pub struct AuthStore { /* private fields */ }Expand description
The identity store. Cheap to share behind an Arc; one connection behind
a mutex (requests are short, and argon2 runs outside the lock).
Implementations§
Source§impl AuthStore
impl AuthStore
Sourcepub fn list_agent_identities(
&self,
org: &OrgId,
) -> AuthResult<Vec<AgentIdentity>>
pub fn list_agent_identities( &self, org: &OrgId, ) -> AuthResult<Vec<AgentIdentity>>
An org’s mappings, oldest first.
Sourcepub fn set_agent_identity(
&self,
org: &OrgId,
kind: AgentKind,
subject: &str,
role: Role,
note: &str,
created_by: &str,
) -> AuthResult<AgentIdentity>
pub fn set_agent_identity( &self, org: &OrgId, kind: AgentKind, subject: &str, role: Role, note: &str, created_by: &str, ) -> AuthResult<AgentIdentity>
Map subject to role in org, or change the role of an existing
mapping. Never owner; an Access email that is an isb user’s is
refused (it acts as that user: make them a member).
Sourcepub fn remove_agent_identity(&self, org: &OrgId, id: i64) -> AuthResult<bool>
pub fn remove_agent_identity(&self, org: &OrgId, id: i64) -> AuthResult<bool>
Remove one of org’s mappings. True if it existed.
Sourcepub fn agent_orgs(
&self,
kind: AgentKind,
subjects: &[String],
) -> AuthResult<Vec<(OrgId, Role)>>
pub fn agent_orgs( &self, kind: AgentKind, subjects: &[String], ) -> AuthResult<Vec<(OrgId, Role)>>
The orgs that map any of subjects (already normalized) for kind,
with the highest role each gives.
Sourcepub fn principal_for_tailnet(
&self,
login: &str,
node: &str,
tags: &[String],
) -> AuthResult<Option<Principal>>
pub fn principal_for_tailnet( &self, login: &str, node: &str, tags: &[String], ) -> AuthResult<Option<Principal>>
The principal of a tailnet node: a tagged node by its tags only, any
other by its user’s login. None when no org maps it.
Sourcepub fn principal_for_access_agent(
&self,
email: Option<&str>,
client_id: Option<&str>,
) -> AuthResult<Option<Principal>>
pub fn principal_for_access_agent( &self, email: Option<&str>, client_id: Option<&str>, ) -> AuthResult<Option<Principal>>
The principal of a verified Access identity that is not an isb user:
a person’s email, else a service token’s client id. None when no
org maps it, and for an email that is an isb user’s (such a caller
acts as that user, AuthStore::principal_for_email).
Source§impl AuthStore
impl AuthStore
Sourcepub fn external_sign_in(
&self,
ext: &ExternalIdentity,
invite: Option<&str>,
open_signup: bool,
) -> AuthResult<(User, SignIn)>
pub fn external_sign_in( &self, ext: &ExternalIdentity, invite: Option<&str>, open_signup: bool, ) -> AuthResult<(User, SignIn)>
Sign in with a provider’s identity, by the rules in the module docs.
invite is an invitation token carried through the flow.
Sourcepub fn link_identity(
&self,
user_id: i64,
ext: &ExternalIdentity,
) -> AuthResult<Identity>
pub fn link_identity( &self, user_id: i64, ext: &ExternalIdentity, ) -> AuthResult<Identity>
Link an identity to a signed-in user. Refused when it already belongs to someone else.
pub fn list_identities(&self, user_id: i64) -> AuthResult<Vec<Identity>>
Sourcepub fn unlink_identity(&self, user_id: i64, id: i64) -> AuthResult<bool>
pub fn unlink_identity(&self, user_id: i64, id: i64) -> AuthResult<bool>
Remove one of a user’s identities, unless it is their last way in. False when there was no such identity.
Sourcepub fn passkey_user_handle(&self, user_id: i64) -> AuthResult<Option<Vec<u8>>>
pub fn passkey_user_handle(&self, user_id: i64) -> AuthResult<Option<Vec<u8>>>
The WebAuthn user handle of user_id’s passkeys, if they have any.
Sourcepub fn add_passkey(
&self,
user_id: i64,
user_handle: &[u8],
reg: &Registration,
name: &str,
transports: &[String],
) -> AuthResult<Passkey>
pub fn add_passkey( &self, user_id: i64, user_handle: &[u8], reg: &Registration, name: &str, transports: &[String], ) -> AuthResult<Passkey>
Store a verified registration.
pub fn passkey_by_credential( &self, credential_id: &[u8], ) -> AuthResult<Option<StoredPasskey>>
pub fn list_passkeys(&self, user_id: i64) -> AuthResult<Vec<Passkey>>
Sourcepub fn use_passkey(
&self,
id: i64,
old_count: u32,
new_count: u32,
) -> AuthResult<()>
pub fn use_passkey( &self, id: i64, old_count: u32, new_count: u32, ) -> AuthResult<()>
Record a sign-in with a passkey: the new counter, if nobody else moved it meanwhile (two racing assertions cannot both pass).
Sourcepub fn delete_passkey(&self, user_id: i64, id: i64) -> AuthResult<bool>
pub fn delete_passkey(&self, user_id: i64, id: i64) -> AuthResult<bool>
Remove one of a user’s passkeys, unless it is their last way in.
Source§impl AuthStore
impl AuthStore
Sourcepub fn principal_from_request(&self, req: &Request) -> Option<Principal>
pub fn principal_from_request(&self, req: &Request) -> Option<Principal>
The caller behind an HTTP request: Authorization: Bearer isb_tok_...
(an API token) when that header is present, else the isb_session
cookie. A bad Authorization never falls back to the cookie.
Source§impl AuthStore
impl AuthStore
Sourcepub fn setup_needed(&self) -> AuthResult<bool>
pub fn setup_needed(&self) -> AuthResult<bool>
True until the first user exists.
Sourcepub fn create_first_admin(
&self,
email: &str,
name: &str,
password: &str,
) -> AuthResult<User>
pub fn create_first_admin( &self, email: &str, name: &str, password: &str, ) -> AuthResult<User>
Create the first user: a platform admin and owner of the default
org. Refused once any user exists.
Sourcepub fn claim_first_admin(
&self,
email: &str,
name: &str,
password: Option<&str>,
link: &ExternalIdentity,
) -> AuthResult<User>
pub fn claim_first_admin( &self, email: &str, name: &str, password: Option<&str>, link: &ExternalIdentity, ) -> AuthResult<User>
The first admin from an edge identity (super::edge), linked to it so it
signs them in from then on. The password is optional: the edge is a
way in, and isb user passwd on the host is the way back.
Source§impl AuthStore
impl AuthStore
Sourcepub fn add_ssh_key(
&self,
user_id: i64,
key: &str,
name: Option<&str>,
) -> AuthResult<SshKey>
pub fn add_ssh_key( &self, user_id: i64, key: &str, name: Option<&str>, ) -> AuthResult<SshKey>
Add a public key to user_id’s account. name defaults to the key’s
comment.
pub fn list_ssh_keys(&self, user_id: i64) -> AuthResult<Vec<SshKey>>
pub fn ssh_key(&self, user_id: i64, id: i64) -> AuthResult<Option<SshKey>>
Sourcepub fn delete_ssh_key(&self, user_id: i64, id: i64) -> AuthResult<bool>
pub fn delete_ssh_key(&self, user_id: i64, id: i64) -> AuthResult<bool>
Remove one of user_id’s keys; false if they have no such key.
Sourcepub fn has_ssh_key(&self, user_id: i64, fingerprint: &str) -> AuthResult<bool>
pub fn has_ssh_key(&self, user_id: i64, fingerprint: &str) -> AuthResult<bool>
Is fingerprint still one of user_id’s keys? Asked during a live
session, so removing a key ends the sessions it opened.
Sourcepub fn touch_ssh_key(&self, user_id: i64, fingerprint: &str) -> AuthResult<()>
pub fn touch_ssh_key(&self, user_id: i64, fingerprint: &str) -> AuthResult<()>
Note that a key just opened a session.
Source§impl AuthStore
impl AuthStore
Sourcepub fn create_superadmin_token(
&self,
name: &str,
expires: Option<Duration>,
) -> AuthResult<NewSuperadminToken>
pub fn create_superadmin_token( &self, name: &str, expires: Option<Duration>, ) -> AuthResult<NewSuperadminToken>
Mint a superadmin token. Only the host CLI calls this (it opens
isb.db as the daemon’s own user); no HTTP endpoint or tool does.
Sourcepub fn authenticate_superadmin_token(
&self,
token: &str,
) -> AuthResult<Option<SuperadminToken>>
pub fn authenticate_superadmin_token( &self, token: &str, ) -> AuthResult<Option<SuperadminToken>>
The token behind isb_sa_..., if it is valid and unexpired.
pub fn list_superadmin_tokens(&self) -> AuthResult<Vec<SuperadminToken>>
pub fn superadmin_token(&self, id: i64) -> AuthResult<SuperadminToken>
Sourcepub fn revoke_superadmin_token(&self, id: i64) -> AuthResult<bool>
pub fn revoke_superadmin_token(&self, id: i64) -> AuthResult<bool>
Delete one. True if it existed.
Source§impl AuthStore
impl AuthStore
Sourcepub fn open(path: impl AsRef<Path>) -> AuthResult<AuthStore>
pub fn open(path: impl AsRef<Path>) -> AuthResult<AuthStore>
Open (creating and migrating) the database at path, default config.
pub fn open_with( path: impl AsRef<Path>, cfg: AuthConfig, ) -> AuthResult<AuthStore>
Sourcepub fn in_memory(cfg: AuthConfig) -> AuthResult<AuthStore>
pub fn in_memory(cfg: AuthConfig) -> AuthResult<AuthStore>
A throwaway in-memory store (tests, previews).
Sourcepub fn with_clock(self, clock: Clock) -> Self
pub fn with_clock(self, clock: Clock) -> Self
Replace the clock (unix seconds), for tests of expiry.
pub fn config(&self) -> &AuthConfig
pub fn path(&self) -> Option<&Path>
pub fn now(&self) -> i64
Sourcepub fn limit_ip(&self, ip: Option<&str>) -> AuthResult<()>
pub fn limit_ip(&self, ip: Option<&str>) -> AuthResult<()>
Count one unauthenticated attempt from ip (login, setup, invitation
acceptance, password resets).
Sourcepub fn create_user(
&self,
email: &str,
name: &str,
password: Option<&str>,
platform_admin: bool,
) -> AuthResult<User>
pub fn create_user( &self, email: &str, name: &str, password: Option<&str>, platform_admin: bool, ) -> AuthResult<User>
Create a user. password may be None for an account that will sign
in through an external identity or reset its password.
pub fn user(&self, id: i64) -> AuthResult<User>
pub fn user_by_email(&self, email: &str) -> AuthResult<Option<User>>
pub fn list_users(&self) -> AuthResult<Vec<User>>
Sourcepub fn set_disabled(&self, user_id: i64, disabled: bool) -> AuthResult<()>
pub fn set_disabled(&self, user_id: i64, disabled: bool) -> AuthResult<()>
Disable (or re-enable) a user. Disabling ends their sessions; their tokens stop working while disabled.
Sourcepub fn last_active(&self, user_id: i64) -> AuthResult<Option<i64>>
pub fn last_active(&self, user_id: i64) -> AuthResult<Option<i64>>
When a user last did anything: the latest of their sessions’ last use
and their tokens’ last use (None: never, or nothing left to tell).
Sourcepub fn other_platform_admins(&self, except: i64) -> AuthResult<i64>
pub fn other_platform_admins(&self, except: i64) -> AuthResult<i64>
Enabled platform admins other than except.
pub fn set_platform_admin(&self, user_id: i64, admin: bool) -> AuthResult<()>
Sourcepub fn set_password(&self, user_id: i64, password: &str) -> AuthResult<()>
pub fn set_password(&self, user_id: i64, password: &str) -> AuthResult<()>
Set a password without the old one (the local CLI, an admin). Ends every session of the user.
Sourcepub fn change_password(
&self,
user_id: i64,
current: &str,
new: &str,
keep: Option<i64>,
) -> AuthResult<()>
pub fn change_password( &self, user_id: i64, current: &str, new: &str, keep: Option<i64>, ) -> AuthResult<()>
Change a password, proving the current one. Ends every other session
(keep is the caller’s own).
Sourcepub fn login(
&self,
email: &str,
password: &str,
meta: LoginMeta,
) -> AuthResult<NewSession>
pub fn login( &self, email: &str, password: &str, meta: LoginMeta, ) -> AuthResult<NewSession>
Check an email and password and start a session. Every failure (no
such user, wrong password, disabled, no password set) is
AuthError::InvalidCredentials and costs one argon2 verification.
Sourcepub fn start_session(
&self,
user_id: i64,
meta: LoginMeta,
) -> AuthResult<NewSession>
pub fn start_session( &self, user_id: i64, meta: LoginMeta, ) -> AuthResult<NewSession>
Start a session for a user already proven by other means (an accepted invitation, a password reset, an external identity).
Sourcepub fn session(&self, token: &str) -> AuthResult<Option<(User, Session)>>
pub fn session(&self, token: &str) -> AuthResult<Option<(User, Session)>>
The live session for token, sliding its idle expiry. An expired one
is deleted; a disabled user has none.
Sourcepub fn principal_for_email(&self, email: &str) -> AuthResult<Option<Principal>>
pub fn principal_for_email(&self, email: &str) -> AuthResult<Option<Principal>>
The principal for a Cloudflare Access identity: the enabled user with that email, with all their memberships.
Sourcepub fn authenticate_session(&self, token: &str) -> AuthResult<Option<Principal>>
pub fn authenticate_session(&self, token: &str) -> AuthResult<Option<Principal>>
The principal behind a session token.
Sourcepub fn logout(&self, token: &str) -> AuthResult<bool>
pub fn logout(&self, token: &str) -> AuthResult<bool>
End the session holding token. True if there was one.
Sourcepub fn list_sessions(&self, user_id: i64) -> AuthResult<Vec<Session>>
pub fn list_sessions(&self, user_id: i64) -> AuthResult<Vec<Session>>
A user’s live sessions, newest first.
Sourcepub fn revoke_session(&self, user_id: i64, session_id: i64) -> AuthResult<bool>
pub fn revoke_session(&self, user_id: i64, session_id: i64) -> AuthResult<bool>
End one of a user’s sessions. True if it existed.
Sourcepub fn revoke_sessions(
&self,
user_id: i64,
keep: Option<i64>,
) -> AuthResult<usize>
pub fn revoke_sessions( &self, user_id: i64, keep: Option<i64>, ) -> AuthResult<usize>
End all of a user’s sessions but keep. Returns how many ended.
Sourcepub fn prune(&self) -> AuthResult<()>
pub fn prune(&self) -> AuthResult<()>
Delete expired sessions, invitations and resets.
Sourcepub fn ensure_org(&self, org: &OrgId) -> AuthResult<()>
pub fn ensure_org(&self, org: &OrgId) -> AuthResult<()>
Record an org (idempotent). The org’s runtime is not this module’s; this row anchors memberships, invitations and tokens.
Sourcepub fn delete_org(&self, org: &OrgId) -> AuthResult<bool>
pub fn delete_org(&self, org: &OrgId) -> AuthResult<bool>
Forget an org: its memberships, invitations and tokens go with it.
pub fn list_orgs(&self) -> AuthResult<Vec<OrgId>>
pub fn memberships(&self, user_id: i64) -> AuthResult<Vec<Membership>>
pub fn list_members(&self, org: &OrgId) -> AuthResult<Vec<(User, Role)>>
Sourcepub fn set_member(
&self,
org: &OrgId,
user_id: i64,
role: Role,
) -> AuthResult<()>
pub fn set_member( &self, org: &OrgId, user_id: i64, role: Role, ) -> AuthResult<()>
Add user to org with role, or change their role. Refuses to
demote the org’s last owner.
Sourcepub fn remove_member(&self, org: &OrgId, user_id: i64) -> AuthResult<bool>
pub fn remove_member(&self, org: &OrgId, user_id: i64) -> AuthResult<bool>
Remove user from org, and their tokens confined to it. Refuses to
remove the last owner. True if they were a member.
Sourcepub fn create_invitation(
&self,
invited_by: Option<i64>,
org: &OrgId,
email: &str,
role: Role,
) -> AuthResult<NewInvitation>
pub fn create_invitation( &self, invited_by: Option<i64>, org: &OrgId, email: &str, role: Role, ) -> AuthResult<NewInvitation>
Invite email to org as role. Replaces any pending invitation for
the same address and org. Authorization is the caller’s
(Principal::max_grant); invited_by is None for the local CLI.
Sourcepub fn list_invitations(&self, org: &OrgId) -> AuthResult<Vec<Invitation>>
pub fn list_invitations(&self, org: &OrgId) -> AuthResult<Vec<Invitation>>
Pending (unaccepted, unexpired) invitations to org.
Sourcepub fn revoke_invitation(&self, org: &OrgId, id: i64) -> AuthResult<bool>
pub fn revoke_invitation(&self, org: &OrgId, id: i64) -> AuthResult<bool>
Withdraw a pending invitation. True if there was one.
Sourcepub fn invitation(&self, token: &str) -> AuthResult<Option<Invitation>>
pub fn invitation(&self, token: &str) -> AuthResult<Option<Invitation>>
The pending invitation for token, if it is valid.
Sourcepub fn accept_invitation(
&self,
token: &str,
name: &str,
password: &str,
) -> AuthResult<Accepted>
pub fn accept_invitation( &self, token: &str, name: &str, password: &str, ) -> AuthResult<Accepted>
Accept an invitation without a session. A new address gets an account
with name and password; an existing account must prove password
(the invitation alone does not let anyone in as someone else).
Sourcepub fn accept_invitation_as(
&self,
token: &str,
user_id: i64,
) -> AuthResult<Accepted>
pub fn accept_invitation_as( &self, token: &str, user_id: i64, ) -> AuthResult<Accepted>
Accept an invitation as the signed-in user, whose email must match.
Sourcepub fn create_api_token(
&self,
user_id: i64,
org: Option<&OrgId>,
name: &str,
expires: Option<Duration>,
) -> AuthResult<NewApiToken>
pub fn create_api_token( &self, user_id: i64, org: Option<&OrgId>, name: &str, expires: Option<Duration>, ) -> AuthResult<NewApiToken>
Make an API token for user_id. Confined to org when given (the
user must belong to it, or be a platform admin); a platform token
(org: None) is for platform admins only. expires: None never expires.
Sourcepub fn create_api_token_scoped(
&self,
user_id: i64,
org: Option<&OrgId>,
name: &str,
expires: Option<Duration>,
scopes: &[String],
) -> AuthResult<NewApiToken>
pub fn create_api_token_scoped( &self, user_id: i64, org: Option<&OrgId>, name: &str, expires: Option<Duration>, scopes: &[String], ) -> AuthResult<NewApiToken>
Self::create_api_token, narrowed to scopes (Scope).
Sourcepub fn authenticate_token(&self, token: &str) -> AuthResult<Option<Principal>>
pub fn authenticate_token(&self, token: &str) -> AuthResult<Option<Principal>>
The principal behind an API token. Expired tokens, disabled users, and org tokens whose user has left the org authenticate nobody.
pub fn api_token(&self, id: i64) -> AuthResult<ApiToken>
Sourcepub fn list_api_tokens(&self, user_id: i64) -> AuthResult<Vec<ApiToken>>
pub fn list_api_tokens(&self, user_id: i64) -> AuthResult<Vec<ApiToken>>
A user’s tokens.
Sourcepub fn list_org_api_tokens(&self, org: &OrgId) -> AuthResult<Vec<ApiToken>>
pub fn list_org_api_tokens(&self, org: &OrgId) -> AuthResult<Vec<ApiToken>>
Every token confined to org, whoever made it.
Sourcepub fn list_all_api_tokens(&self) -> AuthResult<Vec<ApiToken>>
pub fn list_all_api_tokens(&self) -> AuthResult<Vec<ApiToken>>
Every token (the local CLI).
Sourcepub fn revoke_api_token(&self, id: i64) -> AuthResult<bool>
pub fn revoke_api_token(&self, id: i64) -> AuthResult<bool>
Delete a token. True if it existed. Authorization is the caller’s.
Sourcepub fn request_password_reset(&self, email: &str) -> AuthResult<Option<String>>
pub fn request_password_reset(&self, email: &str) -> AuthResult<Option<String>>
A one-hour reset token for email, or None when there is no such
(enabled) user. The caller delivers it, and must answer the same way
either way so the endpoint does not reveal who has an account.
Sourcepub fn reset_password(&self, token: &str, password: &str) -> AuthResult<User>
pub fn reset_password(&self, token: &str, password: &str) -> AuthResult<User>
Set a new password with a reset token. Single use; ends every session.