NewServer creates a new runtime server. The provided ctx is used for the lifetime of the server for background refresh of the JWKS that is used to validate auth tokens.
(ctx context.Context, opts *Options, rt *runtime.Runtime, logger *zap.Logger, limiter ratelimit.Limiter, activityClient *activity.Client)
| 74 | // NewServer creates a new runtime server. |
| 75 | // The provided ctx is used for the lifetime of the server for background refresh of the JWKS that is used to validate auth tokens. |
| 76 | func NewServer(ctx context.Context, opts *Options, rt *runtime.Runtime, logger *zap.Logger, limiter ratelimit.Limiter, activityClient *activity.Client) (*Server, error) { |
| 77 | // The runtime doesn't actually set cookies, but we use securecookie to encode/decode ephemeral tokens. |
| 78 | // If no session key pairs are provided, we generate a random one for the duration of the process. |
| 79 | var codec *securetoken.Codec |
| 80 | if len(opts.SessionKeyPairs) == 0 { |
| 81 | codec = securetoken.NewRandom() |
| 82 | } else { |
| 83 | codec = securetoken.NewCodec(opts.SessionKeyPairs) |
| 84 | } |
| 85 | |
| 86 | srv := &Server{ |
| 87 | runtime: rt, |
| 88 | opts: opts, |
| 89 | logger: logger, |
| 90 | codec: codec, |
| 91 | limiter: limiter, |
| 92 | activity: activityClient, |
| 93 | ai: ai.NewRunner(rt, activityClient), |
| 94 | } |
| 95 | |
| 96 | if opts.AuthEnable { |
| 97 | aud, err := auth.OpenAudience(ctx, logger, opts.AuthIssuerURL, opts.AuthAudienceURL) |
| 98 | if err != nil { |
| 99 | return nil, err |
| 100 | } |
| 101 | srv.aud = aud |
| 102 | } |
| 103 | |
| 104 | return srv, nil |
| 105 | } |
| 106 | |
| 107 | // Close should be called when the server is done |
| 108 | func (s *Server) Close() error { |