pub struct Gate { /* private fields */ }Implementations§
Source§impl Gate
impl Gate
pub fn new( store: Arc<AuthStore>, tailnet: Option<Tailnet>, access: Option<(Arc<AccessValidator>, AccessAllowList, Vec<String>)>, ) -> Gate
Sourcepub fn with_dev(self, email: Option<String>) -> Gate
pub fn with_dev(self, email: Option<String>) -> Gate
Sign every loopback request with no credential in as a superadmin
acting as email (crate::auth::dev).
Sourcepub fn with_agents(
self,
tailnet_listens: Vec<String>,
access: Option<(Arc<AccessValidator>, Vec<String>)>,
) -> Gate
pub fn with_agents( self, tailnet_listens: Vec<String>, access: Option<(Arc<AccessValidator>, Vec<String>)>, ) -> Gate
Let orgs’ tailnet and Access agent identities in
(crate::auth::agent_identities): the tailnet --listen
addresses, and Access’s validator with the Host names to allow.
Sourcepub fn agent_ways(&self) -> AgentWays
pub fn agent_ways(&self) -> AgentWays
Which agent identities can reach this server at all.
Sourcepub fn agent(&self, req: &Request, id: Option<&Identity>) -> Option<Principal>
pub fn agent(&self, req: &Request, id: Option<&Identity>) -> Option<Principal>
The agent identity behind req, if an org maps it: a verified
Access identity (id, else the request’s own assertion) on a
loopback listener Access guards, or a tailnet peer, as tailscaled
says. A bearer token decides on its own, so it is not asked here.
Superadmin sources are judged first, by Gate::resolve.
Sourcepub fn edge(&self, req: &Request, id: Option<&Identity>) -> Option<EdgeIdentity>
pub fn edge(&self, req: &Request, id: Option<&Identity>) -> Option<EdgeIdentity>
The person a front door verified (crate::auth::edge): a verified
Access user on a loopback listener Access guards, or an untagged
tailnet peer. Service tokens and tagged nodes are not people. They
may claim setup unless this front door’s superadmin allow list
exists and leaves them out.
Sourcepub fn agent_fn(self: &Arc<Self>) -> AgentFn
pub fn agent_fn(self: &Arc<Self>) -> AgentFn
Gate::agent and Gate::edge as the identity endpoints ask them.
pub fn edge_fn(self: &Arc<Self>) -> EdgeFn
pub fn tailnet(&self) -> Option<&Tailnet>
Sourcepub fn access_list(&self) -> Option<&AccessAllowList>
pub fn access_list(&self) -> Option<&AccessAllowList>
--superadmin-access, when given.