pub struct ServiceAccountAuthenticator { /* private fields */ }Expand description
Authenticates service-account secrets presented on the api-key header.
Implementations§
Source§impl ServiceAccountAuthenticator
impl ServiceAccountAuthenticator
Sourcepub fn from_config(
accounts: &HashMap<String, ServiceAccountConfig>,
resolve_secret: impl Fn(&str) -> Option<String>,
) -> Option<Arc<Self>>
pub fn from_config( accounts: &HashMap<String, ServiceAccountConfig>, resolve_secret: impl Fn(&str) -> Option<String>, ) -> Option<Arc<Self>>
Build an authenticator from the [service_accounts] config, resolving each
account’s secret via resolve_secret (production: |env| std::env::var(env).ok()).
An account whose secret_env is unset/empty is skipped with a warning — it is
simply unusable (fail-closed), never a silent anonymous grant. Returns None when
no account resolves.
Sourcepub fn resolve(&self, headers: &HeaderMap, jwt_present: bool) -> SaAuth
pub fn resolve(&self, headers: &HeaderMap, jwt_present: bool) -> SaAuth
Resolve a service-account principal from headers, honoring the JWT-collision
rule (ADR-0018 amendment / rider 2). jwt_present is whether the request already
carries a JWT-derived principal. The same logic backs every entry point (GraphQL,
/ws, REST) so they cannot drift.
Sourcepub fn header_present(&self, headers: &HeaderMap) -> bool
pub fn header_present(&self, headers: &HeaderMap) -> bool
Whether the request carries a (non-empty) service-account secret header. Used by callers to reject a request that also carries a JWT (ambiguous identity).
Sourcepub fn authenticate(&self, headers: &HeaderMap) -> Option<Box<SecurityContext>>
pub fn authenticate(&self, headers: &HeaderMap) -> Option<Box<SecurityContext>>
Authenticate a request. Returns the service account’s SecurityContext on an
exact constant-time secret match, or None when the header is absent or
present-but-unmatched (the caller cannot distinguish the two — no oracle).
Trait Implementations§
Auto Trait Implementations§
impl !Freeze for ServiceAccountAuthenticator
impl RefUnwindSafe for ServiceAccountAuthenticator
impl Send for ServiceAccountAuthenticator
impl Sync for ServiceAccountAuthenticator
impl Unpin for ServiceAccountAuthenticator
impl UnsafeUnpin for ServiceAccountAuthenticator
impl UnwindSafe for ServiceAccountAuthenticator
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more