pub enum AdminRole {
Viewer,
Operator,
Admin,
}Expand description
What a web-admin operator’s live sessions are allowed to do.
A privilege tier, not an authentication state (that is admin_sessions.state
and the pending_mfa / active split). Stored in admin_users.role as one
of the AdminRole::as_str spellings, with NULL read as Admin –
an operator created before the column existed keeps the authority they had,
and so does the bootstrap operator, who is the only way into the panel.
Variants are declared low privilege to high, so role >= AdminRole::Operator
is the gate the write extractors run (crates/admin/src/webadmin/session.rs).
Variants§
Viewer
Reads every page and API route; may still act on their own account (password, sessions, second factor, logout). Refused every shared or CA mutation.
Operator
Viewer, plus every CA mutation: revoke a certificate, deactivate or
delete an ACME account, delete an order, mint or revoke EAB credentials,
run a nonce sweep. Refused the colleague-management surface.
Admin
Operator, plus /operators/* – disabling or re-enabling a
colleague, resetting their second factor, revoking one of their
sessions. Everything.
Implementations§
Source§impl AdminRole
impl AdminRole
Sourcepub const ALL: &'static [Self]
pub const ALL: &'static [Self]
Every value, low privilege to high – the order the variants are declared in, and the one an error message lists them in.
Sourcepub fn from_storage(raw: Option<&str>) -> Self
pub fn from_storage(raw: Option<&str>) -> Self
Reads the column back. Infallible: NULL and "admin" are Admin,
and anything unrecognised is Viewer – the least-privilege direction,
the same fail-closed choice AdminUser::is_active makes for a status
outside its CHECK. A garbage value can only arrive by a hand-edit of
the database; every write path here goes through a canonical
AdminRole::as_str.
Trait Implementations§
impl Copy for AdminRole
impl Eq for AdminRole
Source§impl FromStr for AdminRole
impl FromStr for AdminRole
Source§impl Ord for AdminRole
impl Ord for AdminRole
1.21.0 (const: unstable) · Source§fn max(self, other: Self) -> Selfwhere
Self: Sized,
fn max(self, other: Self) -> Selfwhere
Self: Sized,
1.21.0 (const: unstable) · Source§fn min(self, other: Self) -> Selfwhere
Self: Sized,
fn min(self, other: Self) -> Selfwhere
Self: Sized,
Source§impl PartialOrd for AdminRole
impl PartialOrd for AdminRole
impl StructuralPartialEq for AdminRole
Auto Trait Implementations§
impl Freeze for AdminRole
impl RefUnwindSafe for AdminRole
impl Send for AdminRole
impl Sync for AdminRole
impl Unpin for AdminRole
impl UnsafeUnpin for AdminRole
impl UnwindSafe for AdminRole
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Comparable<K> for Q
impl<Q, K> Comparable<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more