Skip to main content

DeviceLifecycleService

Struct DeviceLifecycleService 

Source
pub struct DeviceLifecycleService<S>
where S: DeviceStore,
{ /* private fields */ }
Available on crate feature device only.
Expand description

Composes DeviceStore primitives into the lifecycle operations every axess consumer needs at request/authn boundaries.

Cheap to clone (the inner store is Clone and the optional event sink is Arc-backed); construct once at startup and share across handlers.

Implementations§

Source§

impl<S> DeviceLifecycleService<S>
where S: DeviceStore,

Source

pub fn new(store: S) -> Self

Wrap a DeviceStore. Audit events are dropped on the floor until Self::with_event_sink is called; the underlying device-state mutations always happen regardless.

Source

pub fn with_event_sink<E: DeviceEventSink>(self, sink: E) -> Self

Wire a DeviceEventSink so device-lifecycle transitions emit audit events. Typically wraps an IdentityStore via IdentityStoreEventSink.

Source

pub fn store(&self) -> &S

Borrow the underlying store. Use sparingly: bypasses the lifecycle invariants this service exists to enforce.

Source

pub fn ensure_device( &self, tenant: &TenantId, user: Option<&UserId>, fingerprint: FingerprintHash, now: DateTime<Utc>, new_id_fn: impl FnOnce() -> DeviceId + Send, ) -> impl Future<Output = Result<DeviceId, S::Error>> + Send

Look up a device by fingerprint within tenant. If present, bump last_seen_at = now and return its device_id. If absent, create a new row at DeviceTrustLevel::Unknown using new_id_fn() for the device_id and return it.

user is None for guest sessions (pre-authn requests). The user_id field on the created Device row is set to whatever is passed in; updates that arrive later (e.g. when authn completes for a previously-guest device) need to call DeviceStore::save directly via Self::store; this helper deliberately doesn’t touch user_id on the existing- device path to keep the create-vs-find branches symmetric.

new_id_fn is the application’s choice of identifier scheme. Pass || DeviceId::try_new(Uuid::new_v4().to_string()).unwrap() for the canonical UUID-v4 shape, or a deterministic generator driven by MockRng for tests. Only called on the create path.

Source

pub fn promote_on_authn( &self, tenant: &TenantId, device_id: &DeviceId, now: DateTime<Utc>, ) -> impl Future<Output = Result<Option<DeviceTrustLevel>, S::Error>> + Send

Promote a device’s trust level after a successful authentication ceremony.

State machine:

CurrentAfter promote_on_authn
UnknownSeen (recorded with record_sighting(now))
SeenSeen (no-op; last_seen_at bumped)
TrustedTrusted (no-op; last_seen_at bumped)
RevokedRevoked (no-op; last_seen_at not bumped)

Never re-elevates a Revoked device. Revocation is a terminal state until an admin / user explicitly resurrects the device via DeviceStore::set_trust_level; passing through promote_on_authn after a successful login on a revoked device must not silently undo the revocation. (The application should reject the login earlier in such cases; this is defence-in-depth.)

Never demotes a Trusted device. A Trusted device that authenticates again stays Trusted. This is the standard “user elevated device once via explicit consent; subsequent logins don’t downgrade trust” semantic.

Returns the trust level the device is in after the call. Ok(None) if the device_id doesn’t resolve: defensive, callers shouldn’t see this if they pass an id from Self::ensure_device.

Source

pub fn promote_if_authenticated( &self, outcome: &FactorOutcome, tenant: &TenantId, device_id: &DeviceId, now: DateTime<Utc>, ) -> impl Future<Output = Result<Option<DeviceTrustLevel>, S::Error>> + Send

Convenience composition for the AuthnService glue pattern: fire Self::promote_on_authn iff the FactorOutcome indicates the user just completed authentication. No-op on FactorRequired / InvalidCredential / Locked.

Usage:

let outcome = authn.complete_factor_step(...).await?;
let _ = device_lifecycle
    .promote_if_authenticated(&outcome, &tenant, &device_id, now)
    .await?;

Returns the same Option<DeviceTrustLevel> as Self::promote_on_authn when the outcome was Authenticated; Ok(None) otherwise (including the absent- device-id case, mirroring promote_on_authn semantics).

Source

pub fn bind_webauthn_credential( &self, tenant: &TenantId, device_id: &DeviceId, credential_id: String, attestation_class: AttestationClass, now: DateTime<Utc>, ) -> impl Future<Output = Result<bool, S::Error>> + Send

Available on crate feature fido2 only.

Record a DeviceBinding::WebAuthn on a device after a successful FIDO2 registration ceremony.

If the device already carries a WebAuthn binding for the same credential_id, this is a no-op (idempotent). Otherwise the new binding is appended and a AuthEventType::DeviceBindingAdded audit event is emitted.

Returns Ok(true) when a new binding was added, Ok(false) when deduplicated, Ok(None)-shaped Err when the device doesn’t exist.

Source

pub fn record_webauthn_usage( &self, tenant: &TenantId, device_id: &DeviceId, credential_id: &str, now: DateTime<Utc>, ) -> impl Future<Output = Result<(), S::Error>> + Send

Available on crate feature fido2 only.

Update the last_used_at timestamp on an existing DeviceBinding::WebAuthn after a successful FIDO2 assertion.

No-op if the device doesn’t exist or has no WebAuthn binding matching credential_id.

Trait Implementations§

Source§

impl<S> Clone for DeviceLifecycleService<S>
where S: DeviceStore + Clone,

Source§

fn clone(&self) -> DeviceLifecycleService<S>

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> ArchivePointee for T

Source§

type ArchivedMetadata = ()

The archived version of the pointer metadata for this type.
Source§

fn pointer_metadata( _: &<T as ArchivePointee>::ArchivedMetadata, ) -> <T as Pointee>::Metadata

Converts some archived metadata to the pointer metadata for itself.
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> LayoutRaw for T

Source§

fn layout_raw(_: <T as Pointee>::Metadata) -> Result<Layout, LayoutError>

Returns the layout of the type.
Source§

impl<T, N1, N2> Niching<NichedOption<T, N1>> for N2
where T: SharedNiching<N1, N2>, N1: Niching<T>, N2: Niching<T>,

Source§

unsafe fn is_niched(niched: *const NichedOption<T, N1>) -> bool

Returns whether the given value has been niched. Read more
Source§

fn resolve_niched(out: Place<NichedOption<T, N1>>)

Writes data to out indicating that a T is niched.
Source§

impl<T> Pointable for T

Source§

const ALIGN: usize

The alignment of pointer.
Source§

type Init = T

The type for initializers.
Source§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
Source§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
Source§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
Source§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Pointee for T

Source§

type Metadata = ()

The metadata type for pointers and references to this type.
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more