Skip to main content

Authenticator

Struct Authenticator 

Source
pub struct Authenticator { /* private fields */ }
Expand description

The single definition of the credential rules, shared by every surface.

Absent header → Principal::Anyone. Exactly one Authorization header carrying the service token, the WebDAV Basic pair (where accepted), or a bearer token the TokenVerifier vouches for → Principal::SignedIn. Anything else — a second header, an unknown scheme, a token nobody recognises — is CredentialRefused, never a downgrade to anonymous.

Implementations§

Source§

impl Authenticator

Source

pub fn new(service_token: impl Into<String>) -> Self

An authenticator that recognises only service_token as a bearer.

Source

pub fn with_basic( self, username: impl Into<String>, password: impl Into<String>, ) -> Self

Also accept this Basic username and password, on surfaces that allow it.

Source

pub fn with_token_verifier(self, verifier: Arc<dyn TokenVerifier>) -> Self

Also accept bearer tokens verifier vouches for.

Source

pub fn with_protected_resource(self, resource: ProtectedResource) -> Self

Publish RFC 9728 metadata and name it in bearer challenges.

Source

pub fn accepts_identity_tokens(&self) -> bool

Whether bearer tokens other than the service token can verify at all.

Source

pub fn protected_resource(&self) -> Option<&ProtectedResource>

The published protected-resource metadata, if configured.

Source

pub fn bearer_challenge(&self) -> Option<HeaderValue>

The WWW-Authenticate value a bearer-only surface adds to a 401.

Only present when metadata is published: a bare Bearer challenge tells a client nothing it did not know, and browsers ignore it, so there is nothing to gain from emitting one.

Source

pub async fn resolve( &self, headers: &HeaderMap, accept: Schemes, ) -> Result<Principal, CredentialRefused>

Resolve the principal behind a request’s Authorization headers.

§Errors

CredentialRefused when an Authorization header is present and does not carry exactly one credential this authenticator accepts.

Trait Implementations§

Source§

impl Debug for Authenticator

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more