Skip to content
Accounts and security

Accounts and security

  • Add accounts with make:auth: Give your app user accounts in one command: registration, login with “remember me” and throttling, sign-in with Google and GitHub, two-factor sign-in, account settings, logout, email verification, password reset and API tokens, with their pages, emails, routes, migration and tests. The code is written into your app, where you change it as you like; the parts that must be right (password hashing, tokens, sessions, throttling, the OAuth flow) stay in the auth and social packages, so fixes reach you with go get -u.
  • Authentication: Let people register, log in (with “remember me”), log out, verify their email address and reset a forgotten password, and give API clients tokens. The complete app is examples/auth. In an anetos new project, go tool anetos make:auth writes all of this into your app: see Add accounts with make:auth. This guide is the auth package underneath, step by step.
  • Social login: Let users sign in with Google, GitHub, or any OpenID Connect provider (Okta, Auth0, Microsoft Entra ID, Keycloak, GitLab…). The complete app is examples/auth.
  • Two-factor sign-in and password confirmation: Ask for more than a password: a code from an authenticator app (Google Authenticator, 1Password, Authy… : TOTP, RFC 6238) after it, with recovery codes for a lost phone; and the password again before sensitive pages. Package auth does the parts that must be right (secrets encrypted, codes used once, throttling); your handlers and pages call it. The complete app is examples/auth.
  • Authorization: Decide what a signed-in user may do, with policies the compiler checks.
  • Roles and permissions: Give users roles, globally or in a team, and check what they may do, with package auth/rbac.
  • Rate limiting: Limit how often clients can call your routes, and how often they can attempt actions such as logging in.
  • Keep an audit log: Record who created, changed, deleted and restored the rows of your models, field by field, with package audit: for data governance, for support, and for “who changed this?”.
  • Add an admin panel: Give your staff pages to list, search, filter, create, edit and delete the app’s records, and to manage users and roles, with the admin interface of module anetos.dev/anetos/admin: no front-end build, permissions from roles, and every change in the audit log for the models it tracks.