forked from o1egl/paseto
/
protocol.go
61 lines (54 loc) · 2.2 KB
/
protocol.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
package paseto
import (
"crypto"
"errors"
)
var (
// ErrUnsupportedTokenVersion unsupported parser version
ErrUnsupportedTokenVersion = errors.New("unsupported parser version")
// ErrUnsupportedTokenType unsupported token type
ErrUnsupportedTokenType = errors.New("unsupported token type")
// ErrIncorrectPrivateKeyType incorrect private key type
ErrIncorrectPrivateKeyType = errors.New("incorrect private key type")
// ErrIncorrectPublicKeyType incorrect public key type
ErrIncorrectPublicKeyType = errors.New("incorrect public key type")
// ErrPublicKeyNotFound public key for this version not found
ErrPublicKeyNotFound = errors.New("public key for this version not found")
// ErrIncorrectTokenFormat incorrect token format
ErrIncorrectTokenFormat = errors.New("incorrect token format")
// ErrIncorrectTokenHeader incorrect token header
ErrIncorrectTokenHeader = errors.New("incorrect token header")
// ErrInvalidTokenAuth invalid token authentication
ErrInvalidTokenAuth = errors.New("invalid token authentication")
// ErrInvalidSignature invalid signature
ErrInvalidSignature = errors.New("invalid signature")
// ErrDataUnmarshal can't unmarshal token data to the given type of value
ErrDataUnmarshal = errors.New("can't unmarshal token data to the given type of value")
)
type opsFunc func(ops *options)
type options struct {
footer interface{}
nonce []byte
}
// WithFooter adds footer to the token
func WithFooter(footer interface{}) func(*options) {
return func(c *options) {
c.footer = footer
}
}
func withNonce(nonce []byte) func(*options) {
return func(c *options) {
c.nonce = nonce
}
}
// Protocol defines PASETO tokes protocol
type Protocol interface {
// Encrypt encrypts token with symmetric key
Encrypt(key []byte, payload interface{}, options ...opsFunc) (string, error)
// Decrypt decrypts key encrypted with symmetric key
Decrypt(token string, key []byte, payload interface{}, footer interface{}) error
// Sign signs token with given private key
Sign(privateKey crypto.PrivateKey, payload interface{}, options ...opsFunc) (string, error)
// Verify verifies token with given public key
Verify(token string, publicKey crypto.PublicKey, value interface{}, footer interface{}) error
}