Skip to main content

AuthStore

Struct AuthStore 

Source
pub struct AuthStore { /* private fields */ }
Expand description

The identity store. Cheap to share behind an Arc; one connection behind a mutex (requests are short, and argon2 runs outside the lock).

Implementations§

Source§

impl AuthStore

Source

pub fn list_agent_identities( &self, org: &OrgId, ) -> AuthResult<Vec<AgentIdentity>>

An org’s mappings, oldest first.

Source

pub fn set_agent_identity( &self, org: &OrgId, kind: AgentKind, subject: &str, role: Role, note: &str, created_by: &str, ) -> AuthResult<AgentIdentity>

Map subject to role in org, or change the role of an existing mapping. Never owner; an Access email that is an isb user’s is refused (it acts as that user: make them a member).

Source

pub fn remove_agent_identity(&self, org: &OrgId, id: i64) -> AuthResult<bool>

Remove one of org’s mappings. True if it existed.

Source

pub fn agent_orgs( &self, kind: AgentKind, subjects: &[String], ) -> AuthResult<Vec<(OrgId, Role)>>

The orgs that map any of subjects (already normalized) for kind, with the highest role each gives.

Source

pub fn principal_for_tailnet( &self, login: &str, node: &str, tags: &[String], ) -> AuthResult<Option<Principal>>

The principal of a tailnet node: a tagged node by its tags only, any other by its user’s login. None when no org maps it.

Source

pub fn principal_for_access_agent( &self, email: Option<&str>, client_id: Option<&str>, ) -> AuthResult<Option<Principal>>

The principal of a verified Access identity that is not an isb user: a person’s email, else a service token’s client id. None when no org maps it, and for an email that is an isb user’s (such a caller acts as that user, AuthStore::principal_for_email).

Source§

impl AuthStore

Source

pub fn external_sign_in( &self, ext: &ExternalIdentity, invite: Option<&str>, open_signup: bool, ) -> AuthResult<(User, SignIn)>

Sign in with a provider’s identity, by the rules in the module docs. invite is an invitation token carried through the flow.

Link an identity to a signed-in user. Refused when it already belongs to someone else.

Source

pub fn list_identities(&self, user_id: i64) -> AuthResult<Vec<Identity>>

Remove one of a user’s identities, unless it is their last way in. False when there was no such identity.

Source

pub fn passkey_user_handle(&self, user_id: i64) -> AuthResult<Option<Vec<u8>>>

The WebAuthn user handle of user_id’s passkeys, if they have any.

Source

pub fn add_passkey( &self, user_id: i64, user_handle: &[u8], reg: &Registration, name: &str, transports: &[String], ) -> AuthResult<Passkey>

Store a verified registration.

Source

pub fn passkey_by_credential( &self, credential_id: &[u8], ) -> AuthResult<Option<StoredPasskey>>

Source

pub fn list_passkeys(&self, user_id: i64) -> AuthResult<Vec<Passkey>>

Source

pub fn use_passkey( &self, id: i64, old_count: u32, new_count: u32, ) -> AuthResult<()>

Record a sign-in with a passkey: the new counter, if nobody else moved it meanwhile (two racing assertions cannot both pass).

Source

pub fn delete_passkey(&self, user_id: i64, id: i64) -> AuthResult<bool>

Remove one of a user’s passkeys, unless it is their last way in.

Source§

impl AuthStore

Source

pub fn principal_from_request(&self, req: &Request) -> Option<Principal>

The caller behind an HTTP request: Authorization: Bearer isb_tok_... (an API token) when that header is present, else the isb_session cookie. A bad Authorization never falls back to the cookie.

Source§

impl AuthStore

Source

pub fn setup_needed(&self) -> AuthResult<bool>

True until the first user exists.

Source

pub fn create_first_admin( &self, email: &str, name: &str, password: &str, ) -> AuthResult<User>

Create the first user: a platform admin and owner of the default org. Refused once any user exists.

Source

pub fn claim_first_admin( &self, email: &str, name: &str, password: Option<&str>, link: &ExternalIdentity, ) -> AuthResult<User>

The first admin from an edge identity (super::edge), linked to it so it signs them in from then on. The password is optional: the edge is a way in, and isb user passwd on the host is the way back.

Source§

impl AuthStore

Source

pub fn add_ssh_key( &self, user_id: i64, key: &str, name: Option<&str>, ) -> AuthResult<SshKey>

Add a public key to user_id’s account. name defaults to the key’s comment.

Source

pub fn list_ssh_keys(&self, user_id: i64) -> AuthResult<Vec<SshKey>>

Source

pub fn ssh_key(&self, user_id: i64, id: i64) -> AuthResult<Option<SshKey>>

Source

pub fn delete_ssh_key(&self, user_id: i64, id: i64) -> AuthResult<bool>

Remove one of user_id’s keys; false if they have no such key.

Source

pub fn has_ssh_key(&self, user_id: i64, fingerprint: &str) -> AuthResult<bool>

Is fingerprint still one of user_id’s keys? Asked during a live session, so removing a key ends the sessions it opened.

Source

pub fn touch_ssh_key(&self, user_id: i64, fingerprint: &str) -> AuthResult<()>

Note that a key just opened a session.

Source§

impl AuthStore

Source

pub fn create_superadmin_token( &self, name: &str, expires: Option<Duration>, ) -> AuthResult<NewSuperadminToken>

Mint a superadmin token. Only the host CLI calls this (it opens isb.db as the daemon’s own user); no HTTP endpoint or tool does.

Source

pub fn authenticate_superadmin_token( &self, token: &str, ) -> AuthResult<Option<SuperadminToken>>

The token behind isb_sa_..., if it is valid and unexpired.

Source

pub fn list_superadmin_tokens(&self) -> AuthResult<Vec<SuperadminToken>>

Source

pub fn superadmin_token(&self, id: i64) -> AuthResult<SuperadminToken>

Source

pub fn revoke_superadmin_token(&self, id: i64) -> AuthResult<bool>

Delete one. True if it existed.

Source§

impl AuthStore

Source

pub fn open(path: impl AsRef<Path>) -> AuthResult<AuthStore>

Open (creating and migrating) the database at path, default config.

Source

pub fn open_with( path: impl AsRef<Path>, cfg: AuthConfig, ) -> AuthResult<AuthStore>

Source

pub fn in_memory(cfg: AuthConfig) -> AuthResult<AuthStore>

A throwaway in-memory store (tests, previews).

Source

pub fn with_clock(self, clock: Clock) -> Self

Replace the clock (unix seconds), for tests of expiry.

Source

pub fn config(&self) -> &AuthConfig

Source

pub fn path(&self) -> Option<&Path>

Source

pub fn now(&self) -> i64

Source

pub fn limit_ip(&self, ip: Option<&str>) -> AuthResult<()>

Count one unauthenticated attempt from ip (login, setup, invitation acceptance, password resets).

Source

pub fn create_user( &self, email: &str, name: &str, password: Option<&str>, platform_admin: bool, ) -> AuthResult<User>

Create a user. password may be None for an account that will sign in through an external identity or reset its password.

Source

pub fn user(&self, id: i64) -> AuthResult<User>

Source

pub fn user_by_email(&self, email: &str) -> AuthResult<Option<User>>

Source

pub fn list_users(&self) -> AuthResult<Vec<User>>

Source

pub fn set_disabled(&self, user_id: i64, disabled: bool) -> AuthResult<()>

Disable (or re-enable) a user. Disabling ends their sessions; their tokens stop working while disabled.

Source

pub fn last_active(&self, user_id: i64) -> AuthResult<Option<i64>>

When a user last did anything: the latest of their sessions’ last use and their tokens’ last use (None: never, or nothing left to tell).

Source

pub fn other_platform_admins(&self, except: i64) -> AuthResult<i64>

Enabled platform admins other than except.

Source

pub fn set_platform_admin(&self, user_id: i64, admin: bool) -> AuthResult<()>

Source

pub fn set_password(&self, user_id: i64, password: &str) -> AuthResult<()>

Set a password without the old one (the local CLI, an admin). Ends every session of the user.

Source

pub fn change_password( &self, user_id: i64, current: &str, new: &str, keep: Option<i64>, ) -> AuthResult<()>

Change a password, proving the current one. Ends every other session (keep is the caller’s own).

Source

pub fn login( &self, email: &str, password: &str, meta: LoginMeta, ) -> AuthResult<NewSession>

Check an email and password and start a session. Every failure (no such user, wrong password, disabled, no password set) is AuthError::InvalidCredentials and costs one argon2 verification.

Source

pub fn start_session( &self, user_id: i64, meta: LoginMeta, ) -> AuthResult<NewSession>

Start a session for a user already proven by other means (an accepted invitation, a password reset, an external identity).

Source

pub fn session(&self, token: &str) -> AuthResult<Option<(User, Session)>>

The live session for token, sliding its idle expiry. An expired one is deleted; a disabled user has none.

Source

pub fn principal_for_email(&self, email: &str) -> AuthResult<Option<Principal>>

The principal for a Cloudflare Access identity: the enabled user with that email, with all their memberships.

Source

pub fn authenticate_session(&self, token: &str) -> AuthResult<Option<Principal>>

The principal behind a session token.

Source

pub fn logout(&self, token: &str) -> AuthResult<bool>

End the session holding token. True if there was one.

Source

pub fn list_sessions(&self, user_id: i64) -> AuthResult<Vec<Session>>

A user’s live sessions, newest first.

Source

pub fn revoke_session(&self, user_id: i64, session_id: i64) -> AuthResult<bool>

End one of a user’s sessions. True if it existed.

Source

pub fn revoke_sessions( &self, user_id: i64, keep: Option<i64>, ) -> AuthResult<usize>

End all of a user’s sessions but keep. Returns how many ended.

Source

pub fn prune(&self) -> AuthResult<()>

Delete expired sessions, invitations and resets.

Source

pub fn ensure_org(&self, org: &OrgId) -> AuthResult<()>

Record an org (idempotent). The org’s runtime is not this module’s; this row anchors memberships, invitations and tokens.

Source

pub fn delete_org(&self, org: &OrgId) -> AuthResult<bool>

Forget an org: its memberships, invitations and tokens go with it.

Source

pub fn list_orgs(&self) -> AuthResult<Vec<OrgId>>

Source

pub fn memberships(&self, user_id: i64) -> AuthResult<Vec<Membership>>

Source

pub fn list_members(&self, org: &OrgId) -> AuthResult<Vec<(User, Role)>>

Source

pub fn set_member( &self, org: &OrgId, user_id: i64, role: Role, ) -> AuthResult<()>

Add user to org with role, or change their role. Refuses to demote the org’s last owner.

Source

pub fn remove_member(&self, org: &OrgId, user_id: i64) -> AuthResult<bool>

Remove user from org, and their tokens confined to it. Refuses to remove the last owner. True if they were a member.

Source

pub fn create_invitation( &self, invited_by: Option<i64>, org: &OrgId, email: &str, role: Role, ) -> AuthResult<NewInvitation>

Invite email to org as role. Replaces any pending invitation for the same address and org. Authorization is the caller’s (Principal::max_grant); invited_by is None for the local CLI.

Source

pub fn list_invitations(&self, org: &OrgId) -> AuthResult<Vec<Invitation>>

Pending (unaccepted, unexpired) invitations to org.

Source

pub fn revoke_invitation(&self, org: &OrgId, id: i64) -> AuthResult<bool>

Withdraw a pending invitation. True if there was one.

Source

pub fn invitation(&self, token: &str) -> AuthResult<Option<Invitation>>

The pending invitation for token, if it is valid.

Source

pub fn accept_invitation( &self, token: &str, name: &str, password: &str, ) -> AuthResult<Accepted>

Accept an invitation without a session. A new address gets an account with name and password; an existing account must prove password (the invitation alone does not let anyone in as someone else).

Source

pub fn accept_invitation_as( &self, token: &str, user_id: i64, ) -> AuthResult<Accepted>

Accept an invitation as the signed-in user, whose email must match.

Source

pub fn create_api_token( &self, user_id: i64, org: Option<&OrgId>, name: &str, expires: Option<Duration>, ) -> AuthResult<NewApiToken>

Make an API token for user_id. Confined to org when given (the user must belong to it, or be a platform admin); a platform token (org: None) is for platform admins only. expires: None never expires.

Source

pub fn create_api_token_scoped( &self, user_id: i64, org: Option<&OrgId>, name: &str, expires: Option<Duration>, scopes: &[String], ) -> AuthResult<NewApiToken>

Self::create_api_token, narrowed to scopes (Scope).

Source

pub fn authenticate_token(&self, token: &str) -> AuthResult<Option<Principal>>

The principal behind an API token. Expired tokens, disabled users, and org tokens whose user has left the org authenticate nobody.

Source

pub fn api_token(&self, id: i64) -> AuthResult<ApiToken>

Source

pub fn list_api_tokens(&self, user_id: i64) -> AuthResult<Vec<ApiToken>>

A user’s tokens.

Source

pub fn list_org_api_tokens(&self, org: &OrgId) -> AuthResult<Vec<ApiToken>>

Every token confined to org, whoever made it.

Source

pub fn list_all_api_tokens(&self) -> AuthResult<Vec<ApiToken>>

Every token (the local CLI).

Source

pub fn revoke_api_token(&self, id: i64) -> AuthResult<bool>

Delete a token. True if it existed. Authorization is the caller’s.

Source

pub fn request_password_reset(&self, email: &str) -> AuthResult<Option<String>>

A one-hour reset token for email, or None when there is no such (enabled) user. The caller delivers it, and must answer the same way either way so the endpoint does not reveal who has an account.

Source

pub fn reset_password(&self, token: &str, password: &str) -> AuthResult<User>

Set a new password with a reset token. Single use; ends every session.

Trait Implementations§

Source§

impl Debug for AuthStore

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V