Files
ResolveSpec/pkg/security/types.go
T
Hein c9fa8c60f2 refactor(security): move all database access into pkg/security/lookup
pkg/security no longer contains SQL. Every provider calls a store interface
from lookup, implemented by a procedure backend (Postgres stored procedures,
the default there) and a direct backend (dialect-driven SQL for postgres,
sqlite, mysql and mssql with configurable table and column names).

- add sectypes, lookup, lookup/{dialect,procedure,direct,backends,ddl,conformance}
- split totp and providers sub packages out of the core package
- replace SQLNames/TableNames/QueryMode with lookup.Config (see breaking_changes.md)
- direct backend now covers column/row security and API-key login
- move txsettings SQL to lookup.ApplyTxSettings; remove password.go
- move schema scripts under lookup/, add reference DDL per dialect
- add a shared conformance suite; run it on sqlite, and on Postgres in a
  podman/docker container (RESOLVESPEC_TEST_CONTAINERS=1)
- fix procedure schema bugs found on real Postgres: duplicate p_data
  parameter, JSON null arrays, expires_at timezone casts, passkey list
  GROUP BY, missing resolvespec_passkey_login; accept zone-less timestamps
2026-10-01 13:19:44 +02:00

55 lines
2.8 KiB
Go

package security
import (
"github.com/bitechdev/ResolveSpec/pkg/security/lookup"
"github.com/bitechdev/ResolveSpec/pkg/security/sectypes"
)
// Shared data types live in sectypes so that lookup and the sub packages can use
// them without importing this package. They are aliased here permanently, so
// security.X and sectypes.X are identical types.
type (
UserContext = sectypes.UserContext
LoginRequest = sectypes.LoginRequest
RegisterRequest = sectypes.RegisterRequest
LoginResponse = sectypes.LoginResponse
LogoutRequest = sectypes.LogoutRequest
PasswordResetRequest = sectypes.PasswordResetRequest
PasswordResetResponse = sectypes.PasswordResetResponse
PasswordResetCompleteRequest = sectypes.PasswordResetCompleteRequest
KeyType = sectypes.KeyType
UserKey = sectypes.UserKey
CreateKeyRequest = sectypes.CreateKeyRequest
CreateKeyResponse = sectypes.CreateKeyResponse
OAuthServerClient = sectypes.OAuthServerClient
OAuthCode = sectypes.OAuthCode
OAuthTokenInfo = sectypes.OAuthTokenInfo
PasskeyCredential = sectypes.PasskeyCredential
PasskeyRegistrationOptions = sectypes.PasskeyRegistrationOptions
PasskeyAuthenticationOptions = sectypes.PasskeyAuthenticationOptions
PasskeyRelyingParty = sectypes.PasskeyRelyingParty
PasskeyUser = sectypes.PasskeyUser
PasskeyCredentialParam = sectypes.PasskeyCredentialParam
PasskeyCredentialDescriptor = sectypes.PasskeyCredentialDescriptor
PasskeyAuthenticatorSelection = sectypes.PasskeyAuthenticatorSelection
PasskeyRegistrationResponse = sectypes.PasskeyRegistrationResponse
PasskeyAuthenticatorAttestationResponse = sectypes.PasskeyAuthenticatorAttestationResponse
PasskeyAuthenticationResponse = sectypes.PasskeyAuthenticationResponse
PasskeyAuthenticatorAssertionResponse = sectypes.PasskeyAuthenticatorAssertionResponse
TwoFactorSecret = sectypes.TwoFactorSecret
ColumnSecurity = sectypes.ColumnSecurity
RowSecurity = sectypes.RowSecurity
)
const (
KeyTypeJWTSecret = sectypes.KeyTypeJWTSecret
KeyTypeHeaderAPI = sectypes.KeyTypeHeaderAPI
KeyTypeOAuth2 = sectypes.KeyTypeOAuth2
KeyTypeGenericAPI = sectypes.KeyTypeGenericAPI
)
// errInvalidAPIKey is the single error API-key login returns for unknown, expired, inactive
// and wrong-type keys.
var errInvalidAPIKey = lookup.ErrInvalidAPIKey