AuthApiKeyPlugin<TContext> class
final
Complete API-key capability with lifecycle endpoints and client metadata.
- Implemented types
-
- AuthServerPlugin<
TContext> - AuthEndpointContributor<
TContext> - AuthHostEndpointContributor<
TContext> - AuthPersistenceContributor
- AuthClientOperationContributor
- AuthRateLimitContributor
- AuthAuthenticationMethodInventoryContributor
- AuthAuthenticationMethodInventoryBinding
- AuthAuthenticationMethodInventoryControl
- AuthUserDeletionPlanContributor
- AuthUserAccessRevocationContributor
- AuthServerPlugin<
Constructors
- AuthApiKeyPlugin({required AuthApiKeyStore store, String keyPrefix = 'rka', Duration defaultLifetime = const Duration(days: 90), Duration maxLifetime = const Duration(days: 365), bool sessionExchangeEnabled = false, bool countsAsPrimaryAuthenticationMethod = false, AuthApiKeyTokenGenerator keyIdGenerator = secureRandomToken, AuthApiKeyTokenGenerator secretGenerator = secureRandomToken, DateTime clock()?})
-
Creates an API-key plugin backed by
store.
Properties
- authenticationMethodInventoryEnabled → bool
-
Whether this contributor should participate in inventory composition.
no setteroverride
-
authenticationMethodKinds
→ Set<
AuthAuthenticationMethodKind> -
Method kinds that this store can report authoritatively.
no setteroverride
- authenticationMethodNamespace → String
-
Stable namespace owned by this contributor.
no setteroverride
- authenticationMethodStore → Object
-
Store or coordinator that owns this contributor's method data.
no setteroverride
-
clientOperations
→ Iterable<
AuthClientOperationDescriptor> -
Client operations declared by the plugin.
no setteroverride
- countsAsPrimaryAuthenticationMethod → bool
-
Whether active keys are valid fallback login methods for account safety.
final
- dataContract → AuthServerPluginDataContract
-
Declares data and destructive routes owned by this plugin.
no setteroverride
- defaultLifetime → Duration
-
Lifetime applied when an issue request omits an expiry.
final
-
endpoints
→ Iterable<
AuthEndpointDescriptor< TContext> > -
Runtime endpoints contributed by the plugin.
no setteroverride
- hashCode → int
-
The hash code for this object.
no setterinherited
-
hostEndpoints
→ Iterable<
AuthEndpointDescriptor< TContext> > -
Host-owned endpoint contracts enabled by the plugin.
no setteroverride
- id → String
-
Stable plugin identifier.
no setteroverride
- keyIdGenerator → AuthApiKeyTokenGenerator
-
Generates non-secret key identifiers.
final
- keyPrefix → String
-
Prefix used in raw key values and public key metadata.
final
- maxLifetime → Duration
-
Maximum lifetime accepted for an issued key.
final
-
persistenceSchemas
→ Iterable<
AuthPersistenceSchema> -
Persistence schemas declared by the plugin.
no setteroverride
-
rateLimitOperations
→ Iterable<
AuthRateLimitOperation> -
Rate-limit operations declared by the plugin.
no setteroverride
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
- secretGenerator → AuthApiKeyTokenGenerator
-
Generates the raw secret component returned at issue time.
final
- sessionExchangeEnabled → bool
-
Whether Routed adapters should expose API-key-to-session exchange.
final
- store → AuthApiKeyStore
-
Persistence backend for issued API keys.
final
- userAccessNamespace → String
-
Namespace of credentials or tokens revoked by this contributor.
no setteroverride
- userDataNamespace → String
-
The namespace used for plugin-owned user data.
no setteroverride
Methods
-
authenticate(
String rawKey, {DateTime? now}) → Future< AuthApiKeyAuthentication?> - Verifies a raw API key and atomically records its last use.
-
authenticationMethodsForUser(
String userId) → Future< AuthAuthenticationMethodSnapshot> -
Returns the usable methods for
userId.override -
configure(
AuthServerPluginContext< TContext> context) → void -
Configures this plugin against the shared runtime context.
override
-
createUserDeletionPlan(
AuthUser user) → Future< AuthUserDeletionPlan> -
Creates user deletion plan.
override
-
issue(
{required String userId, required String name, Iterable< String> scopes = const <String>[], DateTime? expiresAt, DateTime? now}) → Future<AuthApiKeyIssued> - Issues a key and returns the raw secret exactly once.
-
list(
String userId) → Future< List< AuthApiKey> > -
Lists public metadata for keys owned by
userId. -
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
revoke(
String userId, String id, {DateTime? now}) → Future< AuthApiKey?> -
Revokes the key
idwhen it belongs touserId. -
revokeUserAccess(
String userId) → Future< void> -
Revokes this contributor's access records for
userId.override -
rotate(
String userId, String id, {String? name, Iterable< String> ? scopes, DateTime? expiresAt, DateTime? now}) → Future<AuthApiKeyIssued?> - Replaces a key atomically and returns the new raw key once.
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited