#[non_exhaustive]pub enum AuthMode {
Open,
Bearer {
token: Redacted,
},
AuthV2(AuthV2Config),
TransportIdentity,
}Expand description
How a deployment authenticates requests.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
Non-exhaustive enums could have additional variants added in future. Therefore, when matching against variants of non-exhaustive enums, an extra wildcard arm must be added to account for any future variants.
Open
No credentials; every request is Anonymous (unsafe-any HTTP, or a
trusted caller). No replay ledger.
Bearer
A shared Authorization: Bearer <token>, required on every RPC,
unary and streaming (as the removed mkit serve --http did). The BLAKE3
digests of the presented and expected values are compared in
constant time, so neither the content nor the length leaks. No
replay ledger.
AuthV2(AuthV2Config)
Auth v2 on writes, with the replay ledger and quota; a read that carries an auth header is verified in full (SPEC-WRITE-GRANTS §9.2), an unsigned read is anonymous.
TransportIdentity
The binding supplies the principal (ssh forced command, enc peer). No replay ledger.
Trait Implementations§
Auto Trait Implementations§
impl Freeze for AuthMode
impl RefUnwindSafe for AuthMode
impl Send for AuthMode
impl Sync for AuthMode
impl Unpin for AuthMode
impl UnsafeUnpin for AuthMode
impl UnwindSafe for AuthMode
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more