package auth import ( "errors" "github.com/gin-gonic/gin" "chat-switchboard/models" "chat-switchboard/store" ) type Mode string const ( ModeBuiltin Mode = "builtin" ModeMTLS Mode = "mtls" ModeOIDC Mode = "oidc" ) func ParseMode(s string) (Mode, error) { switch Mode(s) { case ModeBuiltin, "": return ModeBuiltin, nil case ModeMTLS: return ModeMTLS, nil case ModeOIDC: return ModeOIDC, nil default: return "", ErrUnsupportedMode } } type Result struct { User *models.User IsNewUser bool VaultHint string // password (builtin) or "" (external) } type Provider interface { Mode() Mode Authenticate(c *gin.Context, stores store.Stores) (*Result, error) SupportsRegistration() bool Register(c *gin.Context, stores store.Stores) (*Result, error) } var ( ErrUnsupportedMode = errors.New("unsupported auth mode") ErrNotSupported = errors.New("operation not supported by this auth provider") ErrInvalidCreds = errors.New("invalid credentials") ErrInactive = errors.New("account is inactive") ErrRegistrationOff = errors.New("registration is disabled") ErrDuplicate = errors.New("username or email already taken") )