pub struct AuthInterceptor<B, N, H> { /* private fields */ }Expand description
Runs Pipeline::authenticate once per call, before any message
reaches a handler, and stores the resulting
crate::pipeline::Authenticated (with its test directives under
test-faults) in the request extensions. A unary call is checked
against its exact request bytes; a client stream against its headers
only; DownloadPack’s single request envelope is buffered, verified
over its reconstructed framed body (0x00‖be32(len)‖message, R-129)
and re-injected.
Calls outside mkit.transport.v1.TransportService (health) pass
through unauthenticated. For crate::pipeline::AuthMode::TransportIdentity
an adapter inserts the peer’s Principal into the HTTP request
extensions; nothing a client sends can set it.
It must be the first (outermost) interceptor. An adapter that builds its
own chain from super::router registers it before any other, so no
interceptor can rewrite the message before the signature is checked. A
rewritten unary payload is verified over its re-encoded bytes, which
fails closed.
A unary body is verified as connectrpc hands it over, after any
Content-Encoding is undone. The client signs the bytes it sends
(SPEC-WRITE-GRANTS §9.2, SPEC-TRANSPORT-CONNECT §7.1), so a compressed
signed request does not verify and is rejected unauthenticated, as in
vcs-worker.