pub struct ApiKeyAuthInterceptor { /* private fields */ }Expand description
Rejects requests whose API-key header is absent or not in the allowed set.
The header name defaults to x-api-key (matched case-insensitively, as all
header keys in CallContext are lowercased) and is configurable via
with_header.
Implementations§
Source§impl ApiKeyAuthInterceptor
impl ApiKeyAuthInterceptor
Sourcepub fn new<I, S>(keys: I) -> Self
pub fn new<I, S>(keys: I) -> Self
Creates an interceptor accepting any of the given keys on the default
x-api-key header.
Sourcepub fn with_labelled_keys<I, K, L>(entries: I) -> Self
pub fn with_labelled_keys<I, K, L>(entries: I) -> Self
Creates an interceptor whose keys each name the caller they belong to.
The label becomes CallContext::caller_identity, which is what
RateLimitInterceptor keys a budget on.
Without labels every holder of a valid key shares the "anonymous"
bucket, so one noisy client spends everyone’s budget — per-caller rate
limiting that is not per-caller.
The label is deliberately not derived from the key. A caller key is written to a rate-limit table that may be shared across replicas, and can reach logs and metrics; a credential should be in none of those. Naming the callers keeps the secret out of all of them.
§Example
use a2a_protocol_server::ApiKeyAuthInterceptor;
let auth = ApiKeyAuthInterceptor::with_labelled_keys([
("key-for-acme", "acme"),
("key-for-globex", "globex"),
]);Sourcepub fn with_header(self, header_name: impl Into<String>) -> Self
pub fn with_header(self, header_name: impl Into<String>) -> Self
Sets the header name to read the key from (lowercased automatically).
Trait Implementations§
Source§impl Debug for ApiKeyAuthInterceptor
impl Debug for ApiKeyAuthInterceptor
Source§impl ServerInterceptor for ApiKeyAuthInterceptor
impl ServerInterceptor for ApiKeyAuthInterceptor
Source§fn before<'a>(
&'a self,
ctx: &'a CallContext,
) -> Pin<Box<dyn Future<Output = A2aResult<()>> + Send + 'a>>
fn before<'a>( &'a self, ctx: &'a CallContext, ) -> Pin<Box<dyn Future<Output = A2aResult<()>> + Send + 'a>>
Auto Trait Implementations§
impl Freeze for ApiKeyAuthInterceptor
impl RefUnwindSafe for ApiKeyAuthInterceptor
impl Send for ApiKeyAuthInterceptor
impl Sync for ApiKeyAuthInterceptor
impl Unpin for ApiKeyAuthInterceptor
impl UnsafeUnpin for ApiKeyAuthInterceptor
impl UnwindSafe for ApiKeyAuthInterceptor
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> FutureExt for T
impl<T> FutureExt for T
Source§fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
fn with_context(self, otel_cx: Context) -> WithContext<Self> ⓘ
Source§fn with_current_context(self) -> WithContext<Self> ⓘ
fn with_current_context(self) -> WithContext<Self> ⓘ
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> IntoRequest<T> for T
impl<T> IntoRequest<T> for T
Source§fn into_request(self) -> Request<T>
fn into_request(self) -> Request<T>
T in a tonic::Request