Skip to main content

Module auth

Module auth 

Source
Expand description

Who is calling the API: an API key in Authorization: Bearer <key>, and nothing else. The session cookie never authenticates the API (so no request can ride on a browser login), and a key that is malformed or revoked is refused, never treated as “no key”.

Structs§

ApiCaller
A caller holding a live API key: the key’s account (as loaded for this request) and the key.

Functions§

authenticate
The caller of a request that must carry a key.
bearer_key
The key in the Authorization header: Ok(None) when the header is absent, an error when it is there but isn’t a well-formed Bearer key.
resolve_key
The caller behind a well-formed key: unknown and revoked keys are refused.