コンテンツにスキップ

Basic Auth

Basic Auth ミドルウェアは HTTP Basic 認証を提供します。

  • 有効な認証情報の場合、次のハンドラを呼び出します。
  • 認証情報がない、または無効な場合は 401 Unauthorized レスポンスを送信します。

すべてのコアミドルウェアは middleware パッケージに含まれています:

import "github.com/labstack/echo/v5/middleware"
e.Use(middleware.BasicAuth(func(c *echo.Context, username, password string) (bool, error) {
// Use a constant time comparison to prevent timing attacks.
if subtle.ConstantTimeCompare([]byte(username), []byte("joe")) == 1 &&
subtle.ConstantTimeCompare([]byte(password), []byte("secret")) == 1 {
return true, nil
}
return false, nil
}))
e.Use(middleware.BasicAuthWithConfig(middleware.BasicAuthConfig{}))

BasicAuthConfig · github.com/labstack/echo/v5@5196b9b

フィールドの説明は英語のソースコードのコメントから生成されています。

パッケージのソースコードのフィールド
フィールド型説明ソース
Skipper Skipper Skipper defines a function to skip middleware. L23
Validator BasicAuthValidator Validator is a function to validate BasicAuthWithConfig credentials. Note: if request contains multiple basic auth headers this function would be called once for each header until first valid result is returned Required. L28
Realm string Realm is a string to define realm attribute of BasicAuthWithConfig. Default value "Restricted". L32
AllowedCheckLimit uint AllowedCheckLimit set how many headers are allowed to be checked. This is useful environments like corporate test environments with application proxies restricting access to environment with their own auth scheme. Defaults to 1. L38
パッケージのソースコードの関数
型ソース
func BasicAuth(fn BasicAuthValidator) echo.MiddlewareFunc L87
func BasicAuthWithConfig(config BasicAuthConfig) echo.MiddlewareFunc L92

Validator のシグネチャは次のとおりです。

type BasicAuthValidator func(c *echo.Context, user string, password string) (bool, error)
// Effective defaults applied when fields are left unset.
BasicAuthConfig{
Skipper: DefaultSkipper,
Realm: "Restricted",
}