pub struct GrantSettings {
pub schemes: AcceptedSchemes,
pub relying_parties: Vec<RelyingParty>,
pub allow_loopback: bool,
}Expand description
A deployment’s validated write-grant inputs, kept apart from the
GrantConfig built from them so an adapter’s configuration can be
compared and re-built (a GrantConfig holds no equality).
Fields§
§schemes: AcceptedSchemesThe accepted owner schemes.
relying_parties: Vec<RelyingParty>The accepted WebAuthn relying parties.
allow_loopback: boolDevelopment only: allow a loopback audience or relying party.
Implementations§
Source§impl GrantSettings
impl GrantSettings
Sourcepub fn from_parts(
schemes: Option<AcceptedSchemes>,
relying_parties: Vec<RelyingParty>,
allow_loopback: bool,
) -> Result<Option<Self>, String>
pub fn from_parts( schemes: Option<AcceptedSchemes>, relying_parties: Vec<RelyingParty>, allow_loopback: bool, ) -> Result<Option<Self>, String>
Combine the adapter’s raw settings: None when nothing is set
(grants stay off), otherwise the settings, which a bad or partial
value never degrades to “off”.
§Errors
A message when relying parties or the loopback opt-in are set without any scheme.
Sourcepub fn build(&self, audience: &str) -> Result<GrantConfig, ServerError>
pub fn build(&self, audience: &str) -> Result<GrantConfig, ServerError>
Build the verifier for audience (the deployment’s auth v2 audience):
the production constructor, or the loopback one when the opt-in is set.
§Errors
invalid_argument for any refusal of mkit-attest’s verifier rules:
a loopback audience or relying party without the opt-in,
webauthn-p256 without a relying party, or a duplicate relying party.