Expand description
The page layer’s session extractors.
Thin wrappers over Authenticated and AuthenticatedWrite, and
deliberately nothing more. resolve_session, check_csrf and
check_origin stay the single implementation in
crate::webadmin::session: a second copy written “for pages” is how the
two front ends would drift into disagreeing about what a live session is.
All these add is the answer to a failure. The API says 401; a browser
needs to arrive at the sign-in page, and htmx needs to be told to navigate
rather than swap — see super::error::PageError.
Structs§
- Page
Admin Read - A signed-in admin on a page that only reads other operators. Wraps
AdminRead, so there is no CSRF or origin gate — see that type for why the/ui/operatorsreads are tiered at all. - Page
Admin Write - A signed-in admin on a page that manages other operators, with the
origin and CSRF gates passed. Wraps
AdminWrite. - Page
Enrol Write - A session allowed to set up a factor, on a page that writes.
- Page
MfaPending - A half-authenticated session, on the page that shows the challenge.
- Page
MfaSubmit - A half-authenticated session, on the form that submits a code.
- Page
Self Service Write - A signed-in operator of any role, on a page that only touches their own
account. Wraps
SelfServiceWrite. - Page
Session - A signed-in operator, on a page that only reads.
- Page
Session Write - A signed-in operator on a page that writes, with the origin and CSRF gates already passed.
Traits§
- Page
Auth - What
pages::chromeneeds of a page extractor: the session and the operator behind it.
Functions§
- is_htmx
- Whether this request came from htmx rather than from the address bar.