Skip to main content

AccessControl

Trait AccessControl 

Source
pub trait AccessControl: Send + Sync {
    // Required methods
    fn authorize_connect<'life0, 'life1, 'async_trait>(
        &'life0 self,
        query: &'life1 str,
    ) -> Pin<Box<dyn Future<Output = bool> + Send + 'async_trait>>
       where Self: 'async_trait,
             'life0: 'async_trait,
             'life1: 'async_trait;
    fn on_renderer_connected<'life0, 'life1, 'life2, 'async_trait>(
        &'life0 self,
        name: &'life1 str,
        query: &'life2 str,
    ) -> Pin<Box<dyn Future<Output = ()> + Send + 'async_trait>>
       where Self: 'async_trait,
             'life0: 'async_trait,
             'life1: 'async_trait,
             'life2: 'async_trait;
    fn filter_visible<'life0, 'life1, 'async_trait>(
        &'life0 self,
        api_key: &'life1 str,
        renderers: Vec<RendererInfo>,
    ) -> Pin<Box<dyn Future<Output = Vec<RendererInfo>> + Send + 'async_trait>>
       where Self: 'async_trait,
             'life0: 'async_trait,
             'life1: 'async_trait;
    fn can_target<'life0, 'life1, 'life2, 'async_trait>(
        &'life0 self,
        api_key: &'life1 str,
        renderer_name: &'life2 str,
    ) -> Pin<Box<dyn Future<Output = bool> + Send + 'async_trait>>
       where Self: 'async_trait,
             'life0: 'async_trait,
             'life1: 'async_trait,
             'life2: 'async_trait;

    // Provided methods
    fn authorize_name<'life0, 'life1, 'life2, 'async_trait>(
        &'life0 self,
        _name: &'life1 str,
        _query: &'life2 str,
    ) -> Pin<Box<dyn Future<Output = bool> + Send + 'async_trait>>
       where Self: 'async_trait,
             'life0: 'async_trait,
             'life1: 'async_trait,
             'life2: 'async_trait { ... }
    fn filter_graphics<'life0, 'life1, 'async_trait>(
        &'life0 self,
        _api_key: &'life1 str,
        graphics: Vec<Graphic>,
    ) -> Pin<Box<dyn Future<Output = Vec<Graphic>> + Send + 'async_trait>>
       where Self: 'async_trait,
             'life0: 'async_trait,
             'life1: 'async_trait { ... }
    fn can_load_graphic<'life0, 'life1, 'life2, 'life3, 'async_trait>(
        &'life0 self,
        _api_key: &'life1 str,
        _renderer_name: &'life2 str,
        _graphic_id: &'life3 str,
    ) -> Pin<Box<dyn Future<Output = bool> + Send + 'async_trait>>
       where Self: 'async_trait,
             'life0: 'async_trait,
             'life1: 'async_trait,
             'life2: 'async_trait,
             'life3: 'async_trait { ... }
    fn can_delete_graphic<'life0, 'life1, 'life2, 'async_trait>(
        &'life0 self,
        _api_key: &'life1 str,
        _graphic_id: &'life2 str,
    ) -> Pin<Box<dyn Future<Output = bool> + Send + 'async_trait>>
       where Self: 'async_trait,
             'life0: 'async_trait,
             'life1: 'async_trait,
             'life2: 'async_trait { ... }
}

Required Methods§

Source

fn authorize_connect<'life0, 'life1, 'async_trait>( &'life0 self, query: &'life1 str, ) -> Pin<Box<dyn Future<Output = bool> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Authorizes a renderer’s WebSocket connection before it’s upgraded. query is the connect URL’s raw query string, unparsed and unvalidated by Core — an implementation decides what it means (a zone name + token for ZoneAccessControl, ignored entirely here).

Source

fn on_renderer_connected<'life0, 'life1, 'life2, 'async_trait>( &'life0 self, name: &'life1 str, query: &'life2 str, ) -> Pin<Box<dyn Future<Output = ()> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait, 'life2: 'async_trait,

Called once a renderer’s hello names it, after authorize_connect already approved the connection — a chance to record durable identity for tracking or failover purposes. Best-effort: Core doesn’t drop the connection if this does nothing.

Source

fn filter_visible<'life0, 'life1, 'async_trait>( &'life0 self, api_key: &'life1 str, renderers: Vec<RendererInfo>, ) -> Pin<Box<dyn Future<Output = Vec<RendererInfo>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Filters renderers down to what api_key may see — GET /renderers.

Source

fn can_target<'life0, 'life1, 'life2, 'async_trait>( &'life0 self, api_key: &'life1 str, renderer_name: &'life2 str, ) -> Pin<Box<dyn Future<Output = bool> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait, 'life2: 'async_trait,

Whether api_key may target the renderer named renderer_name — checked before every renderer-scoped call (get/target/load/play/ stop/update/customAction/clear). Keyed on the stable name, not the per-session id.

Provided Methods§

Source

fn authorize_name<'life0, 'life1, 'life2, 'async_trait>( &'life0 self, _name: &'life1 str, _query: &'life2 str, ) -> Pin<Box<dyn Future<Output = bool> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait, 'life2: 'async_trait,

Authorizes the renderer name from hello, before the session is registered. Called after authorize_connect and after name validation, but before attempting to register the session. Returning false closes the connection and never registers it.

Default implementation allows all names (backward compatible). Implementations can enforce policies like “name must match query string” or “name must be authorized for this zone”.

Added in 0.4.0 to prevent name squatting (connecting with valid query but claiming another zone’s renderer name in hello).

Source

fn filter_graphics<'life0, 'life1, 'async_trait>( &'life0 self, _api_key: &'life1 str, graphics: Vec<Graphic>, ) -> Pin<Box<dyn Future<Output = Vec<Graphic>> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait,

Filters graphics down to what api_key may see — GET /graphics. Default implementation returns all graphics (no filtering), maintaining backward compatibility and the original “unscoped by design” behavior.

Source

fn can_load_graphic<'life0, 'life1, 'life2, 'life3, 'async_trait>( &'life0 self, _api_key: &'life1 str, _renderer_name: &'life2 str, _graphic_id: &'life3 str, ) -> Pin<Box<dyn Future<Output = bool> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait, 'life2: 'async_trait, 'life3: 'async_trait,

Whether api_key may load graphic_id onto renderer_name — checked before load() sends a LoadMessage. Default implementation allows all loads (maintaining backward compatibility), but implementations can enforce zone/renderer-specific graphic restrictions.

Source

fn can_delete_graphic<'life0, 'life1, 'life2, 'async_trait>( &'life0 self, _api_key: &'life1 str, _graphic_id: &'life2 str, ) -> Pin<Box<dyn Future<Output = bool> + Send + 'async_trait>>
where Self: 'async_trait, 'life0: 'async_trait, 'life1: 'async_trait, 'life2: 'async_trait,

Whether api_key may delete graphic_id — DELETE /graphics/{id}. Defaults to allowing it, like every other call without access control: a deployment that runs Core on its own already lets anyone on its network clear what’s on air. A delete without force only unlists the graphic, so it’s recoverable until the retention period ends.

Dyn Compatibility§

This trait is dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementors§