1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
// Copyright The OpenTelemetry Authors
// SPDX-License-Identifier: Apache-2.0
//! The `BearerTokenAuthorizer` capability.
//!
//! The request-facing access-control capability for data-path nodes (typically
//! receivers) that authenticate callers with an OAuth/OIDC-style **bearer
//! token**. Given the token presented on an inbound request, it returns a
//! single allow/deny [`AuthzDecision`].
//!
//! A `BearerTokenAuthorizer` performs **authentication** (establishing who the
//! caller is from the token) and **admission** (deciding whether that token is
//! acceptable -- e.g. against a configured allow-list), behind one call, so a
//! receiver depends on this single capability rather than orchestrating the
//! steps itself. For example, a Kubernetes service-account-token authorizer
//! validates the token via the `TokenReview` API (authentication) and then
//! checks the returned service account against a configured allow-list
//! (admission) -- deriving both the trust source and the allowed identities from
//! its own configuration, so the caller supplies only the token.
//!
//! It admits on the token alone; it does not perform contextual, per-request
//! authorization (route, tenant, signal, or action scoping), which needs
//! request context it never receives and belongs downstream -- consuming the
//! [`AuthorizedIdentity`](super::AuthorizedIdentity) this capability emits.
//!
//! This capability is bearer-specific by design (the credential is always a
//! token string) and **transport- and library-agnostic**: the token is carried
//! by [`BearerToken`](super::BearerToken), a secret-protecting wrapper built
//! from plain `&str` (a bare token or a validated bearer `Authorization` header
//! value), never from any HTTP/RPC crate's request type. A receiver extracts it
//! from whatever transport it uses (gRPC, HTTP, ...).
//!
//! The `#[capability]` proc macro expands the trait into:
//!
//! - `pub(crate) mod local::BearerTokenAuthorizer` (`!Send` trait variant)
//! - `pub(crate) mod shared::BearerTokenAuthorizer` (`Send + Sync` trait variant)
//! - A `SharedAsLocalBearerTokenAuthorizer` adapter
//! - A zero-sized `pub struct BearerTokenAuthorizer` registration handle
//! - `local_entry::<E>` / `shared_entry::<E>` factory bridges
//! - A `KNOWN_CAPABILITIES` distributed-slice entry
use ;
use crateCapabilityError;
use capability;
/// Authenticates and admits an inbound bearer token against a configured
/// policy.