Documentation
¶
Overview ¶
Package gin-keycloak implements an Keycloak based authorization middleware for the Gin https://github.com/gin-gonic/gin
Package zalando contains Zalando specific definitions for authorization.
Index ¶
- Variables
- func Auth(accessCheckFunction AccessCheckFunction, endpoints KeycloakConfig) gin.HandlerFunc
- func AuthChain(config KeycloakConfig, accessCheckFunctions ...AccessCheckFunction) gin.HandlerFunc
- func GroupCheck(at []AccessTuple) func(tc *TokenContainer, ctx *gin.Context) bool
- func RequestLogger(keys []string, contentKey string) gin.HandlerFunc
- func UidCheck(at []AccessTuple) func(tc *TokenContainer, ctx *gin.Context) bool
- type AccessCheckFunction
- type AccessTuple
- type KeyCloakToken
- type KeycloakConfig
- type ServiceRole
- type TokenContainer
Constants ¶
This section is empty.
Variables ¶
View Source
var Transport = http.Transport{}
View Source
var VarianceTimer time.Duration = 30000 * time.Millisecond
VarianceTimer controls the max runtime of Auth() and AuthChain() middleware
Functions ¶
func Auth ¶
func Auth(accessCheckFunction AccessCheckFunction, endpoints KeycloakConfig) gin.HandlerFunc
func AuthChain ¶
func AuthChain(config KeycloakConfig, accessCheckFunctions ...AccessCheckFunction) gin.HandlerFunc
func GroupCheck ¶
func GroupCheck(at []AccessTuple) func(tc *TokenContainer, ctx *gin.Context) bool
func RequestLogger ¶
func RequestLogger(keys []string, contentKey string) gin.HandlerFunc
func UidCheck ¶
func UidCheck(at []AccessTuple) func(tc *TokenContainer, ctx *gin.Context) bool
Types ¶
type AccessCheckFunction ¶
type AccessCheckFunction func(tc *TokenContainer, ctx *gin.Context) bool
AccessCheckFunction is a function that checks if a given token grants access.
type AccessTuple ¶
AccessTuple is the type defined for use in AccessTuples.
type KeyCloakToken ¶
type KeyCloakToken struct {
Jti string `json:"jti"`
Exp int64 `json:"exp"`
Nbf int64 `json:"nbf"`
Iat int64 `json:"iat"`
Iss string `json:"iss"`
Aud []string `json:"aud"`
Sub string `json:"sub"`
Typ string `json:"typ"`
Azp string `json:"azp"`
Nonce string `json:"nonce"`
AuthTime int64 `json:"auth_time"`
SessionState string `json:"session_state"`
Acr string `json:"acr"`
ClientSession string `json:"client_session"`
AllowedOrigins []string `json:"allowed-origins"`
ResourceAccess map[string]ServiceRole `json:"resource_access"`
Name string `json:"name"`
PreferredUsername string `json:"preferred_username"`
GivenName string `json:"given_name"`
FamilyName string `json:"family_name"`
Email string `json:"email"`
}
type KeycloakConfig ¶
type ServiceRole ¶
type ServiceRole struct {
Roles []string `json:"roles"`
}
type TokenContainer ¶
type TokenContainer struct {
Token *oauth2.Token
KeyCloakToken *KeyCloakToken
}
TokenContainer stores all relevant token information
func GetTokenContainer ¶
func GetTokenContainer(token *oauth2.Token, config KeycloakConfig) (*TokenContainer, error)
func (*TokenContainer) Valid ¶
func (t *TokenContainer) Valid() bool
Click to show internal directories.
Click to hide internal directories.