pub struct ServerState {Show 15 fields
pub config: ServerConfig,
pub storage: Arc<dyn Storage>,
pub cache: Arc<dyn DistributedCache>,
pub crypto: Arc<dyn CryptoProvider>,
pub token_service: Arc<dyn TokenService>,
pub token_manager: Arc<dyn TokenIssuer>,
pub plugin_registry: Arc<dyn PluginRegistry>,
pub federation_manager: Arc<dyn FederationManager>,
pub login_failure_tracker: Arc<LoginFailureTracker>,
pub email_sender: Arc<dyn EmailSender>,
pub broker_client: Arc<dyn BrokerClient>,
pub logout_notifier: Arc<dyn SessionLogoutNotifier>,
pub signing_key_reload: Arc<dyn Fn() + Send + Sync>,
pub keyset_generation: Arc<AtomicU64>,
pub event_listeners: HashMap<String, Arc<dyn EventListener>>,
}Fields§
§config: ServerConfig§storage: Arc<dyn Storage>§cache: Arc<dyn DistributedCache>§crypto: Arc<dyn CryptoProvider>§token_service: Arc<dyn TokenService>§token_manager: Arc<dyn TokenIssuer>§plugin_registry: Arc<dyn PluginRegistry>§federation_manager: Arc<dyn FederationManager>§login_failure_tracker: Arc<LoginFailureTracker>§email_sender: Arc<dyn EmailSender>§broker_client: Arc<dyn BrokerClient>Server-to-server client for identity brokering. A trait so
tests can stub the external IdP; production uses ReqwestBrokerClient.
logout_notifier: Arc<dyn SessionLogoutNotifier>Back-channel logout dispatcher: notifies clients with a
backchannel_logout_uri whenever one of their sessions is destroyed.
Fire-and-forget; NoOpSessionLogoutNotifier in tests that do not
exercise logout delivery.
signing_key_reload: Arc<dyn Fn() + Send + Sync>Same-node signing-key reload hook: invoked by the admin API after key rotation/disable so the running crypto provider and JWKS snapshot pick up the storage mutation immediately instead of waiting for the next JWKS polling tick. Spawns the reload onto the runtime; no-op in tests that do not wire the concrete provider.
keyset_generation: Arc<AtomicU64>Monotonic counter bumped every time this node reloads the shared signing-key set (admin reload hook, JWKS poll on change). The cached discovery document embeds the signing-algorithm list, so rendered discovery entries validate against it.
event_listeners: HashMap<String, Arc<dyn EventListener>>Event listeners addressable by name from a realm’s events_listeners.
Always contains "logging"; unknown realm listener names
are ignored at dispatch time.
Implementations§
Source§impl ServerState
impl ServerState
Sourcepub fn typed_executor(&self) -> TypedFlowExecutor
pub fn typed_executor(&self) -> TypedFlowExecutor
Build a TypedFlowExecutor from the current plugin registry.
Sourcepub fn typed_executor_with_flows(
&self,
flows: &[FlowConfig],
) -> TypedFlowExecutor
pub fn typed_executor_with_flows( &self, flows: &[FlowConfig], ) -> TypedFlowExecutor
Build a TypedFlowExecutor whose executor resolves sub-flow stages
against flows (pass the realm’s full stored flow set).
Sourcepub async fn bound_flow_executor(
&self,
realm: &Realm,
bound: Option<&str>,
default_alias: &str,
fallback: fn(RealmId) -> FlowConfig,
) -> (FlowConfig, TypedFlowExecutor)
pub async fn bound_flow_executor( &self, realm: &Realm, bound: Option<&str>, default_alias: &str, fallback: fn(RealmId) -> FlowConfig, ) -> (FlowConfig, TypedFlowExecutor)
Resolve the realm’s bound top-level flow and an executor that can run
it: the flow set is loaded from storage per request — one
indexed query on Postgres, trivial on the in-memory/json backends, and
deliberately uncached so admin flow edits take effect immediately. The
realm’s binding field (bound, None → default_alias) picks the
top-level flow; when the read fails (logged) or the alias is not in
storage, the fallback code constructor keeps bootstrapping and legacy
rigs working. The executor is built over the full loaded list so
sub_flow_alias stages resolve.
Only the browser and registration bindings are consumed at runtime (here and in the login/registration routes). The direct-grant, reset-credentials, and first-broker-login bindings exist for Keycloak-representation parity and admin delete-guardrails only — those paths never run the flow engine.
Sourcepub async fn resolve_realm(
&self,
segment: &str,
) -> Result<Option<Realm>, IssuerdError>
pub async fn resolve_realm( &self, segment: &str, ) -> Result<Option<Realm>, IssuerdError>
Resolve the realm segment from a request URL to a realm.
URLs carry the human-readable realm name — discovery documents and
token issuers embed the realm name (see
TokenManager::issuer_for_realm). Name lookup is therefore
deterministic; the id lookup remains as a fallback so old id-spelled
bookmarks/URLs keep resolving (deterministic if an admin ever names a
realm after another realm’s id: the name wins). The by-name step goes
through the shared realm cache; the id fallback stays uncached.
Sourcepub async fn resolve_issuer_realm(
&self,
issuer: &str,
) -> Result<Option<Realm>, IssuerdError>
pub async fn resolve_issuer_realm( &self, issuer: &str, ) -> Result<Option<Realm>, IssuerdError>
Resolve the realm an iss claim belongs to.
Issuers are realm-NAME based ({issuer_url}/realms/{name}). The
trailing /realms/ segment is extracted and resolved by name; callers
then use realm.id for storage lookups. Tokens issued before the
name-based switch (id-spelled issuers) are intentionally NOT resolved
here — they are rejected.
pub async fn from_config(config: &ServerConfig) -> Result<Self, IssuerdError>
Sourcepub async fn from_components(
config: &ServerConfig,
storage: Arc<dyn Storage>,
cache: Arc<dyn DistributedCache>,
) -> Result<Self, IssuerdError>
pub async fn from_components( config: &ServerConfig, storage: Arc<dyn Storage>, cache: Arc<dyn DistributedCache>, ) -> Result<Self, IssuerdError>
Build server state from pre-constructed shared components.
ServerState::from_config constructs storage and cache from the
config and delegates here. Tests (and embeddings) call this directly to
share one storage/cache pair across several state instances, simulating
a multi-node cluster in one process. config.storage still decides the
master-realm bootstrap and JWKS refresh task eligibility.
Sourcepub async fn from_components_with_email_sender(
config: &ServerConfig,
storage: Arc<dyn Storage>,
cache: Arc<dyn DistributedCache>,
email_sender: Arc<dyn EmailSender>,
) -> Result<Self, IssuerdError>
pub async fn from_components_with_email_sender( config: &ServerConfig, storage: Arc<dyn Storage>, cache: Arc<dyn DistributedCache>, email_sender: Arc<dyn EmailSender>, ) -> Result<Self, IssuerdError>
ServerState::from_components with an explicit EmailSender.
Tests inject a recording sender here so both state.email_sender and
the plugin registry’s email-code authenticator capture it — mutating
state.email_sender after construction would leave the registry’s
mailer pointing at the previous sender.
Trait Implementations§
Auto Trait Implementations§
impl !RefUnwindSafe for ServerState
impl !UnwindSafe for ServerState
impl Freeze for ServerState
impl Send for ServerState
impl Sync for ServerState
impl Unpin for ServerState
impl UnsafeUnpin for ServerState
Blanket Implementations§
Source§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
Source§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> Paint for Twhere
T: ?Sized,
impl<T> Paint for Twhere
T: ?Sized,
Source§fn fg(&self, value: Color) -> Painted<&T>
fn fg(&self, value: Color) -> Painted<&T>
Returns a styled value derived from self with the foreground set to
value.
This method should be used rarely. Instead, prefer to use color-specific
builder methods like red() and
green(), which have the same functionality but are
pithier.
§Example
Set foreground color to white using fg():
use yansi::{Paint, Color};
painted.fg(Color::White);Set foreground color to white using white().
use yansi::Paint;
painted.white();Source§fn bright_black(&self) -> Painted<&T>
fn bright_black(&self) -> Painted<&T>
Source§fn bright_red(&self) -> Painted<&T>
fn bright_red(&self) -> Painted<&T>
Source§fn bright_green(&self) -> Painted<&T>
fn bright_green(&self) -> Painted<&T>
Source§fn bright_yellow(&self) -> Painted<&T>
fn bright_yellow(&self) -> Painted<&T>
Source§fn bright_blue(&self) -> Painted<&T>
fn bright_blue(&self) -> Painted<&T>
Source§fn bright_magenta(&self) -> Painted<&T>
fn bright_magenta(&self) -> Painted<&T>
Source§fn bright_cyan(&self) -> Painted<&T>
fn bright_cyan(&self) -> Painted<&T>
Source§fn bright_white(&self) -> Painted<&T>
fn bright_white(&self) -> Painted<&T>
Source§fn bg(&self, value: Color) -> Painted<&T>
fn bg(&self, value: Color) -> Painted<&T>
Returns a styled value derived from self with the background set to
value.
This method should be used rarely. Instead, prefer to use color-specific
builder methods like on_red() and
on_green(), which have the same functionality but
are pithier.
§Example
Set background color to red using fg():
use yansi::{Paint, Color};
painted.bg(Color::Red);Set background color to red using on_red().
use yansi::Paint;
painted.on_red();Source§fn on_primary(&self) -> Painted<&T>
fn on_primary(&self) -> Painted<&T>
Source§fn on_magenta(&self) -> Painted<&T>
fn on_magenta(&self) -> Painted<&T>
Source§fn on_bright_black(&self) -> Painted<&T>
fn on_bright_black(&self) -> Painted<&T>
Source§fn on_bright_red(&self) -> Painted<&T>
fn on_bright_red(&self) -> Painted<&T>
Source§fn on_bright_green(&self) -> Painted<&T>
fn on_bright_green(&self) -> Painted<&T>
Source§fn on_bright_yellow(&self) -> Painted<&T>
fn on_bright_yellow(&self) -> Painted<&T>
Source§fn on_bright_blue(&self) -> Painted<&T>
fn on_bright_blue(&self) -> Painted<&T>
Source§fn on_bright_magenta(&self) -> Painted<&T>
fn on_bright_magenta(&self) -> Painted<&T>
Source§fn on_bright_cyan(&self) -> Painted<&T>
fn on_bright_cyan(&self) -> Painted<&T>
Source§fn on_bright_white(&self) -> Painted<&T>
fn on_bright_white(&self) -> Painted<&T>
Source§fn attr(&self, value: Attribute) -> Painted<&T>
fn attr(&self, value: Attribute) -> Painted<&T>
Enables the styling Attribute value.
This method should be used rarely. Instead, prefer to use
attribute-specific builder methods like bold() and
underline(), which have the same functionality
but are pithier.
§Example
Make text bold using attr():
use yansi::{Paint, Attribute};
painted.attr(Attribute::Bold);Make text bold using using bold().
use yansi::Paint;
painted.bold();Source§fn rapid_blink(&self) -> Painted<&T>
fn rapid_blink(&self) -> Painted<&T>
Source§fn quirk(&self, value: Quirk) -> Painted<&T>
fn quirk(&self, value: Quirk) -> Painted<&T>
Enables the yansi Quirk value.
This method should be used rarely. Instead, prefer to use quirk-specific
builder methods like mask() and
wrap(), which have the same functionality but are
pithier.
§Example
Enable wrapping using .quirk():
use yansi::{Paint, Quirk};
painted.quirk(Quirk::Wrap);Enable wrapping using wrap().
use yansi::Paint;
painted.wrap();Source§fn clear(&self) -> Painted<&T>
👎Deprecated since 1.0.1: renamed to resetting() due to conflicts with Vec::clear().
The clear() method will be removed in a future release.
fn clear(&self) -> Painted<&T>
renamed to resetting() due to conflicts with Vec::clear().
The clear() method will be removed in a future release.
Source§fn whenever(&self, value: Condition) -> Painted<&T>
fn whenever(&self, value: Condition) -> Painted<&T>
Conditionally enable styling based on whether the Condition value
applies. Replaces any previous condition.
See the crate level docs for more details.
§Example
Enable styling painted only when both stdout and stderr are TTYs:
use yansi::{Paint, Condition};
painted.red().on_yellow().whenever(Condition::STDOUTERR_ARE_TTY);