DVApiKeys class
Issues, authenticates, rotates and revokes API keys, over one database.
Constructors
- DVApiKeys({required DVDatabaseAdapter database, required DVApiScopes scopes, bool requireExpiry = false, Duration defaultOverlap = const Duration(days: 7), DateTime clock()?, Random? random, DVLogger? logger})
Properties
- database → DVDatabaseAdapter
-
final
- defaultOverlap → Duration
-
How long a rotated key keeps working when rotate is given no overlap.
final
- hashCode → int
-
The hash code for this object.
no setterinherited
- requireExpiry → bool
-
Whether a key issued with no expiry raises
DV-APIKEY-005.final - runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- scopes → DVApiScopes
-
final
Methods
-
audit(
String id) → Future< List< DVHistoryEntry> > -
Who issued, rotated and revoked key
id, and when. -
authenticate(
String presented, {String? tenant}) → Future< DVApiPrincipal?> -
The principal
presentedauthenticates as, or null. -
authentication(
{required String? credentialOf(Object? request)}) → Middleware -
The authentication stage: the credential
credentialOffinds on the request becomes the principal under principalKey, or the call stops. -
check(
String presented, {String? tenant}) → Future< DVApiKeyCheck> -
Checks
presented, with the reason when it does not authenticate. -
ensureSchema(
) → Future< void> -
find(
String id) → Future< DVApiKey?> -
The key with
id, revoked or expired ones included. -
forTenant(
String tenant) → Future< List< DVApiKey> > -
Every key on
tenant, oldest first. -
issue(
{required List< String> scopes, String? tenant, Duration? expiresIn, String? name, String? ratePlan, String? actor}) → Future<DVIssuedApiKey> -
Issues a key on
tenantwithscopes, defaulting to the tenant the current work is running for. -
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
principalFor(
DVApiKey key) → DVApiPrincipal -
The principal
keyacts as, with its scopes resolved under the current declaration. -
rateLimit(
Map< String, DVApiRatePlan> plans, {DVApiRatePlan? unplanned}) → Middleware - Each key's rate plan, enforced by the rate-limiting middleware that already exists, one limiter per plan counting per key.
-
revoke(
String id, {String? actor}) → Future< void> -
Revokes key
id. Its next call fails; there is no overlap. -
rotate(
String id, {Duration? overlap, String? actor}) → Future< DVIssuedApiKey> -
Issues a replacement for key
idand leavesidworking foroverlap(or defaultOverlap), never past its own expiry. -
toString(
) → String -
A string representation of this object.
inherited
-
usage(
{required DVMeters meters, required DVMeterDefinition meter, required String requestIdOf(Object? request)}) → Middleware -
Records one call against
meteron the key's tenant, idempotently per request, and stops the call when the meter does not admit it.
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited
Constants
- keyPrefix → const String
- Every key starts with this, so a scanner can find one pasted where it should not be.
- principalKey → const String
- Where authentication puts the principal on a MiddlewareContext.