github.com/l1fe-labs/forge-go/auth
Go auth package.
Go auth package.
Package contract
| Field | Value |
|---|---|
| Language | go |
| Source version | module source snapshot |
| Manifest | forge-go/go.mod |
| Source files | 4 |
| Evidence | Source reference; registry publication and runtime conformance are separate checks |
Import boundary
import "github.com/l1fe-labs/forge-go/auth"Use a source checkout or your verified private registry. Manifest coordinates identify the package; they do not establish that a public registry release exists.
Source reference
Download package reference JSON. Each original source file and generated declaration artifact has its own SHA-256 digest. Function bodies and constant values are omitted from downloads. These are source declaration inventories, not compiler-resolved rustdoc, TypeDoc, DocC, or Dokka output. Private modules can contain public declarations that are not reachable through the package boundary; consult the entry point before importing.
capability.go
Read declaration text · 21 declaration entries
type Scope struct
func NewScope(s string) (Scope, error)
func WildcardScope() Scope
func (s Scope) String() string
func (s Scope) Implies(other Scope) bool
type ScopeSet struct
func NewScopeSet(scopes ...Scope) ScopeSet
func ParseScopeSet(scopeStrs ...string) (ScopeSet, error)
func (ss ScopeSet) Allows(requested Scope) bool
func (ss ScopeSet) Strings() []string
func (ss ScopeSet) Len() int
func (ss ScopeSet) IsEmpty() bool
func (ss ScopeSet) IsSubsetOf(other ScopeSet) bool
type DelegationConstraints struct
type ArsenalACT struct
func (a *ArsenalACT) IsExpired() bool
func (a *ArsenalACT) IsNotYetValid() bool
func (a *ArsenalACT) TTLRemaining() time.Duration
func VerifyACT(act *ArsenalACT) error
func ExtractScopes(act *ArsenalACT) []string
func ACTAllowsScope(act *ArsenalACT, scope string) (bool, error)delegation.go
Read declaration text · 2 declaration entries
type DelegationRequest struct
func DelegateCapabilities(req DelegationRequest) (*ArsenalACT, error)error.go
Read declaration text · 16 declaration entries
type ErrKind string
const (
// ErrKindTokenExpired indicates that the ACT has expired.
ErrKindTokenExpired ErrKind;
type AuthError struct
func (e *AuthError) Error() string
func (e *AuthError) Unwrap() error
func (e *AuthError) Is(target error) bool
func (e *AuthError) IsExpired() bool
func (e *AuthError) IsInsufficientScope() bool
func (e *AuthError) IsCapabilityEscalation() bool
func (e *AuthError) IsDelegationDenied() bool
func (e *AuthError) IsInvalidToken() bool
func (e *AuthError) ErrorCode() string
func NewTokenExpiredError(tokenID, agentDID, expiredAt string) *AuthError
func NewInsufficientScopeError(agentDID, requiredScope string, availableScopes []string) *AuthError
func NewCapabilityEscalationError(parentDID, childDID, requested string, available []string) *AuthError
func NewDelegationDeniedError(parentDID, childDID, reason string) *AuthError
func NewInvalidTokenError(reason string) *AuthErrortool_auth.go
Read declaration text · 9 declaration entries
type ToolTier int
const (
// ToolTierPlatform (Tier 1) tools run inside the sandbox and are always
// available without authorization.
ToolTierPlatform ToolTier;
func (t ToolTier) String() string
func (t ToolTier) RequiresAuthorization() bool
type ToolAuthorizationRequest struct
type ToolAuthorizationDecision int
const (
// Allowed indicates the tool invocation is authorized.
Allowed ToolAuthorizationDecision;
func (d ToolAuthorizationDecision) String() string
type ToolAuthorizationResult struct
func AuthorizeToolInvocation(req ToolAuthorizationRequest) (*ToolAuthorizationResult, error)
func BuildToolScope(toolName string) string