Key Auth
Key Auth ミドルウェアは key ベース認証を提供します。
- 有効な key の場合、次のハンドラを呼び出します。
- 無効な key の場合、
401 Unauthorizedレスポンスを送信します。 - key がない場合、
400 Bad Requestレスポンスを送信します。
すべてのコアミドルウェアは middleware パッケージに含まれています:
import "github.com/labstack/echo/v5/middleware"e.Use(middleware.KeyAuth(func(c *echo.Context, key string, source middleware.ExtractorSource) (bool, error) { return key == "valid-key", nil}))カスタム設定
Section titled “カスタム設定”e := echo.New()e.Use(middleware.KeyAuthWithConfig(middleware.KeyAuthConfig{ KeyLookup: "query:api-key", Validator: func(c *echo.Context, key string, source middleware.ExtractorSource) (bool, error) { return key == "valid-key", nil },}))KeyAuthConfig · github.com/labstack/echo/v5@5196b9b
フィールドの説明は英語のソースコードのコメントから生成されています。
| フィールド | 型 | 説明 | ソース |
|---|---|---|---|
Skipper | Skipper | Skipper defines a function to skip middleware. | L21 |
KeyLookup | string | KeyLookup is a string in the form of "<source>:<name>" or "<source>:<name>,<source>:<name>" that is used to extract key from the request. Optional. Default value "header:Authorization:Bearer ". Possible values: - "header:<name>" or "header:<name>:<cut-prefix>" `<cut-prefix>` is argument value to cut/trim prefix of the extracted value. This is useful if header value has static prefix like `Authorization: <auth-scheme> <authorisation-parameters>` where part that we want to cut is `<auth-scheme> ` note the space at the end. In case of basic authentication `Authorization: Basic <credentials>` prefix we want to remove is `Basic `. - "query:<name>" - "form:<name>" - "cookie:<name>" Multiple sources example: - "header:Authorization,header:X-Api-Key" | L37 |
AllowedCheckLimit | uint | AllowedCheckLimit set how many KeyLookup values are allowed to be checked. This is useful environments like corporate test environments with application proxies restricting access to environment with their own auth scheme. | L42 |
Validator | KeyAuthValidator | Validator is a function to validate key. Required. | L46 |
ErrorHandler | KeyAuthErrorHandler | ErrorHandler defines a function which is executed when all lookups have been done and none of them passed Validator function. ErrorHandler is executed with last missing (ErrExtractionValueMissing) or an invalid key. It may be used to define a custom error. Note: when error handler swallows the error (returns nil) middleware continues handler chain execution towards handler. This is useful in cases when portion of your site/api is publicly accessible and has extra features for authorized users In that case you can use ErrorHandler to set default public auth value to request and continue with handler chain. | L55 |
ContinueOnIgnoredError | bool | ContinueOnIgnoredError allows the next middleware/handler to be called when ErrorHandler decides to ignore the error (by returning `nil`). This is useful when parts of your site/api allow public access and some authorized routes provide extra functionality. In that case you can use ErrorHandler to set a default public key auth value in the request context and continue. Some logic down the remaining execution chain needs to check that (public) key auth value then. | L62 |
Validator のシグネチャは次のとおりです。
type KeyAuthValidator func(c *echo.Context, key string, source ExtractorSource) (bool, error)デフォルト設定
Section titled “デフォルト設定”DefaultKeyAuthConfig = KeyAuthConfig{ Skipper: DefaultSkipper, KeyLookup: "header:" + echo.HeaderAuthorization + ":Bearer ",}