secretapi

package
v1.142.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: Apache-2.0 Imports: 7 Imported by: 0

Documentation

Overview

Package secretapi is the admin REST surface for stored secrets (#2051): list, read, create or change, and delete, and an authenticator seed's current code (#2065). The value is write-only: a PUT carries it, and no response ever does.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func Register

func Register(mux *http.ServeMux, wrap func(http.Handler) http.Handler, cfg Config)

Register mounts the secret routes, each behind wrap, the admin API's authentication.

Types

type Config

type Config struct {
	// Store holds the secrets. nil mounts nothing.
	Store Store
	// Author resolves the acting admin.
	Author func(*http.Request) string
}

Config carries the store and the parent-owned helpers.

type SecretInput

type SecretInput struct {
	Description string `json:"description"`
	// Kind is "value" (the default on a create) or "totp", an authenticator
	// seed given as its otpauth://totp URI or bare base32 seed. Omitted on a
	// change, the stored kind is kept.
	Kind             string   `json:"kind,omitempty" enums:"value,totp"`
	Value            *string  `json:"value,omitempty"`
	AllowConnections []string `json:"allow_connections"`
	AllowPersonas    []string `json:"allow_personas"`
}

SecretInput is a create or a change. Value is omitted on a change that keeps the stored value.

type SecretList

type SecretList struct {
	Secrets []secretstore.Secret `json:"secrets"`
}

SecretList is the list response.

type Store

type Store interface {
	List(ctx context.Context) ([]secretstore.Secret, error)
	Get(ctx context.Context, name string) (secretstore.Secret, error)
	Put(ctx context.Context, w secretstore.Write) (secretstore.Secret, bool, error)
	Delete(ctx context.Context, name string) error
	Code(ctx context.Context, name string) (secretstore.CurrentCode, error)
}

Store is what the routes act through. *secretstore.Store satisfies it.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL