package pgconn import ( "fmt" "strings" ) // authMethod is one of the method keywords accepted by libpq's require_auth. type authMethod uint8 const ( authMethodPassword authMethod = iota authMethodMD5 authMethodGSS authMethodSSPI authMethodSCRAMSHA256 authMethodOAuth authMethodNone authMethodCount ) var authMethodNames = [authMethodCount]string{ authMethodPassword: "password", authMethodMD5: "md5", authMethodGSS: "gss", authMethodSSPI: "sspi", authMethodSCRAMSHA256: "scram-sha-256", authMethodOAuth: "oauth", authMethodNone: "none", } // requireAuth is the parsed form of the require_auth connection parameter. It mirrors libpq's // auth_required / allowed_auth_methods bookkeeping (see fe-connect.c, conn->allowed_auth_methods). type requireAuth struct { // raw is the original parameter value, used in error messages. raw string // authRequired is true when the server must complete an authentication exchange before sending // AuthenticationOk. It is false when the parameter is unset, fully negated, or "none" is in the // allowed set. authRequired bool // allowed is a bitmask of permitted authMethod values. allowed uint8 } func (ra requireAuth) allows(m authMethod) bool { return ra.allowed&(1<