pub struct Principal {
pub user: User,
pub kind: PrincipalKind,
pub orgs: Vec<(OrgId, Role)>,
pub platform_admin: bool,
pub downscoped: Option<OrgId>,
}Expand description
An authenticated caller: who, how, and what they may reach. For an
org-scoped token, orgs is that one org and platform_admin is false
whatever the user is.
Fields§
§user: User§kind: PrincipalKind§orgs: Vec<(OrgId, Role)>§platform_admin: bool§downscoped: Option<OrgId>Set on an org-bound endpoint for a superadmin or platform admin: an admin of this org only.
Implementations§
Source§impl Principal
impl Principal
Sourcepub fn restricted(&self) -> bool
pub fn restricted(&self) -> bool
A token scoped short of admin: it may not change who has access.
Sourcepub fn downscoped_to(&self, org: &OrgId) -> Principal
pub fn downscoped_to(&self, org: &OrgId) -> Principal
This principal as an org-bound endpoint sees it. A superadmin or a
platform admin becomes an admin of org only (an owner stays one):
not a platform admin, no other org. Everyone else is unchanged.
Sourcepub fn workspace(org: &OrgId, name: &str, role: Role) -> Principal
pub fn workspace(org: &OrgId, name: &str, role: Role) -> Principal
The principal an org’s workspace token authenticates: no account
(user id 0, named workspace), confined to org with role.
Sourcepub fn is_workspace(&self) -> bool
pub fn is_workspace(&self) -> bool
An org’s workspace, rather than a person or a user’s token.
Source§impl Principal
impl Principal
pub fn is_platform_admin(&self) -> bool
pub fn role_in(&self, org: &OrgId) -> Option<Role>
Sourcepub fn can_admin_org(&self, org: &OrgId) -> bool
pub fn can_admin_org(&self, org: &OrgId) -> bool
Apps, stacks, sandboxes and secrets in org.
Sourcepub fn can_read_org(&self, org: &OrgId) -> bool
pub fn can_read_org(&self, org: &OrgId) -> bool
Read-only tools in org.
Sourcepub fn can_manage_members(&self, org: &OrgId) -> bool
pub fn can_manage_members(&self, org: &OrgId) -> bool
Members, invitations and every token in org.
pub fn can_delete_org(&self, org: &OrgId) -> bool
Sourcepub fn max_grant(&self, org: &OrgId) -> Option<Role>
pub fn max_grant(&self, org: &OrgId) -> Option<Role>
The highest role this principal may hand out in org.
pub fn session_id(&self) -> Option<i64>
Trait Implementations§
impl Eq for Principal
impl StructuralPartialEq for Principal
Auto Trait Implementations§
impl Freeze for Principal
impl RefUnwindSafe for Principal
impl Send for Principal
impl Sync for Principal
impl Unpin for Principal
impl UnsafeUnpin for Principal
impl UnwindSafe for Principal
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.