pub struct CloudAuthenticator { /* private fields */ }Expand description
Ties the OIDC endpoints (Okta) and the SM API together for one environment.
Implementations§
Source§impl CloudAuthenticator
impl CloudAuthenticator
Sourcepub fn new(
issuer: Url,
client_id: impl Into<String>,
sm_api_url: Url,
capi_url: impl Into<String>,
) -> Self
pub fn new( issuer: Url, client_id: impl Into<String>, sm_api_url: Url, capi_url: impl Into<String>, ) -> Self
Build for one environment. issuer/client_id drive the Okta flows, sm_api_url the
key-minting exchange, and capi_url is recorded in the resulting profile.
Sourcepub fn with_http_client(self, http: Client) -> Self
pub fn with_http_client(self, http: Client) -> Self
Use a caller-provided reqwest client (tests / shared client).
Sourcepub fn device(&self) -> DeviceFlowClient
pub fn device(&self) -> DeviceFlowClient
Device-authorization-grant client for headless / agent logins. The flow runs on the
oauth2 crate’s own HTTP stack, so it does not share this authenticator’s SM client.
Sourcepub fn loopback(&self) -> LoopbackFlowClient
pub fn loopback(&self) -> LoopbackFlowClient
Auth-code + PKCE loopback client for interactive human logins.
Sourcepub async fn refresh(&self, refresh_token: &str) -> Result<TokenSet, AuthError>
pub async fn refresh(&self, refresh_token: &str) -> Result<TokenSet, AuthError>
Refresh an Okta refresh token for a fresh token set (Okta rotates it). The grant is
flow-agnostic, so it goes straight through oidc rather than a specific flow client.
Sourcepub async fn revoke_refresh_token(
&self,
refresh_token: &str,
) -> Result<(), AuthError>
pub async fn revoke_refresh_token( &self, refresh_token: &str, ) -> Result<(), AuthError>
Invalidate a stored refresh token at the identity provider.
Sourcepub async fn list_accounts<F>(
&self,
tokens: &TokenSet,
mfa_prompt: F,
) -> Result<AccountListing, AuthError>
pub async fn list_accounts<F>( &self, tokens: &TokenSet, mfa_prompt: F, ) -> Result<AccountListing, AuthError>
List the accounts the signed-in user belongs to, minting nothing and switching nothing.
Sourcepub async fn revoke_capi_key(
&self,
tokens: &TokenSet,
account_id: Option<u64>,
key_name: &str,
) -> Result<bool, AuthError>
pub async fn revoke_capi_key( &self, tokens: &TokenSet, account_id: Option<u64>, key_name: &str, ) -> Result<bool, AuthError>
Revoke a minted CAPI key by name from account_id, using a session established from
tokens.
Returns whether a key of that name was found. Both the listing and the delete are scoped
to the session’s account, so the caller has to say which account holds the key: a sign-in
starts on the user’s server-side default, which is not necessarily the one a profile’s key
was minted for. Passing None searches wherever the session lands, which is all an older
profile that recorded no account can do.
Sourcepub async fn complete_login(
&self,
tokens: &TokenSet,
key_name: &str,
flow: LoginFlow,
account: AccountChoice,
) -> Result<MintedCredentials, AuthError>
pub async fn complete_login( &self, tokens: &TokenSet, key_name: &str, flow: LoginFlow, account: AccountChoice, ) -> Result<MintedCredentials, AuthError>
Given tokens from a flow, run the SM exchange and mint a CAPI key named key_name.
Propagates AuthError::MfaRequired if the account is MFA-protected; use
CloudAuthenticator::complete_login_with_mfa to supply codes interactively.
Sourcepub async fn complete_login_with_mfa<F>(
&self,
tokens: &TokenSet,
key_name: &str,
flow: LoginFlow,
account: AccountChoice,
superseded: Option<SupersededKey>,
mfa_prompt: F,
) -> Result<(MintedCredentials, Option<SupersededRevoker>), AuthError>
pub async fn complete_login_with_mfa<F>( &self, tokens: &TokenSet, key_name: &str, flow: LoginFlow, account: AccountChoice, superseded: Option<SupersededKey>, mfa_prompt: F, ) -> Result<(MintedCredentials, Option<SupersededRevoker>), AuthError>
As CloudAuthenticator::complete_login, but mfa_prompt is consulted when SM challenges
the login for multi-factor authentication.
mfa_prompt(factors, attempt) is called with the factor types SM offered (possibly empty)
and a 1-based attempt number. Return Some(code) to submit a TOTP code, or None to give
up — which surfaces the original AuthError::MfaRequired to the caller, the right
behaviour when there is no terminal to prompt on.