DVApiKeys class

Issues, authenticates, rotates and revokes API keys, over one database.

Constructors

DVApiKeys({required DVDatabaseAdapter database, required DVApiScopes scopes, bool requireExpiry = false, Duration defaultOverlap = const Duration(days: 7), DateTime clock()?, Random? random, DVLogger? logger})

Properties

database → DVDatabaseAdapter
final
defaultOverlap → Duration
How long a rotated key keeps working when rotate is given no overlap.
final
hashCode → int
The hash code for this object.
no setterinherited
requireExpiry → bool
Whether a key issued with no expiry raises DV-APIKEY-005.
final
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
scopes → DVApiScopes
final

Methods

audit(String id) → Future<List<DVHistoryEntry>>
Who issued, rotated and revoked key id, and when.
authenticate(String presented, {String? tenant}) → Future<DVApiPrincipal?>
The principal presented authenticates as, or null.
authentication({required String? credentialOf(Object? request)}) → Middleware
The authentication stage: the credential credentialOf finds on the request becomes the principal under principalKey, or the call stops.
check(String presented, {String? tenant}) → Future<DVApiKeyCheck>
Checks presented, with the reason when it does not authenticate.
ensureSchema() → Future<void>
find(String id) → Future<DVApiKey?>
The key with id, revoked or expired ones included.
forTenant(String tenant) → Future<List<DVApiKey>>
Every key on tenant, oldest first.
issue({required List<String> scopes, String? tenant, Duration? expiresIn, String? name, String? ratePlan, String? actor}) → Future<DVIssuedApiKey>
Issues a key on tenant with scopes, defaulting to the tenant the current work is running for.
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
principalFor(DVApiKey key) → DVApiPrincipal
The principal key acts as, with its scopes resolved under the current declaration.
rateLimit(Map<String, DVApiRatePlan> plans, {DVApiRatePlan? unplanned}) → Middleware
Each key's rate plan, enforced by the rate-limiting middleware that already exists, one limiter per plan counting per key.
revoke(String id, {String? actor}) → Future<void>
Revokes key id. Its next call fails; there is no overlap.
rotate(String id, {Duration? overlap, String? actor}) → Future<DVIssuedApiKey>
Issues a replacement for key id and leaves id working for overlap (or defaultOverlap), never past its own expiry.
toString() → String
A string representation of this object.
inherited
usage({required DVMeters meters, required DVMeterDefinition meter, required String requestIdOf(Object? request)}) → Middleware
Records one call against meter on the key's tenant, idempotently per request, and stops the call when the meter does not admit it.

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Constants

keyPrefix → const String
Every key starts with this, so a scanner can find one pasted where it should not be.
principalKey → const String
Where authentication puts the principal on a MiddlewareContext.