Documentation
¶
There is no documentation for this package.
Directories
¶
| Path | Synopsis |
|---|---|
|
cmd/gen_error_schemas
command
gen_error_schemas generates individual OpenAPI error schema files.
|
gen_error_schemas generates individual OpenAPI error schema files. |
|
cmd/gen_event_schemas
command
gen_event_schemas generates per-event-type OpenAPI schemas and the Event oneOf union with discriminator mapping from domain.EventType constants.
|
gen_event_schemas generates per-event-type OpenAPI schemas and the Event oneOf union with discriminator mapping from domain.EventType constants. |
|
cmd/gen_openapi_errors
command
gen_openapi_errors generates OpenAPI default responses for each operation.
|
gen_openapi_errors generates OpenAPI default responses for each operation. |
|
generated
Code generated by ogen, DO NOT EDIT.
|
Code generated by ogen, DO NOT EDIT. |
|
internal/erroranalysis
Package erroranalysis infers, from the Go source itself, which domain error constructors a service interface method can return.
|
Package erroranalysis infers, from the Go source itself, which domain error constructors a service interface method can return. |
|
openapi/endpoints/flow_definitions
Package flow_definitions embeds the default flow definitions for use by the internal package
|
Package flow_definitions embeds the default flow definitions for use by the internal package |
|
openapi/endpoints/schemas
Package schemas embeds the OpenAPI JSON meta-schema files for use by internal packages during schema validation.
|
Package schemas embeds the OpenAPI JSON meta-schema files for use by internal packages during schema validation. |
|
cmd
|
|
|
internal
|
|
|
authz
Package authz holds the shared intermediate representation for permission catalogs.
|
Package authz holds the shared intermediate representation for permission catalogs. |
|
authz/authztest
Package authztest holds shared helpers for authz property and integration tests.
|
Package authztest holds shared helpers for authz property and integration tests. |
|
authz/compiler
Package compiler turns a profile-valid authz model into storage-neutral catalog mutations and query-plan metadata.
|
Package compiler turns a profile-valid authz model into storage-neutral catalog mutations and query-plan metadata. |
|
authz/openfga
Package openfga adapts the upstream OpenFGA language package into Zitadel's authz IR.
|
Package openfga adapts the upstream OpenFGA language package into Zitadel's authz IR. |
|
authz/profile
Package profile enforces the bounded subset of OpenFGA that Zitadel can compile into portable relational query plans (ADR 032 §2).
|
Package profile enforces the bounded subset of OpenFGA that Zitadel can compile into portable relational query plans (ADR 032 §2). |
|
authz/resolver
Package resolver evaluates single-resource permission checks and list authorization against relational authz storage (ADR 032–033 / issue #423).
|
Package resolver evaluates single-resource permission checks and list authorization against relational authz storage (ADR 032–033 / issue #423). |
|
bootstrap/platform
Package platform bootstraps deployment-level platform resources at server startup.
|
Package platform bootstraps deployment-level platform resources at server startup. |
|
crypto/mock
Package cryptomock is a generated GoMock package.
|
Package cryptomock is a generated GoMock package. |
|
domain/mock
Package domainmock is a generated GoMock package.
|
Package domainmock is a generated GoMock package. |
|
errreport
Package errreport centralizes error location and stack capture for structured logging and GCP Error Reporting (ADR 030).
|
Package errreport centralizes error location and stack capture for structured logging and GCP Error Reporting (ADR 030). |
|
httputil
Package httputil provides the hardened egress HTTP client for every fetch of a URL a platform user can inject (schema ingestion today; social login and tenant webhooks later).
|
Package httputil provides the hardened egress HTTP client for every fetch of a URL a platform user can inject (schema ingestion today; social login and tenant webhooks later). |
|
idp
Package idp is the identity-provider engine: it turns a pinned connection revision into a relying-party client and drives the sign-in ceremony with it.
|
Package idp is the identity-provider engine: it turns a pinned connection revision into a relying-party client and drives the sign-in ceremony with it. |
|
instrumentation/metrics
Package metrics holds the instrument sets the server reports through, one per kind of thing worth measuring, so a component becomes observable by passing an option to its constructor rather than by declaring instruments of its own.
|
Package metrics holds the instrument sets the server reports through, one per kind of thing worth measuring, so a component becomes observable by passing an option to its constructor rather than by declaring instruments of its own. |
|
service/mocks
Package mocks is a generated GoMock package.
|
Package mocks is a generated GoMock package. |
|
staticui
Package staticui serves an embedded SPA under a URL prefix with trailing-slash redirect and index.html fallback for client-side routes.
|
Package staticui serves an embedded SPA under a URL prefix with trailing-slash redirect and index.html fallback for client-side routes. |
|
storage/branding
Package branding holds shared encoding helpers for the branding definition JSON column used by v2 dialect statements.
|
Package branding holds shared encoding helpers for the branding definition JSON column used by v2 dialect statements. |
|
storage/dbtest
Package dbtest provides shared bring-up of databases for v2 storage integration test suites.
|
Package dbtest provides shared bring-up of databases for v2 storage integration test suites. |
|
storage/deployment
Package deployment holds shared helpers for the deployments table used by v2 dialect statements: list options, the create-time guard, and the encoding of the metadata JSON column.
|
Package deployment holds shared helpers for the deployments table used by v2 dialect statements: list options, the create-time guard, and the encoding of the metadata JSON column. |
|
storage/dialect/authattempt
Package authattempt holds shared helpers for auth-attempt statement dialects.
|
Package authattempt holds shared helpers for auth-attempt statement dialects. |
|
storage/dialect/authz
Package authz holds dialect-independent Wave 1 authz persistence helpers: lifecycle projection (multi-write), membership-edge Filter schema, and catalog row mapping from compiler mutations.
|
Package authz holds dialect-independent Wave 1 authz persistence helpers: lifecycle projection (multi-write), membership-edge Filter schema, and catalog row mapping from compiler mutations. |
|
storage/dialect/compare
Package compare provides shared SQL fragments for dialect statement compilers.
|
Package compare provides shared SQL fragments for dialect statement compilers. |
|
storage/dialect/idgen
Package idgen provides managed resource ID generation for v2 dialects.
|
Package idgen provides managed resource ID generation for v2 dialects. |
|
storage/dialect/idgen/idgenmock
Package idgenmock is a generated GoMock package.
|
Package idgenmock is a generated GoMock package. |
|
storage/dialect/schematest
Package schematest asserts the nullable-binding contract shared by every dialect schema: the Nullable flag is set, the absent state binds untyped nil, and the present state binds the dereferenced value.
|
Package schematest asserts the nullable-binding contract shared by every dialect schema: the Nullable flag is set, the absent state binds untyped nil, and the present state binds the dereferenced value. |
|
storage/dialect/sqlite/migration
Package migration applies SQLite schema migrations using goose.
|
Package migration applies SQLite schema migrations using goose. |
|
storage/flowdefinition
Package flowdefinition holds shared encoding helpers for the flow_definitions definition JSON column used by v2 dialect statements.
|
Package flowdefinition holds shared encoding helpers for the flow_definitions definition JSON column used by v2 dialect statements. |
|
storage/idpconnection
Package idpconnection holds the read plumbing every dialect shares for identity provider connections joined to their revisions.
|
Package idpconnection holds the read plumbing every dialect shares for identity provider connections joined to their revisions. |
|
storage/idpidentitylink
Package idpidentitylink holds the read plumbing every dialect shares for identity links.
|
Package idpidentitylink holds the read plumbing every dialect shares for identity links. |
|
storage/project
Package project holds the shared encoding for the projects table's one JSON column -- the password hashing policy -- used by every dialect's statements.
|
Package project holds the shared encoding for the projects table's one JSON column -- the password hashing policy -- used by every dialect's statements. |
|
storage/release
Package release holds shared encoding helpers for the two JSON columns of the releases table — the pinned pointer set and the metadata — used by v2 dialect statements.
|
Package release holds shared encoding helpers for the two JSON columns of the releases table — the pinned pointer set and the metadata — used by v2 dialect statements. |
|
storage/stmttest
Package stmttest holds shared behavioral integration tests for v2 statement implementations.
|
Package stmttest holds shared behavioral integration tests for v2 statement implementations. |
|
storage/userteam
Package userteam binds the user roster read: team memberships joined to the teams they point at.
|
Package userteam binds the user roster read: team memberships joined to the teams they point at. |
|
storage/variable
Package variable holds the dialect-independent row shape, query options and domain mapping for the variables table.
|
Package variable holds the dialect-independent row shape, query options and domain mapping for the variables table. |
|
packages
|
|
|
config/defaults
Package defaults embeds the versioned Zitadel config defaults shared by the CLI and server fallback path.
|
Package defaults embeds the versioned Zitadel config defaults shared by the CLI and server fallback path. |
|
tools
|
|
|
analyzers/cmd/analyzers
command
Command analyzers bundles this repository's custom go/analysis analyzers into one binary.
|
Command analyzers bundles this repository's custom go/analysis analyzers into one binary. |
|
analyzers/egresslint
Package egresslint is a go/analysis analyzer that enforces the single egress-client invariant behind ADR 061: every outbound HTTP or TCP client in production code must come from internal/httputil, the hardened client that applies the SSRF deny list at dial time, caps redirects and body size, and refuses https-to-http downgrades.
|
Package egresslint is a go/analysis analyzer that enforces the single egress-client invariant behind ADR 061: every outbound HTTP or TCP client in production code must come from internal/httputil, the hardened client that applies the SSRF deny list at dial time, caps redirects and body size, and refuses https-to-http downgrades. |
Click to show internal directories.
Click to hide internal directories.