Files
headscale/hscontrol/db/credential.go
T
Kristoffer Dalby 393dd3e2d9 db: store all credentials in one SHA-256-hashed table
API keys, pre-auth keys and OAuth clients/tokens share one table and verify
path. Secrets carry 256 bits of crypto/rand entropy, so a SHA-256 digest
needs no stretching; bcrypt/argon2id rows rehash on use until 0.32.
2026-09-26 00:33:12 +02:00

73 lines
2.1 KiB
Go

package db
import (
"github.com/juanfont/headscale/hscontrol/types"
)
// credentialToAPIKey projects a unified credentials row onto the [types.APIKey]
// shape the API, state, and CLI layers consume.
func credentialToAPIKey(c *types.Credential) *types.APIKey {
return &types.APIKey{
ID: c.ID,
Prefix: c.Identifier,
Hash: c.Hash,
UserID: c.UserID,
CreatedAt: c.CreatedAt,
Expiration: c.Expiration,
LastSeen: c.LastSeen,
}
}
// credentialToOAuthClient projects a unified credentials row onto the
// [types.OAuthClient] shape. The client id is stored as the row's identifier.
func credentialToOAuthClient(c *types.Credential) *types.OAuthClient {
return &types.OAuthClient{
ID: c.ID,
ClientID: c.Identifier,
SecretHash: c.Hash,
Scopes: c.Scopes,
Tags: c.Tags,
Description: c.Description,
UserID: c.UserID,
CreatedAt: c.CreatedAt,
Revoked: c.Revoked,
}
}
// credentialToPreAuthKey projects a unified credentials row onto the
// [types.PreAuthKey] shape. The lookup prefix is stored as the row's identifier;
// the User association is carried through when preloaded.
func credentialToPreAuthKey(c *types.Credential) *types.PreAuthKey {
return &types.PreAuthKey{
ID: c.ID,
Prefix: c.Identifier,
Hash: c.Hash,
UserID: c.UserID,
User: c.User,
Description: c.Description,
Reusable: c.Reusable,
Ephemeral: c.Ephemeral,
Used: c.Used,
Tags: c.Tags,
CreatedAt: c.CreatedAt,
Expiration: c.Expiration,
Revoked: c.Revoked,
}
}
// credentialToOAuthAccessToken projects a unified credentials row onto the
// [types.OAuthAccessToken] shape. The token's lookup prefix is stored as the
// row's identifier; ClientID links back to the issuing client's identifier.
func credentialToOAuthAccessToken(c *types.Credential) *types.OAuthAccessToken {
return &types.OAuthAccessToken{
ID: c.ID,
Prefix: c.Identifier,
Hash: c.Hash,
ClientID: c.ClientID,
Scopes: c.Scopes,
Tags: c.Tags,
Expiration: c.Expiration,
CreatedAt: c.CreatedAt,
}
}