mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-01 19:20:31 +00:00
pkg/security no longer contains SQL. Every provider calls a store interface
from lookup, implemented by a procedure backend (Postgres stored procedures,
the default there) and a direct backend (dialect-driven SQL for postgres,
sqlite, mysql and mssql with configurable table and column names).
- add sectypes, lookup, lookup/{dialect,procedure,direct,backends,ddl,conformance}
- split totp and providers sub packages out of the core package
- replace SQLNames/TableNames/QueryMode with lookup.Config (see breaking_changes.md)
- direct backend now covers column/row security and API-key login
- move txsettings SQL to lookup.ApplyTxSettings; remove password.go
- move schema scripts under lookup/, add reference DDL per dialect
- add a shared conformance suite; run it on sqlite, and on Postgres in a
podman/docker container (RESOLVESPEC_TEST_CONTAINERS=1)
- fix procedure schema bugs found on real Postgres: duplicate p_data
parameter, JSON null arrays, expires_at timezone casts, passkey list
GROUP BY, missing resolvespec_passkey_login; accept zone-less timestamps
76 lines
3.1 KiB
Go
76 lines
3.1 KiB
Go
package security
|
|
|
|
import (
|
|
"context"
|
|
"encoding/json"
|
|
)
|
|
|
|
// PasskeyProvider handles passkey registration and authentication
|
|
type PasskeyProvider interface {
|
|
// BeginRegistration creates registration options for a new passkey
|
|
BeginRegistration(ctx context.Context, userID int, username, displayName string) (*PasskeyRegistrationOptions, error)
|
|
|
|
// CompleteRegistration verifies and stores a new passkey credential
|
|
CompleteRegistration(ctx context.Context, userID int, response PasskeyRegistrationResponse, expectedChallenge []byte) (*PasskeyCredential, error)
|
|
|
|
// BeginAuthentication creates authentication options for passkey login
|
|
BeginAuthentication(ctx context.Context, username string) (*PasskeyAuthenticationOptions, error)
|
|
|
|
// CompleteAuthentication verifies a passkey assertion and returns the user
|
|
CompleteAuthentication(ctx context.Context, response PasskeyAuthenticationResponse, expectedChallenge []byte) (int, error)
|
|
|
|
// GetCredentials returns all passkey credentials for a user
|
|
GetCredentials(ctx context.Context, userID int) ([]PasskeyCredential, error)
|
|
|
|
// DeleteCredential removes a passkey credential
|
|
DeleteCredential(ctx context.Context, userID int, credentialID string) error
|
|
|
|
// UpdateCredentialName updates the friendly name of a credential
|
|
UpdateCredentialName(ctx context.Context, userID int, credentialID string, name string) error
|
|
}
|
|
|
|
// PasskeyLoginRequest contains passkey authentication data
|
|
type PasskeyLoginRequest struct {
|
|
Response PasskeyAuthenticationResponse `json:"response"`
|
|
ExpectedChallenge []byte `json:"expected_challenge"`
|
|
Claims map[string]any `json:"claims"` // Additional login data
|
|
}
|
|
|
|
// PasskeyRegisterRequest contains passkey registration data
|
|
type PasskeyRegisterRequest struct {
|
|
UserID int `json:"user_id"`
|
|
Response PasskeyRegistrationResponse `json:"response"`
|
|
ExpectedChallenge []byte `json:"expected_challenge"`
|
|
CredentialName string `json:"credential_name,omitempty"`
|
|
}
|
|
|
|
// PasskeyBeginRegistrationRequest contains options for starting passkey registration
|
|
type PasskeyBeginRegistrationRequest struct {
|
|
UserID int `json:"user_id"`
|
|
Username string `json:"username"`
|
|
DisplayName string `json:"display_name"`
|
|
}
|
|
|
|
// PasskeyBeginAuthenticationRequest contains options for starting passkey authentication
|
|
type PasskeyBeginAuthenticationRequest struct {
|
|
Username string `json:"username,omitempty"` // Optional for resident key flow
|
|
}
|
|
|
|
// ParsePasskeyRegistrationResponse parses a JSON passkey registration response
|
|
func ParsePasskeyRegistrationResponse(data []byte) (*PasskeyRegistrationResponse, error) {
|
|
var response PasskeyRegistrationResponse
|
|
if err := json.Unmarshal(data, &response); err != nil {
|
|
return nil, err
|
|
}
|
|
return &response, nil
|
|
}
|
|
|
|
// ParsePasskeyAuthenticationResponse parses a JSON passkey authentication response
|
|
func ParsePasskeyAuthenticationResponse(data []byte) (*PasskeyAuthenticationResponse, error) {
|
|
var response PasskeyAuthenticationResponse
|
|
if err := json.Unmarshal(data, &response); err != nil {
|
|
return nil, err
|
|
}
|
|
return &response, nil
|
|
}
|