pub enum Caller {
Local {
uid: Option<u32>,
},
Access(Identity),
Unauthenticated {
addr: SocketAddr,
},
User {
principal: Arc<Principal>,
},
Superadmin(Arc<Superadmin>),
}Expand description
Who made a call. Handlers use it for audit logs and to hold remote callers to a stricter policy than the local CLI.
Variants§
Local
Over the unix socket, where filesystem permissions are the gate.
Access(Identity)
Through Cloudflare Access, with a verified assertion.
Unauthenticated
Loopback TCP with Access validation explicitly turned off. Anyone who can reach the port.
Fields
addr: SocketAddrUser
A signed-in isb user: an API token, a session, or an Access identity that maps to a user.
Superadmin(Arc<Superadmin>)
The unix socket’s reach over HTTP: a superadmin token, or a tailnet
identity on the superadmin allow list (crate::auth::superadmin).
Implementations§
Source§impl Caller
impl Caller
Sourcepub fn downscope(&self) -> Option<&OrgId>
pub fn downscope(&self) -> Option<&OrgId>
The org an org-bound endpoint scoped this caller down to, if it did.
Sourcepub fn downscoped_to(self, org: &OrgId) -> Caller
pub fn downscoped_to(self, org: &OrgId) -> Caller
This caller on an org-bound endpoint (/orgs/<org>/...): a
superadmin over HTTP or a platform admin acts as an admin of org
only (crate::auth::Principal::downscoped_to). The unix socket and
everyone else are unchanged.
Source§impl Caller
impl Caller
Sourcepub fn is_trusted(&self) -> bool
pub fn is_trusted(&self) -> bool
A superadmin: the unix socket, or an HTTP caller with the socket’s reach. Every tool, no remote-spec policy, any instance.
pub fn superadmin(&self) -> Option<&Superadmin>
Sourcepub fn superadmin_source(&self) -> Option<String>
pub fn superadmin_source(&self) -> Option<String>
Where a superadmin’s power comes from: socket, token:<name>,
tailnet:<login>; None for everyone else.
pub fn identity(&self) -> Option<&Identity>
Trait Implementations§
impl Eq for Caller
impl StructuralPartialEq for Caller
Auto Trait Implementations§
impl Freeze for Caller
impl RefUnwindSafe for Caller
impl Send for Caller
impl Sync for Caller
impl Unpin for Caller
impl UnsafeUnpin for Caller
impl UnwindSafe for Caller
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.