Runs the server side of a SASL exchange against a Sovite.SASL.Backend.
opts = [backend: {Sovite.SASL.Backend.Static, file: "/etc/sovite/users"}]
Sovite.SASL.Server.mechanisms(opts)
#=> ["PLAIN", "LOGIN", "SCRAM-SHA-256"]
case Sovite.SASL.Server.start("PLAIN", initial_response, opts) do
{:ok, identity} -> ...
{:challenge, data, server} -> # send data, then Sovite.SASL.Server.step(server, response)
{:error, reason, username} -> ...
endOptions
:backend-{module, opts}for passwords andSCRAM-SHA-256. Required.:token_backend-{module, opts}forOAUTHBEARER. Defaults to:backend.:mechanisms- mechanisms to allow, in order of preference. Defaults to all the backends support. Unknown names are ignored.:scram_secret- a secret to derive fake salts for unknown users, soSCRAM-SHA-256does not reveal which users exist. Defaults to a random value per VM.:oauth_error- the JSON sent when anOAUTHBEARERtoken is rejected (RFC 7628 §3.2.2). Defaults to{"status":"invalid_token"}.
Errors
reason is :invalid_credentials, :malformed (the client broke the
protocol), :authorization_failed (the client asked to act as another
user), :temporary (the backend failed), :unsupported_mechanism, or
:no_scram_credentials (the user has no SCRAM-SHA-256 values; the
client sees the same reply as for a wrong password). username is the
name the client gave, if any, for logs.
Summary
Functions
Returns the mechanisms the backends support, filtered by :mechanisms.
Starts an exchange. initial is the client's initial response, ""
for an empty one, or nil for none.
Continues an exchange with the client's response to the last challenge.
Types
Functions
Returns the mechanisms the backends support, filtered by :mechanisms.
Starts an exchange. initial is the client's initial response, ""
for an empty one, or nil for none.
Continues an exchange with the client's response to the last challenge.