Skip to main content

Module auth

Module auth 

Source
Expand description

The page layer’s session extractors.

Thin wrappers over Authenticated and AuthenticatedWrite, and deliberately nothing more. resolve_session, check_csrf and check_origin stay the single implementation in crate::webadmin::session: a second copy written “for pages” is how the two front ends would drift into disagreeing about what a live session is.

All these add is the answer to a failure. The API says 401; a browser needs to arrive at the sign-in page, and htmx needs to be told to navigate rather than swap — see super::error::PageError.

Structs§

PageAdminRead
A signed-in admin on a page that only reads other operators. Wraps AdminRead, so there is no CSRF or origin gate — see that type for why the /ui/operators reads are tiered at all.
PageAdminWrite
A signed-in admin on a page that manages other operators, with the origin and CSRF gates passed. Wraps AdminWrite.
PageEnrolWrite
A session allowed to set up a factor, on a page that writes.
PageMfaPending
A half-authenticated session, on the page that shows the challenge.
PageMfaSubmit
A half-authenticated session, on the form that submits a code.
PageSelfServiceWrite
A signed-in operator of any role, on a page that only touches their own account. Wraps SelfServiceWrite.
PageSession
A signed-in operator, on a page that only reads.
PageSessionWrite
A signed-in operator on a page that writes, with the origin and CSRF gates already passed.

Traits§

PageAuth
What pages::chrome needs of a page extractor: the session and the operator behind it.

Functions§

is_htmx
Whether this request came from htmx rather than from the address bar.