mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-03 03:51:59 +00:00
refactor(security): move all database access into pkg/security/lookup
pkg/security no longer contains SQL. Every provider calls a store interface
from lookup, implemented by a procedure backend (Postgres stored procedures,
the default there) and a direct backend (dialect-driven SQL for postgres,
sqlite, mysql and mssql with configurable table and column names).
- add sectypes, lookup, lookup/{dialect,procedure,direct,backends,ddl,conformance}
- split totp and providers sub packages out of the core package
- replace SQLNames/TableNames/QueryMode with lookup.Config (see breaking_changes.md)
- direct backend now covers column/row security and API-key login
- move txsettings SQL to lookup.ApplyTxSettings; remove password.go
- move schema scripts under lookup/, add reference DDL per dialect
- add a shared conformance suite; run it on sqlite, and on Postgres in a
podman/docker container (RESOLVESPEC_TEST_CONTAINERS=1)
- fix procedure schema bugs found on real Postgres: duplicate p_data
parameter, JSON null arrays, expires_at timezone casts, passkey list
GROUP BY, missing resolvespec_passkey_login; accept zone-less timestamps
This commit is contained in:
@@ -0,0 +1,54 @@
|
||||
package security
|
||||
|
||||
import (
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/lookup"
|
||||
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
||||
)
|
||||
|
||||
// Shared data types live in sectypes so that lookup and the sub packages can use
|
||||
// them without importing this package. They are aliased here permanently, so
|
||||
// security.X and sectypes.X are identical types.
|
||||
|
||||
type (
|
||||
UserContext = sectypes.UserContext
|
||||
LoginRequest = sectypes.LoginRequest
|
||||
RegisterRequest = sectypes.RegisterRequest
|
||||
LoginResponse = sectypes.LoginResponse
|
||||
LogoutRequest = sectypes.LogoutRequest
|
||||
PasswordResetRequest = sectypes.PasswordResetRequest
|
||||
PasswordResetResponse = sectypes.PasswordResetResponse
|
||||
PasswordResetCompleteRequest = sectypes.PasswordResetCompleteRequest
|
||||
KeyType = sectypes.KeyType
|
||||
UserKey = sectypes.UserKey
|
||||
CreateKeyRequest = sectypes.CreateKeyRequest
|
||||
CreateKeyResponse = sectypes.CreateKeyResponse
|
||||
OAuthServerClient = sectypes.OAuthServerClient
|
||||
OAuthCode = sectypes.OAuthCode
|
||||
OAuthTokenInfo = sectypes.OAuthTokenInfo
|
||||
PasskeyCredential = sectypes.PasskeyCredential
|
||||
PasskeyRegistrationOptions = sectypes.PasskeyRegistrationOptions
|
||||
PasskeyAuthenticationOptions = sectypes.PasskeyAuthenticationOptions
|
||||
PasskeyRelyingParty = sectypes.PasskeyRelyingParty
|
||||
PasskeyUser = sectypes.PasskeyUser
|
||||
PasskeyCredentialParam = sectypes.PasskeyCredentialParam
|
||||
PasskeyCredentialDescriptor = sectypes.PasskeyCredentialDescriptor
|
||||
PasskeyAuthenticatorSelection = sectypes.PasskeyAuthenticatorSelection
|
||||
PasskeyRegistrationResponse = sectypes.PasskeyRegistrationResponse
|
||||
PasskeyAuthenticatorAttestationResponse = sectypes.PasskeyAuthenticatorAttestationResponse
|
||||
PasskeyAuthenticationResponse = sectypes.PasskeyAuthenticationResponse
|
||||
PasskeyAuthenticatorAssertionResponse = sectypes.PasskeyAuthenticatorAssertionResponse
|
||||
TwoFactorSecret = sectypes.TwoFactorSecret
|
||||
ColumnSecurity = sectypes.ColumnSecurity
|
||||
RowSecurity = sectypes.RowSecurity
|
||||
)
|
||||
|
||||
const (
|
||||
KeyTypeJWTSecret = sectypes.KeyTypeJWTSecret
|
||||
KeyTypeHeaderAPI = sectypes.KeyTypeHeaderAPI
|
||||
KeyTypeOAuth2 = sectypes.KeyTypeOAuth2
|
||||
KeyTypeGenericAPI = sectypes.KeyTypeGenericAPI
|
||||
)
|
||||
|
||||
// errInvalidAPIKey is the single error API-key login returns for unknown, expired, inactive
|
||||
// and wrong-type keys.
|
||||
var errInvalidAPIKey = lookup.ErrInvalidAPIKey
|
||||
Reference in New Issue
Block a user