pub struct SecurityContextBuilder { /* private fields */ }Expand description
Builds a SecurityContext field by field.
subject_id and subject_tenant_id are required; Self::build reports a
missing one rather than defaulting it, since a nil subject is how an
anonymous context is represented and silently producing one would turn a
wiring mistake into an unauthenticated caller. Use
SecurityContext::anonymous when that is what you actually mean.
Debug never renders the bearer token: the field holds a SecretString,
which redacts itself.
Implementations§
Source§impl SecurityContextBuilder
impl SecurityContextBuilder
Sourcepub fn subject_id(self, subject_id: Uuid) -> Self
pub fn subject_id(self, subject_id: Uuid) -> Self
Set the subject’s unique id. Required.
Sourcepub fn subject_type(self, subject_type: &str) -> Self
pub fn subject_type(self, subject_type: &str) -> Self
Set the subject’s classification, e.g. "user" or "service".
Optional to build, but it is the positive marker a real AuthN resolver
always populates, so consumers use its absence to spot a context that
never went through authentication.
Sourcepub fn subject_tenant_id(self, subject_tenant_id: Uuid) -> Self
pub fn subject_tenant_id(self, subject_tenant_id: Uuid) -> Self
Set the subject’s home tenant. Required.
Sourcepub fn token_scopes(self, scopes: Vec<String>) -> Self
pub fn token_scopes(self, scopes: Vec<String>) -> Self
Set the token’s capability scopes.
["*"] is first-party / unrestricted. See the field documentation on
SecurityContext for what an empty list means.
Sourcepub fn bearer_token(self, token: impl Into<SecretString>) -> Self
pub fn bearer_token(self, token: impl Into<SecretString>) -> Self
Carry the original bearer token, for forwarding to a policy decision
point. Never serialized and never rendered by Debug.
Sourcepub fn build(self) -> Result<SecurityContext, SecurityContextBuildError>
pub fn build(self) -> Result<SecurityContext, SecurityContextBuildError>
Build the SecurityContext.
§Errors
Returns SecurityContextBuildError if subject_id or
subject_tenant_id was not set. Use SecurityContext::anonymous()
for contexts that intentionally have no authenticated subject.