go-dev-auth是一个专为Go语言开发的认证库,采用纯标准库实现,不依赖任何第三方模块1。该项目已进入生产使用阶段,在真实项目的PostgreSQL数据库上成功运行完整功能集,目前正推进v1.0正式版发布1。
该库支持丰富的认证方式与功能,包括邮箱密码登录、OAuth 2.0和OIDC社交登录、会话管理、双因素认证、WebAuthn密钥、魔法链接、组织管理、单点登录、API密钥及JWT1。在安全性方面,采用scrypt密码哈希(参数为N=16384、r=16、p=1)、AES-256-GCM加密、审计日志、速率限制和密钥轮换机制1。库内置了CBOR和COSE解析功能,以及ES256、RS256和Ed25519签名验证能力1。
数据库方面,该库已验证支持SQLite、PostgreSQL和MySQL,MongoDB仍处于测试阶段1。要达成v1.0发布目标,项目仍需完成可运行示例的开发、MySQL生产环境的验证,以及第三方安全审计1。
Go-dev-auth, a zero-dependency authentication library for the Go programming language, is moving toward its v1.0 release after reaching production readiness 1. The library implements a comprehensive feature set using only the Go standard library, including email-password authentication, OAuth 2.0 and OIDC social login, session management, two-factor authentication, WebAuthn keys, magic links, organization management, single sign-on, API keys, and JWT support 1.
The library's implementation handles complex cryptographic operations natively, featuring CBOR and COSE parsing alongside ES256, RS256, and Ed25519 signature verification without external dependencies 1. Security is enforced through scrypt password hashing with parameters set to N=16384, r=16, and p=1, combined with AES-256-GCM encryption, audit logging, rate limiting, and key rotation mechanisms 1. The project has been validated across multiple database backends including SQLite, PostgreSQL, and MySQL in production environments, with MongoDB support currently in testing stages 1.
To complete the v1.0 milestone, the project requires a runnable example application, production environment verification on MySQL, and a third-party security audit 1.
评论
还没有评论,欢迎留下第一条。