pub struct CredentialProbe { /* private fields */ }Expand description
Answers “is this credential the one we present?” without handing the credential itself to the caller.
#1270: the NATS monitoring endpoint reports authorized_user per
connection. A current nats-server hides that field for
token-authenticated connections, but that is the broker build’s
behaviour, not a guarantee this side can lean on — a consumer of
/connz has to treat the value as possibly being the fleet-wide secret.
The one question it may safely answer about it is whether it equals the
credential this process already holds, and that answer is enough to
label a connection (“still on the shared token”) without ever storing or
serving the value.
Constructed once and reused: [resolve_token] hits the Windows registry,
and the caller compares against every connection on the broker.
Implementations§
Source§impl CredentialProbe
impl CredentialProbe
Sourcepub fn from_token(token: Option<String>) -> Self
pub fn from_token(token: Option<String>) -> Self
Build a probe around an explicitly-supplied token.
The production path is Self::for_role; this exists so callers can
be tested against a known credential without a Windows registry to
write to — and, on a developer’s machine, without accidentally
probing the real fleet token that for_role would find there.
Sourcepub fn from_user(name: impl Into<String>) -> Self
pub fn from_user(name: impl Into<String>) -> Self
Build a probe for a process that authenticates as a named user.
Describes a fixed user credential, for testing the consumers of
CredentialKind::User without a connection.
Sourcepub fn kind(&self) -> CredentialKind
pub fn kind(&self) -> CredentialKind
Which shape of credential this process is presenting right now.
A role that holds a user but is on the token fallback reports
CredentialKind::Token; the user shape is reported only once the
broker has accepted it. Before any decision a role holding a token
reports the token, and one holding only a user reports None: the
user shape is proof of the broker’s mode and is not claimed on a
guess.
Sourcepub fn is_ours(&self, candidate: &str) -> bool
pub fn is_ours(&self, candidate: &str) -> bool
Whether candidate is the secret this process presents.
Only ever true for a token. A user’s secret is its password, which
authorized_user never carries — matching a username here would
mean “this connection is on the same account”, a different and much
weaker statement than the one callers use this for.
A plain comparison: candidate comes from the broker’s own report of
connections it already authenticated, not from an attacker-chosen
input, so there is no oracle to time.