| Safe Haskell | None |
|---|---|
| Language | GHC2021 |
Ecluse.Core.Credential
Description
The outbound-credential handle: the bearer token Écluse uses to write approved packages
to the mirror target. It serves Écluse's own store access only, never a read on a user's behalf:
a private-upstream read forwards the client's own credential (see
docs/architecture/registry-model.md, "Credential flow and authority").
The handle stays apart from the protocol handle Ecluse.Core.Registry because every managed registry speaks one protocol and differs only in how it hands out a token. Refresh, cache and expiry policy over a per-cloud mint live in Ecluse.Core.Credential.Refresh.
Synopsis
- data Secret
- mkSecret :: Text -> Secret
- unSecret :: Secret -> Text
- data ClientCredential = ClientCredential {}
- bareCredential :: Secret -> ClientCredential
- data AuthToken = AuthToken {}
- newtype CredentialProvider = CredentialProvider {}
- mintSecret :: CredentialProvider -> IO Secret
- staticProvider :: AuthToken -> CredentialProvider
Secrets
A short-lived secret (an access token). Build one with mkSecret and recover the text
only at the point of use with unSecret.
Instances
| FromJSON Secret Source # | Decoding reads the secret from configuration, for example the environment AST. |
Defined in Ecluse.Core.Credential | |
| ToJSON Secret Source # | The JSON encoding redacts the secret, so it never leaks into a JSON log. |
| Show Secret Source # | Render a fixed placeholder, never the secret text. It defines |
| Eq Secret Source # | Constant-time equality over the UTF-8 encoding. The |
unSecret :: Secret -> Text Source #
Recover the raw token text. Call this only at the point of use, when setting the auth header, and never log or otherwise render the result.
A client's presented credential
data ClientCredential Source #
A credential as a client presents it. The username is not part of the secret: a gate
compares credSecret alone, and a passthrough leg renders the pair verbatim.
Constructors
| ClientCredential | |
Fields
| |
Instances
| Show ClientCredential Source # | |
Defined in Ecluse.Core.Credential Methods showsPrec :: Int -> ClientCredential -> ShowS # show :: ClientCredential -> String # showList :: [ClientCredential] -> ShowS # | |
| Eq ClientCredential Source # | |
Defined in Ecluse.Core.Credential Methods (==) :: ClientCredential -> ClientCredential -> Bool # (/=) :: ClientCredential -> ClientCredential -> Bool # | |
bareCredential :: Secret -> ClientCredential Source #
A credential carrying no username, the form a bearer scheme recovers and a configured token takes.
Tokens
A bearer token for a registry endpoint. Cloud lifetimes run from CodeArtifact's ~12h to
ADC's ~1h, so a refresh schedules off authExpiresAt rather than a fixed interval.
Constructors
| AuthToken | |
Fields
| |
Provider handle
newtype CredentialProvider Source #
The credential handle: it yields the token currently valid for the mirror target and refreshes it before expiry internally, so no caller blocks on a mint on the hot path.
Constructors
| CredentialProvider | |
Fields
| |
mintSecret :: CredentialProvider -> IO Secret Source #
The secret a provider's current token carries, for a caller that presents it and reads no expiry. It refreshes behind the provider, so a long-lived caller mints per use.
In-memory double
staticProvider :: AuthToken -> CredentialProvider Source #
A CredentialProvider that always returns the same token, the static leaf. It never
refreshes, so it fits a registry reached with a long-lived credential.