luci: Index | Files | Directories

package server

import ""

Package server implements authentication for inbound HTTP requests on GAE. It provides adapters for GAE Users and OAuth2 APIs to make them usable by server/auth package.

It also provides GAE-specific implementation of some other interface used by server/auth package, such as SessionStore.

By defualt, gaeauth must have its handlers installed into the "default" AppEngine module, and must be running on an instance with read/write datastore access.


Package Files

cookies.go db.go default.go doc.go oauth.go service.go session.go settings.go


const EmailScope = ""

EmailScope is a scope used to identifies user's email. Present in most tokens by default. Can be used as a base scope for authentication.


var CookieAuth auth.Method

CookieAuth is default cookie-based auth method to use on GAE.

On dev server it is based on dev server cookies, in prod it is based on OpenID. Works only if appropriate handlers have been installed into the router. See InstallHandlers.

func GetAuthDB Uses

func GetAuthDB(c context.Context, prev authdb.DB) (authdb.DB, error)

GetAuthDB fetches AuthDB snapshot from the datastore and returns authdb.DB interface wrapping it.

It may reuse existing one (`prev`), if no changes were made. If `prev` is nil, always fetches a new copy from the datastore.

If auth_service URL is not configured, returns special kind of authdb.DB that implements some default authorization rules (allow everything on dev server, forbid everything and emit errors on real GAE).

func InstallHandlers Uses

func InstallHandlers(r *router.Router, base router.MiddlewareChain)

InstallHandlers installs HTTP handlers for various default routes related to authentication system.

Must be installed in server HTTP router for authentication to work.

type InboundAppIDAuthMethod Uses

type InboundAppIDAuthMethod struct{}

InboundAppIDAuthMethod implements auth.Method by checking special HTTP header (X-Appengine-Inbound-Appid), that is set iff one GAE app talks to another.

func (InboundAppIDAuthMethod) Authenticate Uses

func (m InboundAppIDAuthMethod) Authenticate(c context.Context, r *http.Request) (*auth.User, error)

Authenticate extracts peer's identity from the incoming request.

type OAuth2Method Uses

type OAuth2Method struct {
    // Scopes is a list of OAuth scopes to check when authenticating the token.
    Scopes []string

OAuth2Method implements auth.Method on top of GAE OAuth2 API. It doesn't implement auth.UsersAPI.

func (*OAuth2Method) Authenticate Uses

func (m *OAuth2Method) Authenticate(c context.Context, r *http.Request) (*auth.User, error)

Authenticate extracts peer's identity from the incoming request.

type SessionStore Uses

type SessionStore struct {
    Prefix string // used as prefix for datastore keys

SessionStore stores auth sessions in the datastore (always in the default namespace). It implements auth.SessionStore.

func (*SessionStore) CloseSession Uses

func (s *SessionStore) CloseSession(c context.Context, sessionID string) error

CloseSession closes a session given its ID. Does nothing if session is already closed or doesn't exist. Returns only transient errors.

func (*SessionStore) GetSession Uses

func (s *SessionStore) GetSession(c context.Context, sessionID string) (*auth.Session, error)

GetSession returns existing non-expired session given its ID. Returns nil if session doesn't exist, closed or expired. Returns only transient errors.

func (*SessionStore) OpenSession Uses

func (s *SessionStore) OpenSession(c context.Context, userID string, u *auth.User, exp time.Time) (string, error)

OpenSession create a new session for a user with given expiration time. It returns unique session ID.

type UsersAPIAuthMethod Uses

type UsersAPIAuthMethod struct{}

UsersAPIAuthMethod implements auth.Method and auth.UsersAPI interfaces on top of GAE Users API (that uses HTTP cookies internally to track user sessions).

func (UsersAPIAuthMethod) Authenticate Uses

func (m UsersAPIAuthMethod) Authenticate(c context.Context, r *http.Request) (*auth.User, error)

Authenticate extracts peer's identity from the incoming request.

func (UsersAPIAuthMethod) LoginURL Uses

func (m UsersAPIAuthMethod) LoginURL(c context.Context, dest string) (string, error)

LoginURL returns a URL that, when visited, prompts the user to sign in, then redirects the user to the URL specified by dest.

func (UsersAPIAuthMethod) LogoutURL Uses

func (m UsersAPIAuthMethod) LogoutURL(c context.Context, dest string) (string, error)

LogoutURL returns a URL that, when visited, signs the user out, then redirects the user to the URL specified by dest.


gaesignerPackage gaesigner implements signing.Signer interface using GAE App Identity API.
internal/authdbimplPackage authdbimpl implements datastore-based storage and update of AuthDB snapshots used for authorization decisions by server/auth/*.

Package server imports 27 packages (graph) and is imported by 17 packages. Updated 2018-08-19. Refresh now. Tools for package owners.