pub struct PasswordContext { /* private fields */ }Expand description
The words that name this deployment, barred from an operator’s password.
ASVS 5.0 V6.1.2 asks for such a list to be documented and V6.2.11
for it to be enforced; the operator-facing copy is
doc/src/operations/webadmin_users.md. It is derived rather than
hardcoded because the name of the thing being protected is the first
password anybody reaches for, and that name differs per deployment.
Two limits are deliberate and worth knowing before trusting it:
- A CA already on disk is not described here.
[signer.local_ca.subject]is read only when this server generates a CA, so an adoptedca.pemcarries a subject configuration never sees. Reading it back would mean parsing every mounted profile’s certificate on a CLI path that has not otherwise opened one. Whencommon_nameis unset the built-in default isacme-proxy local CA, whose only words worth barring are already in [UNIVERSAL_CONTEXT_WORDS]. countryis excluded, being two characters and so below [MIN_CONTEXT_WORD_LEN] whatever it holds.
Implementations§
Source§impl PasswordContext
impl PasswordContext
Sourcepub fn empty() -> Self
pub fn empty() -> Self
No words: every password passes the context rule.
What a caller with no configuration in hand uses. It is a weaker check, never a wrong one – the length and corpus rules still run.
Sourcepub fn from_config(config: &Config, username: &str) -> Self
pub fn from_config(config: &Config, username: &str) -> Self
Derives the list from the deployment’s own configuration and the operator’s own name.
Cannot fail. A [profiles] table that will not resolve contributes
nothing and the global [signer] still does: refusing a password change
because an unrelated profile is misconfigured would be a lockout caused
by the control that exists to prevent one.
Trait Implementations§
Source§impl Clone for PasswordContext
impl Clone for PasswordContext
Source§impl Debug for PasswordContext
impl Debug for PasswordContext
Source§impl Default for PasswordContext
impl Default for PasswordContext
impl Eq for PasswordContext
Source§impl PartialEq for PasswordContext
impl PartialEq for PasswordContext
impl StructuralPartialEq for PasswordContext
Auto Trait Implementations§
impl Freeze for PasswordContext
impl RefUnwindSafe for PasswordContext
impl Send for PasswordContext
impl Sync for PasswordContext
impl Unpin for PasswordContext
impl UnsafeUnpin for PasswordContext
impl UnwindSafe for PasswordContext
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more