Struct mls_rs::identity::x509::X509IdentityProvider
source · #[non_exhaustive]pub struct X509IdentityProvider<IE, V> {
pub identity_extractor: IE,
pub validator: V,
}
Expand description
A customizable generic X.509 certificate identity provider.
This provider forwards its individual IdentityProvider
behavior to its generic sub-components.
Only X509 credentials are supported by this provider.
Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Non-exhaustive structs could have additional fields added in future. Therefore, non-exhaustive structs cannot be constructed in external crates using the traditional
Struct { .. }
syntax; cannot be matched against without a wildcard ..
; and struct update syntax will not work.identity_extractor: IE
§validator: V
Implementations§
source§impl<IE, V> X509IdentityProvider<IE, V>where
IE: X509IdentityExtractor,
V: X509CredentialValidator,
impl<IE, V> X509IdentityProvider<IE, V>where
IE: X509IdentityExtractor,
V: X509CredentialValidator,
sourcepub fn new(identity_extractor: IE, validator: V) -> X509IdentityProvider<IE, V>
pub fn new(identity_extractor: IE, validator: V) -> X509IdentityProvider<IE, V>
Create a new identity provider.
sourcepub fn validate(
&self,
signing_identity: &SigningIdentity,
timestamp: Option<MlsTime>,
) -> Result<(), X509IdentityError>
pub fn validate( &self, signing_identity: &SigningIdentity, timestamp: Option<MlsTime>, ) -> Result<(), X509IdentityError>
Determine if a certificate is valid based on the behavior of the underlying validator provided.
sourcepub fn identity(
&self,
signing_id: &SigningIdentity,
) -> Result<Vec<u8>, X509IdentityError>
pub fn identity( &self, signing_id: &SigningIdentity, ) -> Result<Vec<u8>, X509IdentityError>
Produce a unique identity value to represent the entity controlling a certificate credential within an MLS group.
sourcepub fn valid_successor(
&self,
predecessor: &SigningIdentity,
successor: &SigningIdentity,
) -> Result<bool, X509IdentityError>
pub fn valid_successor( &self, predecessor: &SigningIdentity, successor: &SigningIdentity, ) -> Result<bool, X509IdentityError>
Determine if successor
is controlled by the same entity as
predecessor
based on the behavior of the underlying identity
extractor provided.
sourcepub fn supported_types(&self) -> Vec<CredentialType>
pub fn supported_types(&self) -> Vec<CredentialType>
Supported credential types.
Only CredentialType::X509
is supported.
Trait Implementations§
source§impl<IE, V> Clone for X509IdentityProvider<IE, V>
impl<IE, V> Clone for X509IdentityProvider<IE, V>
source§fn clone(&self) -> X509IdentityProvider<IE, V>
fn clone(&self) -> X509IdentityProvider<IE, V>
Returns a copy of the value. Read more
1.0.0 · source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source
. Read moresource§impl<IE, V> Debug for X509IdentityProvider<IE, V>
impl<IE, V> Debug for X509IdentityProvider<IE, V>
source§impl<IE, V> IdentityProvider for X509IdentityProvider<IE, V>
impl<IE, V> IdentityProvider for X509IdentityProvider<IE, V>
source§type Error = X509IdentityError
type Error = X509IdentityError
Error type that this provider returns on internal failure.
source§fn validate_member(
&self,
signing_identity: &SigningIdentity,
timestamp: Option<MlsTime>,
_extensions: Option<&ExtensionList>,
) -> Result<(), <X509IdentityProvider<IE, V> as IdentityProvider>::Error>
fn validate_member( &self, signing_identity: &SigningIdentity, timestamp: Option<MlsTime>, _extensions: Option<&ExtensionList>, ) -> Result<(), <X509IdentityProvider<IE, V> as IdentityProvider>::Error>
Determine if
signing_identity
is valid for a group member. Read moresource§fn validate_external_sender(
&self,
signing_identity: &SigningIdentity,
timestamp: Option<MlsTime>,
_extensions: Option<&ExtensionList>,
) -> Result<(), <X509IdentityProvider<IE, V> as IdentityProvider>::Error>
fn validate_external_sender( &self, signing_identity: &SigningIdentity, timestamp: Option<MlsTime>, _extensions: Option<&ExtensionList>, ) -> Result<(), <X509IdentityProvider<IE, V> as IdentityProvider>::Error>
Determine if
signing_identity
is valid for an external sender in
the ExternalSendersExtension stored in the group context. Read moresource§fn identity(
&self,
signing_id: &SigningIdentity,
_extensions: &ExtensionList,
) -> Result<Vec<u8>, <X509IdentityProvider<IE, V> as IdentityProvider>::Error>
fn identity( &self, signing_id: &SigningIdentity, _extensions: &ExtensionList, ) -> Result<Vec<u8>, <X509IdentityProvider<IE, V> as IdentityProvider>::Error>
A unique identifier for
signing_identity
. Read moresource§fn valid_successor(
&self,
predecessor: &SigningIdentity,
successor: &SigningIdentity,
_extensions: &ExtensionList,
) -> Result<bool, <X509IdentityProvider<IE, V> as IdentityProvider>::Error>
fn valid_successor( &self, predecessor: &SigningIdentity, successor: &SigningIdentity, _extensions: &ExtensionList, ) -> Result<bool, <X509IdentityProvider<IE, V> as IdentityProvider>::Error>
source§fn supported_types(&self) -> Vec<CredentialType>
fn supported_types(&self) -> Vec<CredentialType>
Credential types that are supported by this provider.
Auto Trait Implementations§
impl<IE, V> Freeze for X509IdentityProvider<IE, V>
impl<IE, V> RefUnwindSafe for X509IdentityProvider<IE, V>where
IE: RefUnwindSafe,
V: RefUnwindSafe,
impl<IE, V> Send for X509IdentityProvider<IE, V>
impl<IE, V> Sync for X509IdentityProvider<IE, V>
impl<IE, V> Unpin for X509IdentityProvider<IE, V>
impl<IE, V> UnwindSafe for X509IdentityProvider<IE, V>where
IE: UnwindSafe,
V: UnwindSafe,
Blanket Implementations§
source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
source§unsafe fn clone_to_uninit(&self, dst: *mut T)
unsafe fn clone_to_uninit(&self, dst: *mut T)
🔬This is a nightly-only experimental API. (
clone_to_uninit
)source§impl<T> IntoEither for T
impl<T> IntoEither for T
source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
Converts
self
into a Left
variant of Either<Self, Self>
if into_left
is true
.
Converts self
into a Right
variant of Either<Self, Self>
otherwise. Read moresource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
Converts
self
into a Left
variant of Either<Self, Self>
if into_left(&self)
returns true
.
Converts self
into a Right
variant of Either<Self, Self>
otherwise. Read more