Named middleware resolves at boot, HS256 tokens are pinned with required exp/sub, and both binaries expose a signal-aware serve command. Co-authored-by: Cursor <cursoragent@cursor.com>
29 lines
642 B
Go
29 lines
642 B
Go
package bouncer
|
|
|
|
import "context"
|
|
|
|
type userKey struct{}
|
|
|
|
// Principal is the authenticated identity stored on the request context.
|
|
type Principal struct {
|
|
ID uint
|
|
MustChangePassword bool
|
|
}
|
|
|
|
// WithUser stores the verified principal on ctx.
|
|
func WithUser(ctx context.Context, user *Principal) context.Context {
|
|
if ctx == nil {
|
|
ctx = context.Background()
|
|
}
|
|
return context.WithValue(ctx, userKey{}, user)
|
|
}
|
|
|
|
// User returns the verified principal from ctx.
|
|
func User(ctx context.Context) (*Principal, bool) {
|
|
if ctx == nil {
|
|
return nil, false
|
|
}
|
|
u, ok := ctx.Value(userKey{}).(*Principal)
|
|
return u, ok && u != nil
|
|
}
|