Documentation
¶
Index ¶
- Constants
- Variables
- func GetUserFromRequest(r *http.Request, signingKey string, store Store) (*models.User, error)
- func ValidatePasswords(password, passwordConf string) (bool, error)
- type RedisStore
- func (rs *RedisStore) Delete(sid SessionID) error
- func (rs *RedisStore) Get(sid SessionID, sessionState interface{}) error
- func (rs *RedisStore) NewPasswordResetToken(email string) (string, error)
- func (rs *RedisStore) Save(sid SessionID, sessionState interface{}) error
- func (rs *RedisStore) ValidatePasswordResetToken(email, token string) (bool, error)
- type SessionID
- func BeginSession(signingKey string, store Store, sessionState interface{}, ...) (SessionID, error)
- func EndSession(r *http.Request, signingKey string, store Store) (SessionID, error)
- func GetSessionID(r *http.Request, signingKey string) (SessionID, error)
- func GetState(r *http.Request, signingKey string, store Store, sessionState interface{}) (SessionID, error)
- func NewSessionID(signingKey string) (SessionID, error)
- func ValidateID(id string, signingKey string) (SessionID, error)
- type SessionState
- type Store
Constants ¶
const DefaultSessionDuration = time.Hour
DefaultSessionDuration is the default length of the redis client's expiry time that will be used if a valid sessionDuration is not given
Variables ¶
var ErrInvalidID = errors.New("Invalid Session ID")
ErrInvalidID is returned when an invalid session id is passed to ValidateID()
var ErrInvalidScheme = errors.New("authorization scheme not supported")
ErrInvalidScheme is used when the authorization scheme is not supported
var ErrNoSessionID = errors.New("no session ID found in " + headerAuthorization + " header")
ErrNoSessionID is used when no session ID was found in the Authorization header
var ErrStateNotFound = errors.New("no session state was found in the session store")
ErrStateNotFound is returned from Store.Get() when the requested session id was not found in the store
Functions ¶
func GetUserFromRequest ¶
Gets the User from the given request. Returns an error if there was an error getting the user
func ValidatePasswords ¶
ValidatePasswords returns true if the password and passwordConf combination are valid, false and an error if otherwise.
Types ¶
type RedisStore ¶
type RedisStore struct {
//Redis client used to talk to redis server.
Client *redis.Client
//Used for key expiry time on redis.
SessionDuration time.Duration
}
RedisStore represents a session.Store backed by redis.
func NewRedisStore ¶
NewRedisStore constructs a new RedisStore
func (*RedisStore) Delete ¶
func (rs *RedisStore) Delete(sid SessionID) error
Delete deletes all state data associated with the SessionID from the store.
func (*RedisStore) Get ¶
func (rs *RedisStore) Get(sid SessionID, sessionState interface{}) error
Get populates `sessionState` with the data previously saved for the given SessionID
func (*RedisStore) NewPasswordResetToken ¶
func (rs *RedisStore) NewPasswordResetToken(email string) (string, error)
NewPasswordResetToken generates a new password reset token for the given email and saves it to this redis store for the time specified by PasswordResetValidityDuration
func (*RedisStore) Save ¶
func (rs *RedisStore) Save(sid SessionID, sessionState interface{}) error
Save saves the provided `sessionState` and associated SessionID to the store. The `sessionState` parameter is typically a pointer to a struct containing all the data you want to associated with the given SessionID.
func (*RedisStore) ValidatePasswordResetToken ¶
func (rs *RedisStore) ValidatePasswordResetToken(email, token string) (bool, error)
ValidatePasswordResetToken validates that the given token exists for the given email. Returns an error if no such token exists, or there was an error validating it.
type SessionID ¶
type SessionID string
const InvalidSessionID SessionID = ""
InvalidSessionID represents an empty, invalid session ID
func BeginSession ¶
func BeginSession(signingKey string, store Store, sessionState interface{}, w http.ResponseWriter) (SessionID, error)
BeginSession creates a new SessionID, saves the `sessionState` to the store, adds an Authorization header to the response with the SessionID, and returns the new SessionID
func EndSession ¶
EndSession extracts the SessionID from the request, and deletes the associated data in the provided store, returning the extracted SessionID.
func GetSessionID ¶
GetSessionID extracts and validates the SessionID from the request headers
func GetState ¶
func GetState(r *http.Request, signingKey string, store Store, sessionState interface{}) (SessionID, error)
GetState extracts the SessionID from the request, gets the associated state from the provided store into the `sessionState` parameter, and returns the SessionID
func NewSessionID ¶
NewSessionID creates and returns a new digitally-signed session ID, using `signingKey` as the HMAC signing key. An error is returned only if there was an error generating random bytes for the session ID
func ValidateID ¶
ValidateID validates the string in the `id` parameter using the `signingKey` as the HMAC signing key and returns an error if invalid, or a SessionID if valid
type SessionState ¶
SessionState is a struct representing an authenticated session
func NewSessionState ¶
func NewSessionState(user *models.User) *SessionState
NewSessionState creates a new SessionState with the given user
type Store ¶
type Store interface {
//Save saves the provided `sessionState` and associated SessionID to the store.
//The `sessionState` parameter is typically a pointer to a struct containing
//all the data you want to associated with the given SessionID.
Save(sid SessionID, sessionState interface{}) error
//Get populates `sessionState` with the data previously saved
//for the given SessionID
Get(sid SessionID, sessionState interface{}) error
//Delete deletes all state data associated with the SessionID from the store.
Delete(sid SessionID) error
// NewPasswordResetToken generates a new password reset token for the given email and
// saves it to this redis store for the time specified by PasswordResetValidityDuration
NewPasswordResetToken(email string) (string, error)
// ValidatePasswordResetToken validates that the given token exists for the given
// email. Returns an error if no such token exists, or there was an error validating it.
ValidatePasswordResetToken(email, token string) (bool, error)
}
Store represents a session data store. This is an abstract interface that can be implemented against several different types of data stores. For example, session data could be stored in memory in a concurrent map, or more typically in a shared key/value server store like redis.