pub struct CredentialProbe { /* private fields */ }Expand description
Answers “is this credential the one we present?” without handing the credential itself to the caller.
#1270: the NATS monitoring endpoint reports authorized_user per
connection. A current nats-server hides that field for
token-authenticated connections, but that is the broker build’s
behaviour, not a guarantee this side can lean on — a consumer of
/connz has to treat the value as possibly being the fleet-wide secret.
The one question it may safely answer about it is whether it equals the
credential this process already holds, and that answer is enough to
label a connection (“still on the shared token”) without ever storing or
serving the value.
Constructed once and reused: [resolve_token] hits the Windows registry,
and the caller compares against every connection on the broker.
Implementations§
Source§impl CredentialProbe
impl CredentialProbe
Sourcepub fn for_role(role: NatsRole) -> Self
pub fn for_role(role: NatsRole) -> Self
Resolve the credential role would present, exactly as connect
does.
Sourcepub fn from_token(token: Option<String>) -> Self
pub fn from_token(token: Option<String>) -> Self
Build a probe around an explicitly-supplied token.
The production path is Self::for_role; this exists so callers can
be tested against a known credential without a Windows registry to
write to — and, on a developer’s machine, without accidentally
probing the real fleet token that for_role would find there.
Sourcepub fn from_user(name: impl Into<String>) -> Self
pub fn from_user(name: impl Into<String>) -> Self
Build a probe for a process that authenticates as a named user.
Nothing constructs this in production yet — connect cannot
present a user (#1266). It exists so the consumers of
CredentialKind::User are testable now rather than written blind
later.
Sourcepub fn kind(&self) -> CredentialKind
pub fn kind(&self) -> CredentialKind
Which shape of credential this process presents.
Sourcepub fn is_ours(&self, candidate: &str) -> bool
pub fn is_ours(&self, candidate: &str) -> bool
Whether candidate is the secret this process presents.
Only ever true for a token. A user’s secret is its password, which
authorized_user never carries — matching a username here would
mean “this connection is on the same account”, a different and much
weaker statement than the one callers use this for.
A plain comparison: candidate comes from the broker’s own report of
connections it already authenticated, not from an attacker-chosen
input, so there is no oracle to time.