pub struct SecurityApi { /* private fields */ }Expand description
Security system calls.
Implementations§
Source§impl SecurityApi
impl SecurityApi
Sourcepub fn new(
auth_manager: Arc<Mutex<AuthManager>>,
audit_trail: Arc<AuditTrail>,
access_manager: Arc<Mutex<AccessManager>>,
state_store: Arc<StateStore>,
) -> Self
pub fn new( auth_manager: Arc<Mutex<AuthManager>>, audit_trail: Arc<AuditTrail>, access_manager: Arc<Mutex<AccessManager>>, state_store: Arc<StateStore>, ) -> Self
Create a new SecurityApi.
Sourcepub fn generate_ws_ticket(&self) -> String
pub fn generate_ws_ticket(&self) -> String
Generate a one-time WebSocket ticket.
The ticket is valid for [WS_TICKET_TTL_SECS] seconds (single-use).
Pruning removes entries older than [WS_TICKET_PRUNE_AFTER_SECS]
seconds — the prune window is intentionally a bit longer than the
validate window so a ticket that has just expired is still cleared
from memory on the next generate.
Sourcepub fn validate_ws_ticket(&self, ticket: &str) -> bool
pub fn validate_ws_ticket(&self, ticket: &str) -> bool
Validate and consume a one-time WebSocket ticket. Returns false if invalid/expired/already-used.
Sourcepub fn audit(&self, actor: &str, action: AuditAction, resource: &str) -> String
pub fn audit(&self, actor: &str, action: AuditAction, resource: &str) -> String
Audit an action.
Sourcepub fn verify_chain(&self) -> Result<bool>
pub fn verify_chain(&self) -> Result<bool>
Verify audit chain integrity.
Sourcepub fn query_audit(&self, from_seq: u64, to_seq: u64) -> Vec<TrailEntry>
pub fn query_audit(&self, from_seq: u64, to_seq: u64) -> Vec<TrailEntry>
Query audit entries by sequence range.
Sourcepub fn query_audit_by_agent(&self, agent_id: &str) -> Vec<TrailEntry>
pub fn query_audit_by_agent(&self, agent_id: &str) -> Vec<TrailEntry>
Query audit entries whose agent/subject matches agent_id.
Field access is serde-based so this is robust to TrailEntry field
renames in oxi-sdk.
Sourcepub fn audit_count(&self) -> usize
pub fn audit_count(&self) -> usize
Get audit entry count.
Sourcepub fn flush(&self, git: &GitLayer) -> Result<()>
pub fn flush(&self, git: &GitLayer) -> Result<()>
Flush audit trail to disk and commit to git.
Persists all in-memory audit entries to the state store, then commits the audit file to git for versioning.
Sourcepub fn validate_token(&self, token: &str) -> bool
pub fn validate_token(&self, token: &str) -> bool
Validate a bearer token.
Sourcepub fn get_audit_log(&self) -> Vec<AuditEntry>
pub fn get_audit_log(&self) -> Vec<AuditEntry>
Get audit log entries from access manager.
Sourcepub fn get_permissions(&self, agent: &str) -> Option<AgentPermissions>
pub fn get_permissions(&self, agent: &str) -> Option<AgentPermissions>
Get permissions for an agent.
Sourcepub fn ensure_permissions(&self, agent: &str) -> AgentPermissions
pub fn ensure_permissions(&self, agent: &str) -> AgentPermissions
Ensure permissions exist for an agent (get or create).
Sourcepub fn update_permissions(
&self,
agent: &str,
update: PermissionUpdate,
) -> Result<()>
pub fn update_permissions( &self, agent: &str, update: PermissionUpdate, ) -> Result<()>
Update permissions for an agent.
Sourcepub fn log_action(&self, agent_name: &str, action: &str, resource: &str)
pub fn log_action(&self, agent_name: &str, action: &str, resource: &str)
Log an audit action.
Sourcepub fn list_approvals(&self) -> Vec<(PendingApproval, ApprovalStatus)>
pub fn list_approvals(&self) -> Vec<(PendingApproval, ApprovalStatus)>
List all pending approvals.
Auto Trait Implementations§
impl !RefUnwindSafe for SecurityApi
impl !UnwindSafe for SecurityApi
impl Freeze for SecurityApi
impl Send for SecurityApi
impl Sync for SecurityApi
impl Unpin for SecurityApi
impl UnsafeUnpin for SecurityApi
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
impl<T> ErasedDestructor for Twhere
T: 'static,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreimpl<T> MaybeSendSync for T
Source§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.Source§impl<T> Pointable for T
impl<T> Pointable for T
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> Read<Exclusive, BecauseExclusive> for Twhere
T: ?Sized,
Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.