mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-02 11:31:57 +00:00
pkg/security no longer contains SQL. Every provider calls a store interface
from lookup, implemented by a procedure backend (Postgres stored procedures,
the default there) and a direct backend (dialect-driven SQL for postgres,
sqlite, mysql and mssql with configurable table and column names).
- add sectypes, lookup, lookup/{dialect,procedure,direct,backends,ddl,conformance}
- split totp and providers sub packages out of the core package
- replace SQLNames/TableNames/QueryMode with lookup.Config (see breaking_changes.md)
- direct backend now covers column/row security and API-key login
- move txsettings SQL to lookup.ApplyTxSettings; remove password.go
- move schema scripts under lookup/, add reference DDL per dialect
- add a shared conformance suite; run it on sqlite, and on Postgres in a
podman/docker container (RESOLVESPEC_TEST_CONTAINERS=1)
- fix procedure schema bugs found on real Postgres: duplicate p_data
parameter, JSON null arrays, expires_at timezone casts, passkey list
GROUP BY, missing resolvespec_passkey_login; accept zone-less timestamps
29 lines
1.2 KiB
Go
29 lines
1.2 KiB
Go
package security
|
|
|
|
import (
|
|
"context"
|
|
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
|
)
|
|
|
|
// hashSHA256Hex is kept as a short alias for sectypes.HashKey inside this package.
|
|
func hashSHA256Hex(raw string) string { return sectypes.HashKey(raw) }
|
|
|
|
// KeyStore manages per-user auth keys with pluggable storage backends.
|
|
// Implementations: ConfigKeyStore (static list) and DatabaseKeyStore (stored procedures).
|
|
type KeyStore interface {
|
|
// CreateKey generates a new key, stores its hash, and returns the raw key once.
|
|
CreateKey(ctx context.Context, req CreateKeyRequest) (*CreateKeyResponse, error)
|
|
|
|
// GetUserKeys returns all active, non-expired keys for a user.
|
|
// Pass an empty KeyType to return all types.
|
|
GetUserKeys(ctx context.Context, userID int, keyType KeyType) ([]UserKey, error)
|
|
|
|
// DeleteKey soft-deletes a key by ID after verifying ownership.
|
|
DeleteKey(ctx context.Context, userID int, keyID int64) error
|
|
|
|
// ValidateKey checks a raw key, returns the matching UserKey on success.
|
|
// The implementation hashes the raw key before any lookup.
|
|
// Pass an empty KeyType to accept any type.
|
|
ValidateKey(ctx context.Context, rawKey string, keyType KeyType) (*UserKey, error)
|
|
}
|