pub trait InternalAuthenticator: Send + Sync {
// Required method
fn authenticate(
&self,
token: &str,
) -> impl Future<Output = Result<PlatformIdentity, InternalAuthNError>> + Send;
}Expand description
Authenticates a raw platform-plane credential and resolves the caller’s
PlatformIdentity.
The transport layer (Axum middleware / tonic interceptor) stays generic over
this trait; the concrete validator (K8s TokenReview in the first phase) is
supplied at the gear/bootstrap layer so neither toolkit-http nor
toolkit-transport-grpc depend on kube.
The returned future is Send so the trait can be used from Axum/Tower
middleware on a multi-threaded runtime.
Required Methods§
Sourcefn authenticate(
&self,
token: &str,
) -> impl Future<Output = Result<PlatformIdentity, InternalAuthNError>> + Send
fn authenticate( &self, token: &str, ) -> impl Future<Output = Result<PlatformIdentity, InternalAuthNError>> + Send
Authenticate the raw X-ToolKit-Internal-Token value and resolve the
caller’s PlatformIdentity.
cancel-safe: this future is dropped mid-flight when a client
disconnects — it runs from middleware on an abortable task — and also
when a caller bounds it with tokio::time::timeout, as the caching
wrapper in this crate does. An implementation must hold no state across
the await that would be corrupted by never resuming: an abandoned call
must leave the authenticator exactly as it found it.
§Errors
Returns InternalAuthNError if the credential is invalid, the backend
is unavailable, or authentication otherwise fails.
Dyn Compatibility§
This trait is not dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety".