mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-02 11:31:57 +00:00
pkg/security no longer contains SQL. Every provider calls a store interface
from lookup, implemented by a procedure backend (Postgres stored procedures,
the default there) and a direct backend (dialect-driven SQL for postgres,
sqlite, mysql and mssql with configurable table and column names).
- add sectypes, lookup, lookup/{dialect,procedure,direct,backends,ddl,conformance}
- split totp and providers sub packages out of the core package
- replace SQLNames/TableNames/QueryMode with lookup.Config (see breaking_changes.md)
- direct backend now covers column/row security and API-key login
- move txsettings SQL to lookup.ApplyTxSettings; remove password.go
- move schema scripts under lookup/, add reference DDL per dialect
- add a shared conformance suite; run it on sqlite, and on Postgres in a
podman/docker container (RESOLVESPEC_TEST_CONTAINERS=1)
- fix procedure schema bugs found on real Postgres: duplicate p_data
parameter, JSON null arrays, expires_at timezone casts, passkey list
GROUP BY, missing resolvespec_passkey_login; accept zone-less timestamps
55 lines
2.8 KiB
Go
55 lines
2.8 KiB
Go
package security
|
|
|
|
import (
|
|
"github.com/bitechdev/ResolveSpec/pkg/security/lookup"
|
|
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
|
|
)
|
|
|
|
// Shared data types live in sectypes so that lookup and the sub packages can use
|
|
// them without importing this package. They are aliased here permanently, so
|
|
// security.X and sectypes.X are identical types.
|
|
|
|
type (
|
|
UserContext = sectypes.UserContext
|
|
LoginRequest = sectypes.LoginRequest
|
|
RegisterRequest = sectypes.RegisterRequest
|
|
LoginResponse = sectypes.LoginResponse
|
|
LogoutRequest = sectypes.LogoutRequest
|
|
PasswordResetRequest = sectypes.PasswordResetRequest
|
|
PasswordResetResponse = sectypes.PasswordResetResponse
|
|
PasswordResetCompleteRequest = sectypes.PasswordResetCompleteRequest
|
|
KeyType = sectypes.KeyType
|
|
UserKey = sectypes.UserKey
|
|
CreateKeyRequest = sectypes.CreateKeyRequest
|
|
CreateKeyResponse = sectypes.CreateKeyResponse
|
|
OAuthServerClient = sectypes.OAuthServerClient
|
|
OAuthCode = sectypes.OAuthCode
|
|
OAuthTokenInfo = sectypes.OAuthTokenInfo
|
|
PasskeyCredential = sectypes.PasskeyCredential
|
|
PasskeyRegistrationOptions = sectypes.PasskeyRegistrationOptions
|
|
PasskeyAuthenticationOptions = sectypes.PasskeyAuthenticationOptions
|
|
PasskeyRelyingParty = sectypes.PasskeyRelyingParty
|
|
PasskeyUser = sectypes.PasskeyUser
|
|
PasskeyCredentialParam = sectypes.PasskeyCredentialParam
|
|
PasskeyCredentialDescriptor = sectypes.PasskeyCredentialDescriptor
|
|
PasskeyAuthenticatorSelection = sectypes.PasskeyAuthenticatorSelection
|
|
PasskeyRegistrationResponse = sectypes.PasskeyRegistrationResponse
|
|
PasskeyAuthenticatorAttestationResponse = sectypes.PasskeyAuthenticatorAttestationResponse
|
|
PasskeyAuthenticationResponse = sectypes.PasskeyAuthenticationResponse
|
|
PasskeyAuthenticatorAssertionResponse = sectypes.PasskeyAuthenticatorAssertionResponse
|
|
TwoFactorSecret = sectypes.TwoFactorSecret
|
|
ColumnSecurity = sectypes.ColumnSecurity
|
|
RowSecurity = sectypes.RowSecurity
|
|
)
|
|
|
|
const (
|
|
KeyTypeJWTSecret = sectypes.KeyTypeJWTSecret
|
|
KeyTypeHeaderAPI = sectypes.KeyTypeHeaderAPI
|
|
KeyTypeOAuth2 = sectypes.KeyTypeOAuth2
|
|
KeyTypeGenericAPI = sectypes.KeyTypeGenericAPI
|
|
)
|
|
|
|
// errInvalidAPIKey is the single error API-key login returns for unknown, expired, inactive
|
|
// and wrong-type keys.
|
|
var errInvalidAPIKey = lookup.ErrInvalidAPIKey
|