Skip to main content

AuthInterceptor

Struct AuthInterceptor 

Source
pub struct AuthInterceptor<B, N, H> { /* private fields */ }
Expand description

Runs Pipeline::authenticate once per call, before any message reaches a handler, and stores the resulting crate::pipeline::Authenticated (with its test directives under test-faults) in the request extensions. A unary call is checked against its exact request bytes; a client stream against its headers only; DownloadPack’s single request envelope is buffered, verified over its reconstructed framed body (0x00‖be32(len)‖message, R-129) and re-injected.

Calls outside mkit.transport.v1.TransportService (health) pass through unauthenticated. For crate::pipeline::AuthMode::TransportIdentity an adapter inserts the peer’s Principal into the HTTP request extensions; nothing a client sends can set it.

It must be the first (outermost) interceptor. An adapter that builds its own chain from super::router registers it before any other, so no interceptor can rewrite the message before the signature is checked. A rewritten unary payload is verified over its re-encoded bytes, which fails closed.

A unary body is verified as connectrpc hands it over, after any Content-Encoding is undone. The client signs the bytes it sends (SPEC-WRITE-GRANTS §9.2, SPEC-TRANSPORT-CONNECT §7.1), so a compressed signed request does not verify and is rejected unauthenticated, as in vcs-worker.

Implementations§

Source§

impl<B: MultipartBlobStore, N: NamespaceStore, H: HookSet> AuthInterceptor<B, N, H>

Source

pub fn new(pipeline: Arc<Pipeline<B, N, H>>) -> Self

An interceptor authenticating against pipeline’s auth mode.

Trait Implementations§

Source§

impl<B, N, H> Debug for AuthInterceptor<B, N, H>

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<B, N, H> Interceptor for AuthInterceptor<B, N, H>
where B: MultipartBlobStore + 'static, N: NamespaceStore + 'static, H: HookSet + 'static,

Source§

fn intercept_unary<'life0, 'life1, 'async_trait>( &'life0 self, req: UnaryRequest, next: Next<'life1>, ) -> Pin<Box<dyn Future<Output = Result<UnaryResponse, ConnectError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Wrap a unary RPC. The default is a passthrough. Read more
Source§

fn intercept_streaming<'life0, 'life1, 'async_trait>( &'life0 self, req: StreamRequest, inbound: PayloadStream, next: NextStream<'life1>, ) -> Pin<Box<dyn Future<Output = Result<StreamResponse, ConnectError>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Wrap a streaming RPC. The default is a passthrough. Read more

Auto Trait Implementations§

§

impl<B, N, H> !RefUnwindSafe for AuthInterceptor<B, N, H>

§

impl<B, N, H> !UnwindSafe for AuthInterceptor<B, N, H>

§

impl<B, N, H> Freeze for AuthInterceptor<B, N, H>
where Shared<Pipeline<B, N, H>>: Freeze,

§

impl<B, N, H> Send for AuthInterceptor<B, N, H>
where Shared<Pipeline<B, N, H>>: Send,

§

impl<B, N, H> Sync for AuthInterceptor<B, N, H>
where Shared<Pipeline<B, N, H>>: Sync,

§

impl<B, N, H> Unpin for AuthInterceptor<B, N, H>
where Shared<Pipeline<B, N, H>>: Unpin,

§

impl<B, N, H> UnsafeUnpin for AuthInterceptor<B, N, H>
where Shared<Pipeline<B, N, H>>: UnsafeUnpin,

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> MaybeSend for T
where T: Send + ?Sized,

Source§

impl<T> MaybeSync for T
where T: Sync + ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more