is the account's display name.
Name string
// Password is the account's demo password.
Password string
// Role is the role the account stands under.
Role string
}
Account is one demo account a seed step ensures.
type Accounts ¶ added in v0.6.0
type Accounts interface {
authkit.AdminStore
// GrantRoleToRoleless gives role to every account holding none and returns how many it changed.
GrantRoleToRoleless(ctx context.Context, role string) (int64, error)
}
Accounts is the account store the account commands and Authorize run on.
type Config ¶
type Config struct {
// Roles returns the program's role vocabulary.
Roles func(ctx context.Context, call gonsole.Call) (Roles, error)
// Capability names the capability every account write requires, empty for none.
Capability string
// RecordTimeout bounds storing one record when the COMMAND_RECORD_TIMEOUT setting is empty.
RecordTimeout time.Duration
// RecordsLimit is how many records account:records lists when the COMMAND_RECORDS_LIMIT setting is empty.
RecordsLimit int
// Stores builds a call's stores and the release of what it opened, if any, nil for PostgreSQL at the database setting.
Stores func(ctx context.Context, call gonsole.Call) (Stores, func(context.Context) error, error)
}
Config is what a program hands its account commands.
type Entry ¶ added in v0.6.0
type Entry struct {
// ID is the entry's UUIDv7, which the document of account:records leaves out.
ID string `json:"-"`
// AppliedAt is when the command applied.
AppliedAt time.Time `json:"applied_at"`
// Actor is the address of the acting account.
Actor string `json:"actor"`
// AccountID is the id of the account at the actor's address, nil when none held it.
AccountID *string `json:"account_id"`
// Command is the full name of the command.
Command string `json:"command"`
// Args are the command's positional arguments.
Args []string `json:"args"`
// Flags maps each of the command's own flags the line set to its value.
Flags map[string]string `json:"flags"`
}
Entry is one applied guarded command as account:records answers it.
type RecordStore ¶ added in v0.6.0
type RecordStore interface {
// Held reports whether the database holds the table the records go to.
Held(ctx context.Context) (bool, error)
// Insert stores entry, finding the account its actor names.
Insert(ctx context.Context, entry Entry) error
// Latest returns the newest entries first, at most limit of them.
Latest(ctx context.Context, limit int) ([]Entry, error)
}
RecordStore is the store of the command records Record writes and account:records lists.
func PostgresRecords ¶ added in v0.6.0
func PostgresRecords(pool *pgxpool.Pool) RecordStore
PostgresRecords returns the record store of the PostgreSQL database behind pool.
type Roles ¶
type Roles struct {
// Known lists every role an account may hold.
Known []string
// Privileged lists the roles one enabled account must always keep.
Privileged gouncer.Roles
// Capabilities maps each role onto the capabilities it carries, a role left out carrying none.
Capabilities map[string][]string
}
Roles is one program's role vocabulary.
type Stores ¶ added in v0.6.0
type Stores struct {
// Accounts holds the accounts.
Accounts Accounts
// Records holds the command records.
Records RecordStore
}
Stores is the account store and the record store one call runs on.
Source Files
¶
Directories
¶
| Path | Synopsis |
|---|---|
|
Package recordstest is the contract every record store of gonsole/auth keeps, run as one test suite.
|
Package recordstest is the contract every record store of gonsole/auth keeps, run as one test suite. |