Skip to main content

mobius_gateway/auth/
config.rs

1//! Pairing policy selected locally by the operator.
2
3use crate::Result;
4
5mobius::embedded_config! {
6    copy;
7/// Limits for paired devices and one-use pairing credentials.
8#[derive(Debug, Clone, Copy, PartialEq, Eq)]
9pub struct AuthConfig {
10    /// Maximum paired clients, including the local client credential.
11    pub paired_clients: usize,
12    /// Lifetime of each newly issued pairing code.
13    pub pairing_lifetime_seconds: u64,
14}
15    defaults = include_str!("defaults.toml");
16}
17impl AuthConfig {
18    /// Validates authentication capacity and credential lifetime.
19    /// # Errors
20    /// Returns an error if a value is zero or outside the bounded authentication budget.
21    pub fn validate(&self) -> Result<()> {
22        crate::config::bounded(
23            "auth.paired_clients",
24            self.paired_clients,
25            1..=crate::config::MAX_CAPACITY,
26        )?;
27        crate::config::bounded(
28            "auth.pairing_lifetime_seconds",
29            self.pairing_lifetime_seconds,
30            1..=86_400,
31        )?;
32        Ok(())
33    }
34}