ecluse:ecluse-core
Safe HaskellNone
LanguageGHC2021

Ecluse.Core.Credential

Description

The outbound-credential handle: the bearer token Écluse uses to write approved packages to the mirror target. It serves Écluse's own store access only, never a read on a user's behalf: a private-upstream read forwards the client's own credential (see docs/architecture/registry-model.md, "Credential flow and authority").

The handle stays apart from the protocol handle Ecluse.Core.Registry because every managed registry speaks one protocol and differs only in how it hands out a token. Refresh, cache and expiry policy over a per-cloud mint live in Ecluse.Core.Credential.Refresh.

Synopsis

Secrets

data Secret Source #

A short-lived secret (an access token). Build one with mkSecret and recover the text only at the point of use with unSecret.

Instances

Instances details
FromJSON Secret Source #

Decoding reads the secret from configuration, for example the environment AST.

Instance details

Defined in Ecluse.Core.Credential

ToJSON Secret Source #

The JSON encoding redacts the secret, so it never leaks into a JSON log.

Instance details

Defined in Ecluse.Core.Credential

Show Secret Source #

Render a fixed placeholder, never the secret text. It defines showsPrec because relude re-exports a polymorphic show that is not the class method.

Instance details

Defined in Ecluse.Core.Credential

Eq Secret Source #

Constant-time equality over the UTF-8 encoding. The ECLUSE_SERVER__AUTH_TOKEN edge gate compares through it, a short-circuit would leak the prefix length. The token length still leaks.

Instance details

Defined in Ecluse.Core.Credential

Methods

(==) :: Secret -> Secret -> Bool #

(/=) :: Secret -> Secret -> Bool #

mkSecret :: Text -> Secret Source #

Wrap raw token text as a Secret.

unSecret :: Secret -> Text Source #

Recover the raw token text. Call this only at the point of use, when setting the auth header, and never log or otherwise render the result.

A client's presented credential

data ClientCredential Source #

A credential as a client presents it. The username is not part of the secret: a gate compares credSecret alone, and a passthrough leg renders the pair verbatim.

Constructors

ClientCredential 

Fields

bareCredential :: Secret -> ClientCredential Source #

A credential carrying no username, the form a bearer scheme recovers and a configured token takes.

Tokens

data AuthToken Source #

A bearer token for a registry endpoint. Cloud lifetimes run from CodeArtifact's ~12h to ADC's ~1h, so a refresh schedules off authExpiresAt rather than a fixed interval.

Constructors

AuthToken 

Fields

Instances

Instances details
Show AuthToken Source # 
Instance details

Defined in Ecluse.Core.Credential

Eq AuthToken Source # 
Instance details

Defined in Ecluse.Core.Credential

Provider handle

newtype CredentialProvider Source #

The credential handle: it yields the token currently valid for the mirror target and refreshes it before expiry internally, so no caller blocks on a mint on the hot path.

Constructors

CredentialProvider 

Fields

mintSecret :: CredentialProvider -> IO Secret Source #

The secret a provider's current token carries, for a caller that presents it and reads no expiry. It refreshes behind the provider, so a long-lived caller mints per use.

In-memory double

staticProvider :: AuthToken -> CredentialProvider Source #

A CredentialProvider that always returns the same token, the static leaf. It never refreshes, so it fits a registry reached with a long-lived credential.