CI / changes (push) Successful in 7s
CI / commitlint (push) Has been skipped
CI / openapi (push) Successful in 25s
CI / web (push) Successful in 28s
CI / go (push) Failing after 24s
CI / bird2 (push) Has been skipped
CI / release (push) Has been skipped
- Added endpoints for managing API keys, including creation, retrieval, updating, and revocation. - Introduced a new Auth session endpoint to retrieve current tenant and role information. - Updated the authentication middleware to support API key-based authentication and track last used timestamps. - Enhanced documentation to reflect new API key functionalities and usage guidelines. - Improved logging for demo authentication scenarios.
35 lines
836 B
Go
35 lines
836 B
Go
// Package authkey generates API tokens and derives lookup hashes (no persistence).
|
|
package authkey
|
|
|
|
import (
|
|
"crypto/rand"
|
|
"crypto/sha256"
|
|
"encoding/base64"
|
|
"fmt"
|
|
)
|
|
|
|
const tokenPrefix = "evobgp_"
|
|
|
|
// GenerateToken returns a new bearer token (evobgp_ + 32 random bytes, base64url).
|
|
func GenerateToken() (string, error) {
|
|
b := make([]byte, 32)
|
|
if _, err := rand.Read(b); err != nil {
|
|
return "", fmt.Errorf("authkey: generate token: %w", err)
|
|
}
|
|
return tokenPrefix + base64.RawURLEncoding.EncodeToString(b), nil
|
|
}
|
|
|
|
// HashToken returns SHA-256 of the full token (32 bytes).
|
|
func HashToken(token string) []byte {
|
|
sum := sha256.Sum256([]byte(token))
|
|
return sum[:]
|
|
}
|
|
|
|
// Prefix returns the first 8 characters of the token for display.
|
|
func Prefix(token string) string {
|
|
if len(token) <= 8 {
|
|
return token
|
|
}
|
|
return token[:8]
|
|
}
|