config

package
v2.11.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 4, 2026 License: AGPL-3.0 Imports: 16 Imported by: 0

Documentation

Overview

Package config holds the deployment-time configuration for the authentication service. It defines the typed shape of the application config (REST server, Postgres, SMTP, role/permission map, short-code lifetimes, language settings, observability) and the defaults applied when an environment variable is unset.

The env subpackage parses the process environment into the App struct; configtest exposes shared fixtures for tests. Runtime code should depend on the typed structs declared here rather than reading os.Getenv directly.

Index

Constants

View Source
const (
	// LangFR is the French language code.
	LangFR = auth.LangFR
	// LangEN is the English language code.
	LangEN = auth.LangEN
)
View Source
const (
	// RoleAnon is the unauthenticated caller.
	RoleAnon = auth.RoleAnon
	// RoleUser is an authenticated standard user.
	RoleUser = auth.RoleUser
	// RoleAdmin is an operator with elevated access.
	RoleAdmin = auth.RoleAdmin
	// RoleSuperAdmin holds the highest level of access.
	RoleSuperAdmin = auth.RoleSuperAdmin
)
View Source
const (
	// OtelFlushTimeout bounds how long the process waits to flush buffered telemetry on shutdown.
	OtelFlushTimeout = 2 * time.Second
)

Variables

View Source
var AppPresetDefault = App{
	App: Main{
		Name: env.AppName,
	},
	Rest: Rest{
		Port:           env.RestPort,
		MaxRequestSize: env.RestMaxRequestSize,
		Timeouts: RestTimeouts{
			Read:       env.RestTimeoutRead,
			ReadHeader: env.RestTimeoutReadHeader,
			Write:      env.RestTimeoutWrite,
			Idle:       env.RestTimeoutIdle,
			Request:    env.RestTimeoutRequest,
			Shutdown:   env.RestTimeoutShutdown,
		},
		Cors: Cors{
			AllowedOrigins:   env.CorsAllowedOrigins,
			AllowedHeaders:   env.CorsAllowedHeaders,
			AllowCredentials: env.CorsAllowCredentials,
			MaxAge:           env.CorsMaxAge,
		},
	},

	DependenciesConfig: Dependencies{
		ServiceJsonKeysPort: env.ServiceJsonKeysPort,
		ServiceJsonKeysHost: env.ServiceJsonKeysHost,
		ServiceJsonKeysCredentials: lo.Ternary[grpcf.CredentialsProvider](
			env.GcloudProjectId == "",
			&grpcf.LocalCredentialsProvider{},
			&grpcf.GcloudCredentialsProvider{
				Host: env.ServiceJsonKeysHost,
			},
		),
	},
	Permissions:      PermissionsConfigDefault,
	Waitlist:         authconfig.Waitlist{URL: env.WaitlistURL, Secret: env.WaitlistSecret, Timeout: env.WaitlistTimeout},
	ShortCodesConfig: ShortCodesPresetDefault,
	SmtpUrlsConfig: SmtpUrls{
		UpdateEmail:    env.PlatformAuthUpdateEmailUrl,
		UpdatePassword: env.PlatformAuthUpdatePasswordUrl,
		Register:       env.PlatformAuthRegisterUrl,
	},

	Smtp: lo.Ternary[smtp.Sender](env.SmtpAddr == "", smtp.NewDebugSender(nil), &smtp.ProdSender{
		Addr:                env.SmtpAddr,
		Name:                env.SmtpSenderName,
		Email:               env.SmtpSenderEmail,
		Username:            env.SmtpUsername,
		Password:            env.SmtpSenderPassword,
		Domain:              env.SmtpSenderDomain,
		ForceUnencryptedTls: env.SmtpForceUnencrypted,
		Timeout:             env.SmtpTimeout,
	}),
	Otel: lo.If[otel.Config](!env.Otel, &otelpresets.Disabled{}).
		ElseIf(env.GcloudProjectId == "", &otelpresets.Local{
			FlushTimeout: OtelFlushTimeout,
		}).
		Else(&otelpresets.Gcloud{
			ProjectID:    env.GcloudProjectId,
			FlushTimeout: OtelFlushTimeout,
		}),
	Logger: lo.Ternary[logging.Log](env.GcloudProjectId == "", LoggerDev, LoggerProd),
	HttpLogger: lo.Ternary[logging.HTTPConfig](
		env.GcloudProjectId == "",
		&loggingpresets.HTTPLocal{
			BaseLogger: LoggerDev,
		},
		&loggingpresets.HTTPGcloud{
			BaseLogger: LoggerProd,
		},
	),
	Postgres: PostgresPresetDefault,
}

AppPresetDefault is the application configuration read from the environment, with each field falling back to its documented default when the variable is unset.

View Source
var ErrUnknownRole = auth.ErrUnknownRole

ErrUnknownRole reports a role absent from the permission configuration.

View Source
var KnownLangs = auth.KnownLangs

KnownLangs lists the language codes supported by the service.

View Source
var LoggerDev = &loggingpresets.LogLocal{
	Out: os.Stdout,
}

LoggerDev writes human-readable logs to stdout for local development.

View Source
var LoggerProd = &loggingpresets.LogGcloud{
	ProjectId: env.GcloudProjectId,
}

LoggerProd emits structured logs for the Google Cloud Logging backend.

View Source
var PermissionsConfigDefault = auth.PermissionsConfigDefault

PermissionsConfigDefault is the built-in role/permission map.

PostgresPresetDefault is the default PostgreSQL connection preset.

View Source
var ShortCodesPresetDefault = auth.ShortCodesPresetDefault

ShortCodesPresetDefault is the built-in short-code configuration.

Functions

func NewPostgresPreset added in v2.5.3

func NewPostgresPreset(
	connection PostgresConnection,
	maxOpenConns int,
	maxIdleConns int,
) *postgrespresets.Default

NewPostgresPreset returns a PostgreSQL preset whose pool is bounded before it opens.

Setting the limits on the handle afterwards stops working once anything has taken a connection, because the handle is cached; past that point they apply to nothing and report nothing.

Types

type App

type App struct {
	App  Main `json:"app"  yaml:"app"`
	Rest Rest `json:"rest" yaml:"rest"`

	DependenciesConfig Dependencies        `json:"dependencies" yaml:"dependencies"`
	Permissions        Permissions         `json:"permissions"  yaml:"permissions"`
	ShortCodesConfig   ShortCodes          `json:"shortCodes"   yaml:"shortCodes"`
	SmtpUrlsConfig     SmtpUrls            `json:"smtpUrls"     yaml:"smtpUrls"`
	Waitlist           authconfig.Waitlist `json:"waitlist"     yaml:"waitlist"`

	Smtp       smtp.Sender        `json:"smtp"       yaml:"smtp"`
	Otel       otel.Config        `json:"otel"       yaml:"otel"`
	Logger     logging.Log        `json:"logger"     yaml:"logger"`
	HttpLogger logging.HTTPConfig `json:"httplogger" yaml:"httplogger"`
	Postgres   postgres.Config    `json:"postgres"   yaml:"postgres"`
}

App is the fully resolved configuration for the service, assembled at startup from the environment.

type Cors

type Cors struct {
	AllowedOrigins   []string `json:"allowedOrigins"   yaml:"allowedOrigins"`
	AllowedHeaders   []string `json:"allowedHeaders"   yaml:"allowedHeaders"`
	AllowCredentials bool     `json:"allowCredentials" yaml:"allowCredentials"`
	MaxAge           int      `json:"maxAge"           yaml:"maxAge"`
}

Cors configures the cross-origin resource sharing policy of the REST server.

type Dependencies

type Dependencies struct {
	ServiceJsonKeysHost        string                    `json:"jsonKeysServiceHost" yaml:"jsonKeysServiceHost"`
	ServiceJsonKeysPort        int                       `json:"jsonKeysServicePort" yaml:"jsonKeysServicePort"`
	ServiceJsonKeysCredentials grpcf.CredentialsProvider `json:"-"                   yaml:"-"`
}

Dependencies configures how the service reaches the backing services it calls.

type Main

type Main struct {
	Name string `json:"name" yaml:"name"`
}

Main holds the core identity of the service, used to tag its logs and traces.

type Permissions

type Permissions = auth.Permissions

Permissions maps role identifiers to their permission definitions.

type PostgresConnection added in v2.5.3

type PostgresConnection struct {
	DSN        string
	Host       string
	Port       int
	User       string
	Password   string
	Database   string
	TLSEnabled bool
}

PostgresConnection describes how to reach PostgreSQL. Host selects the discrete fields; an empty Host selects the legacy DSN fallback.

type Rest added in v2.4.0

type Rest struct {
	Port           int          `json:"port"           yaml:"port"`
	Timeouts       RestTimeouts `json:"timeouts"       yaml:"timeouts"`
	MaxRequestSize int64        `json:"maxRequestSize" yaml:"maxRequestSize"`
	Cors           Cors         `json:"cors"           yaml:"cors"`
}

Rest configures the public REST HTTP server.

type RestTimeouts added in v2.4.0

type RestTimeouts struct {
	Read       time.Duration `json:"read"       yaml:"read"`
	ReadHeader time.Duration `json:"readHeader" yaml:"readHeader"`
	Write      time.Duration `json:"write"      yaml:"write"`
	Idle       time.Duration `json:"idle"       yaml:"idle"`
	Request    time.Duration `json:"request"    yaml:"request"`
	// Shutdown bounds the whole stop: the HTTP server's drain and the wait on detached work share it.
	Shutdown time.Duration `json:"shutdown" yaml:"shutdown"`
}

RestTimeouts bounds the phases of the REST server's request lifecycle.

type Role

type Role = auth.Role

Role bundles permissions and inheritance for a named role.

type ShortCodeUsage

type ShortCodeUsage = auth.ShortCodeUsage

ShortCodeUsage holds the settings for a single short-code usage.

type ShortCodes

type ShortCodes = auth.ShortCodes

ShortCodes configures the one-time codes that authorize account changes.

type SmtpUrls

type SmtpUrls = auth.SmtpUrls

SmtpUrls configures the web-client links embedded in outgoing emails.

Directories

Path Synopsis
Package auth defines the static authentication settings shared by core logic and clients.
Package auth defines the static authentication settings shared by core logic and clients.
Package configtest holds shared test fixtures for the config package.
Package configtest holds shared test fixtures for the config package.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL