Documentation
¶
Overview ¶
Package secretapi is the admin REST surface for stored secrets (#2051): list, read, create or change, and delete, and an authenticator seed's current code (#2065). The value is write-only: a PUT carries it, and no response ever does.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
Types ¶
type Config ¶
type Config struct {
// Store holds the secrets. nil mounts nothing.
Store Store
// Author resolves the acting admin.
Author func(*http.Request) string
}
Config carries the store and the parent-owned helpers.
type SecretInput ¶
type SecretInput struct {
Description string `json:"description"`
// Kind is "value" (the default on a create) or "totp", an authenticator
// seed given as its otpauth://totp URI or bare base32 seed. Omitted on a
// change, the stored kind is kept.
Kind string `json:"kind,omitempty" enums:"value,totp"`
Value *string `json:"value,omitempty"`
AllowConnections []string `json:"allow_connections"`
AllowPersonas []string `json:"allow_personas"`
}
SecretInput is a create or a change. Value is omitted on a change that keeps the stored value.
type SecretList ¶
type SecretList struct {
Secrets []secretstore.Secret `json:"secrets"`
}
SecretList is the list response.
type Store ¶
type Store interface {
List(ctx context.Context) ([]secretstore.Secret, error)
Get(ctx context.Context, name string) (secretstore.Secret, error)
Put(ctx context.Context, w secretstore.Write) (secretstore.Secret, bool, error)
Delete(ctx context.Context, name string) error
Code(ctx context.Context, name string) (secretstore.CurrentCode, error)
}
Store is what the routes act through. *secretstore.Store satisfies it.
Click to show internal directories.
Click to hide internal directories.