pub struct CredentialMap {
pub version: u32,
pub tokens: Vec<CredentialEntry>,
pub groups: Option<BTreeMap<String, String>>,
}Expand description
The host-side credential map (areev-auth.json): tokens → principal
names, nothing else. No verbs, no namespaces, no raw secrets — a token is
referenced by its SHA-256 or by the env var that holds it, so the file is
inert if stolen or synced.
Fields§
§version: u32§tokens: Vec<CredentialEntry>§groups: Option<BTreeMap<String, String>>IdP group → principal (A2). The same job the tokens list already
does — map an external identifier onto a principal the FILE grants
rights to — for the axis SSO actually scales on: without it every
person behind the proxy needs their own grant grain, which is the
administrative burden SSO exists to remove.
A group-derived principal is a ROLE, not a person. That is why it can
never answer a HITL approval, even under --sso-approvals allow:
“someone in engineering approved this” is not an audit record.
Implementations§
Source§impl CredentialMap
impl CredentialMap
Sourcepub fn from_json(s: &str) -> Result<CredentialMap>
pub fn from_json(s: &str) -> Result<CredentialMap>
Parse and validate. Fail closed: unknown keys, a bad version, an entry with both or neither credential form, or a malformed digest all refuse the whole map.
Sourcepub fn resolve(&self, presented: &str) -> Result<&str>
pub fn resolve(&self, presented: &str) -> Result<&str>
Resolve a presented bearer token to its principal. The error carries no part of the token — a refused secret must not leak into logs.
Expiry is evaluated against the system clock; resolve_at takes the
instant explicitly for tests.
Sourcepub fn resolve_at(&self, presented: &str, now_ms: i64) -> Result<&str>
pub fn resolve_at(&self, presented: &str, now_ms: i64) -> Result<&str>
resolve at an explicit instant.
Sourcepub fn resolve_id_at(&self, presented: &str, now_ms: i64) -> Option<String>
pub fn resolve_id_at(&self, presented: &str, now_ms: i64) -> Option<String>
The credential id that authenticated presented, for the audit/log
line on a SUCCESSFUL auth. Never call this on a failure path.
Sourcepub fn resolve_for_memory(&self, presented: &str, memory: &str) -> Result<&str>
pub fn resolve_for_memory(&self, presented: &str, memory: &str) -> Result<&str>
Resolve a token FOR ONE MEMORY: like resolve, but
a credential carrying a memories scope only authenticates when
memory is listed. The refusal is indistinguishable from an unknown
token — a scoped credential must not confirm which memories exist.
Sourcepub fn resolve_for_memory_at(
&self,
presented: &str,
memory: &str,
now_ms: i64,
) -> Result<&str>
pub fn resolve_for_memory_at( &self, presented: &str, memory: &str, now_ms: i64, ) -> Result<&str>
resolve_for_memory at an explicit
instant.
Sourcepub fn resolve_id_for_memory_at(
&self,
presented: &str,
memory: &str,
now_ms: i64,
) -> Option<String>
pub fn resolve_id_for_memory_at( &self, presented: &str, memory: &str, now_ms: i64, ) -> Option<String>
The credential id that authenticated presented on memory, for the
success log line. None on any refusal.
Sourcepub fn expiring_within(
&self,
now_ms: i64,
window_ms: i64,
) -> Vec<(String, String)>
pub fn expiring_within( &self, now_ms: i64, window_ms: i64, ) -> Vec<(String, String)>
Credentials expiring within window_ms of now_ms (and those already
expired), for the startup banner. Returns (id, expires_at) pairs.
A console that only reports an expiry at the moment it starts refusing is a console that reports it during an incident.
Sourcepub fn principal_for_group(&self, group: &str) -> Option<&str>
pub fn principal_for_group(&self, group: &str) -> Option<&str>
The principal an IdP group maps to, if any (A2).
Group names are compared case-insensitively: directories are
inconsistent about the case they emit (Engineering vs
engineering), and a mapping that silently misses because of it
fails open into whatever the identity alone was granted — which is
the wrong direction for an authorization lookup to be sloppy in.
Sourcepub fn knows_principal(&self, principal: &str) -> Result<()>
pub fn knows_principal(&self, principal: &str) -> Result<()>
Whether any credential authenticates as this principal — surfaces that require a known principal name use this to refuse typos early.