pub struct AuthUser { /* private fields */ }Expand description
The logged-in user. Requests without one are sent to the login route
(HTMX requests via HX-Redirect) or get 401 when they want JSON. Use
Option<AuthUser> where logging in is optional.
Implementations§
Source§impl AuthUser
impl AuthUser
Sourcepub fn token_id(&self) -> Option<i64>
pub fn token_id(&self) -> Option<i64>
The id of the API token this request logged in with
(Authorization: Bearer), or None for a session login. Revoke just
that token on “log out” from an app: user.revoke_token(&db, id).
Sourcepub fn token_can(&self, ability: &str) -> bool
pub fn token_can(&self, ability: &str) -> bool
Whether the API token this request logged in with may do ability
(create_token_with(.., &["orders:read"], ..)). Sessions, and tokens
made without a list, may do everything.
Sourcepub fn has_role(&self, role: &str) -> bool
pub fn has_role(&self, role: &str) -> bool
Whether the user has role (the Permissions module): a global
role, or one given in the request’s scope (permissions::set_scope),
within its dates.
Sourcepub fn has_permission(&self, permission: &str) -> bool
pub fn has_permission(&self, permission: &str) -> bool
Whether one of the user’s roles grants permission (the
Permissions module; the same roles as has_role).
allows(permission) also asks App::gate_before.
Sourcepub fn has_role_in(&self, role: &str, scope: &Scope) -> bool
pub fn has_role_in(&self, role: &str, scope: &Scope) -> bool
Whether the user has role globally or in scope (the record’s,
not the request’s), within its dates.
Sourcepub fn has_permission_in(&self, permission: &str, scope: &Scope) -> bool
pub fn has_permission_in(&self, permission: &str, scope: &Scope) -> bool
Whether a global role of the user, or one given in scope (the
record’s, not the request’s), grants permission now; for
policies and handlers that work on one record.
Sourcepub fn scopes_with<M: Model>(&self, permission: &str) -> Scopes<M::Key>
pub fn scopes_with<M: Model>(&self, permission: &str) -> Scopes<M::Key>
The records of model M in which the user holds permission:
Scopes::All when a global role grants it, else their keys. See
User::scopes_with.
Sourcepub fn role_names(&self) -> &[String]
pub fn role_names(&self) -> &[String]
The user’s roles (the Permissions module) in effect: the global
ones plus those in the request’s scope, sorted, as they were the
first time this was asked.
Sourcepub fn can(&self, ability: &str, target: &impl Policy) -> bool
pub fn can(&self, ability: &str, target: &impl Policy) -> bool
Whether the policy of target allows ability (after
App::gate_before).
Like can, but a refusal becomes a 403 response.
Sourcepub fn allows(&self, gate: &str) -> bool
pub fn allows(&self, gate: &str) -> bool
Whether the gate named gate lets this user through: gate_before,
then the gate, then the user’s permissions of that name. Unknown
names deny.
Sourcepub async fn allows_async(&self, gate: &str) -> Result<bool>
pub async fn allows_async(&self, gate: &str) -> Result<bool>
Whether the gate named gate lets this user through, for gates made
with App::gate_async (which may query the database) as well as
plain ones. Unknown gates deny.
Sourcepub async fn gate_async(&self, gate: &str) -> Result
pub async fn gate_async(&self, gate: &str) -> Result
Like allows_async, but a refusal becomes a 403 response.
Methods from Deref<Target = User>§
Sourcepub async fn delete_account(&self, db: &Db) -> Result
pub async fn delete_account(&self, db: &Db) -> Result
Deletes the user (their tokens, notifications and sessions go with the row) and their data grid preferences. The account page’s “delete account” does this.
Sourcepub async fn notifications(
&self,
db: &Db,
limit: u32,
) -> Result<Vec<DatabaseNotification>>
pub async fn notifications( &self, db: &Db, limit: u32, ) -> Result<Vec<DatabaseNotification>>
The user’s notifications, newest first.
Sourcepub async fn notifications_before(
&self,
db: &Db,
before: i64,
limit: u32,
) -> Result<Vec<DatabaseNotification>>
pub async fn notifications_before( &self, db: &Db, before: i64, limit: u32, ) -> Result<Vec<DatabaseNotification>>
The user’s notifications older than the one with id before,
newest first: the next page after a list ending at before.
Sourcepub async fn notification(
&self,
db: &Db,
id: i64,
) -> Result<Option<DatabaseNotification>>
pub async fn notification( &self, db: &Db, id: i64, ) -> Result<Option<DatabaseNotification>>
One of the user’s notifications, or None if it isn’t theirs.
Sourcepub async fn unread_notifications(
&self,
db: &Db,
) -> Result<Vec<DatabaseNotification>>
pub async fn unread_notifications( &self, db: &Db, ) -> Result<Vec<DatabaseNotification>>
The user’s unread notifications, newest first.
Sourcepub async fn unread_notification_count(&self, db: &Db) -> Result<i64>
pub async fn unread_notification_count(&self, db: &Db) -> Result<i64>
How many of the user’s notifications are unread.
Sourcepub async fn mark_notification_read(&self, db: &Db, id: i64) -> Result<bool>
pub async fn mark_notification_read(&self, db: &Db, id: i64) -> Result<bool>
Marks one of the user’s notifications read; returns whether it was theirs.
Sourcepub async fn mark_notification_unread(&self, db: &Db, id: i64) -> Result<bool>
pub async fn mark_notification_unread(&self, db: &Db, id: i64) -> Result<bool>
Marks one of the user’s notifications unread again; returns whether it was theirs.
Sourcepub async fn delete_notification(&self, db: &Db, id: i64) -> Result<bool>
pub async fn delete_notification(&self, db: &Db, id: i64) -> Result<bool>
Deletes one of the user’s notifications; returns whether it was theirs.
Sourcepub async fn delete_notifications(&self, db: &Db) -> Result<u64>
pub async fn delete_notifications(&self, db: &Db) -> Result<u64>
Deletes all the user’s notifications; returns how many there were.
Sourcepub async fn mark_all_notifications_read(&self, db: &Db) -> Result<u64>
pub async fn mark_all_notifications_read(&self, db: &Db) -> Result<u64>
Marks all the user’s unread notifications read; returns how many there were.
Sourcepub async fn assign_role(&self, db: &Db, role: &str) -> Result
pub async fn assign_role(&self, db: &Db, role: &str) -> Result
Gives the user the existing role role (see
permissions::define_role) everywhere and for good.
Sourcepub fn assign_role_in<'a>(
&self,
db: &'a Db,
role: &'a str,
scope: &Scope,
) -> AssignRole<'a>
pub fn assign_role_in<'a>( &self, db: &'a Db, role: &'a str, scope: &Scope, ) -> AssignRole<'a>
Gives the user the existing role role in scope (a store, a
team), optionally from / until a date; .await it:
user.assign_role_in(&db, "manager", &Scope::of(&store)).until(end).await?.
It counts when that scope is the request’s (set_scope) and for
User::has_permission_in on that scope. With
Scope::global, it is a global role with dates.
Sourcepub async fn remove_role(&self, db: &Db, role: &str) -> Result
pub async fn remove_role(&self, db: &Db, role: &str) -> Result
Takes the global role role away from the user (roles given in a
scope stay; see User::remove_role_in).
Sourcepub async fn remove_role_in(&self, db: &Db, role: &str, scope: &Scope) -> Result
pub async fn remove_role_in(&self, db: &Db, role: &str, scope: &Scope) -> Result
Takes the role role in scope away from the user.
Sourcepub async fn sync_roles(&self, db: &Db, roles: &[&str]) -> Result
pub async fn sync_roles(&self, db: &Db, roles: &[&str]) -> Result
Makes the user’s global roles exactly roles (each must exist);
roles given in a scope stay.
Sourcepub async fn sync_roles_in(
&self,
db: &Db,
roles: &[&str],
scope: &Scope,
) -> Result
pub async fn sync_roles_in( &self, db: &Db, roles: &[&str], scope: &Scope, ) -> Result
Makes the user’s roles in scope exactly roles (each must exist),
with no dates; other scopes stay.
Sourcepub async fn roles(&self, db: &Db) -> Result<Vec<String>>
pub async fn roles(&self, db: &Db) -> Result<Vec<String>>
The names of the user’s roles in effect now, sorted: the global ones
plus those in the request’s scope (set_scope), within their
dates.
Sourcepub async fn permissions(&self, db: &Db) -> Result<Vec<String>>
pub async fn permissions(&self, db: &Db) -> Result<Vec<String>>
The permissions the user’s roles in effect now grant, sorted (the
same roles as User::roles).
Sourcepub async fn assignments(&self, db: &Db) -> Result<Vec<Assignment>>
pub async fn assignments(&self, db: &Db) -> Result<Vec<Assignment>>
Every role the user was given, with where and when, ordered by role
and scope; ended ones too until permissions:prune deletes them.
For account and admin pages.
Sourcepub fn has_role_in(&self, role: &str, scope: &Scope) -> bool
pub fn has_role_in(&self, role: &str, scope: &Scope) -> bool
Whether this user has role globally or in scope, within its
dates, from the roles loaded for the current request (like
User::has_role); scope is the record’s, not the request’s.
Sourcepub fn has_permission_in(&self, permission: &str, scope: &Scope) -> bool
pub fn has_permission_in(&self, permission: &str, scope: &Scope) -> bool
Whether a global role of this user, or one given in scope, grants
permission now: for policies, which check the record’s scope
(Scope::of_id::<Store>(order.store_id)) rather than the request’s.
Answered from the roles loaded for the current request (like
User::has_permission): false for another user and outside a
request.
Sourcepub fn scopes_with<M: Model>(&self, permission: &str) -> Scopes<M::Key>
pub fn scopes_with<M: Model>(&self, permission: &str) -> Scopes<M::Key>
The records of model M in which this user holds permission now:
Scopes::All when a global role grants it, else the keys of the
records whose roles do. For filtering lists (Scopes::apply).
Answered from the roles loaded for the current request; nothing for
another user and outside a request.
Sourcepub async fn create_token(
&self,
db: &Db,
name: &str,
expires_at: Option<DateTime>,
) -> Result<NewToken>
pub async fn create_token( &self, db: &Db, name: &str, expires_at: Option<DateTime>, ) -> Result<NewToken>
Creates an API token that may do everything the user may, optionally
expiring at expires_at.
Sourcepub async fn create_token_with(
&self,
db: &Db,
name: &str,
abilities: &[&str],
expires_at: Option<DateTime>,
) -> Result<NewToken>
pub async fn create_token_with( &self, db: &Db, name: &str, abilities: &[&str], expires_at: Option<DateTime>, ) -> Result<NewToken>
Creates an API token limited to abilities (checked with
AuthUser::token_can or Routes::require_ability), e.g. a read-only
token: create_token_with(&db, "reports", &["orders:read"], None).
"*" allows everything.
Sourcepub async fn tokens(&self, db: &Db) -> Result<Vec<AccessToken>>
pub async fn tokens(&self, db: &Db) -> Result<Vec<AccessToken>>
The user’s API tokens, newest first.
Sourcepub async fn revoke_token(&self, db: &Db, token_id: i64) -> Result<bool>
pub async fn revoke_token(&self, db: &Db, token_id: i64) -> Result<bool>
Revokes one of the user’s tokens; returns whether it existed.
Sourcepub async fn revoke_tokens(&self, db: &Db) -> Result<u64>
pub async fn revoke_tokens(&self, db: &Db) -> Result<u64>
Revokes all of the user’s tokens.
Sourcepub fn get<T: DeserializeOwned>(&self, column: &str) -> Option<T>
pub fn get<T: DeserializeOwned>(&self, column: &str) -> Option<T>
One of the app’s own columns (see extra), e.g.
user.get::<String>("role"); None if missing, null or of another type.
A BOOLEAN column reads as bool on SQLite too, where it is stored as
0 or 1.
Sourcepub async fn revoke_sessions(&self, db: &Db) -> Result
pub async fn revoke_sessions(&self, db: &Db) -> Result
Ends every session of the user, e.g. on logout or when an account
may be compromised. API tokens stay; see User::revoke_tokens.
Sourcepub fn has_password(&self) -> bool
pub fn has_password(&self) -> bool
Whether the user has a password. Users made by a social login
(auth::register_verified, the renox-oauth crate) don’t: their
password is empty, which no typed password matches, until they
choose one with “Forgot your password?”.
Sourcepub async fn check_password(&self, password: &str) -> bool
pub async fn check_password(&self, password: &str) -> bool
Whether password matches the stored hash (Argon2id or an imported bcrypt one).
Sourcepub fn can(&self, ability: &str, target: &impl Policy) -> bool
pub fn can(&self, ability: &str, target: &impl Policy) -> bool
Whether target’s Policy allows this user ability.
Like User::can, but a refusal becomes a 403 error.
Sourcepub fn has_role(&self, role: &str) -> bool
pub fn has_role(&self, role: &str) -> bool
Whether this user has role (the Permissions module), answered
from the roles loaded for the current request, so it works in
Policy::allows and App::gate_before (“admins may do anything”).
It is false for any other user, and outside a request (a job, a
command): use the async user.roles(&db) there.
Global roles count, plus those given in the request’s scope
(permissions::set_scope), within their dates.
Sourcepub fn has_permission(&self, permission: &str) -> bool
pub fn has_permission(&self, permission: &str) -> bool
Like User::has_role, for a permission granted by one of the
user’s roles.
Trait Implementations§
Auto Trait Implementations§
impl !Freeze for AuthUser
impl !RefUnwindSafe for AuthUser
impl !UnwindSafe for AuthUser
impl Send for AuthUser
impl Sync for AuthUser
impl Unpin for AuthUser
impl UnsafeUnpin for AuthUser
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<S, T> FromRequest<S, ViaParts> for T
impl<S, T> FromRequest<S, ViaParts> for T
Source§type Rejection = <T as FromRequestParts<S>>::Rejection
type Rejection = <T as FromRequestParts<S>>::Rejection
Source§fn from_request(
req: Request<Body>,
state: &S,
) -> impl Future<Output = Result<T, <T as FromRequest<S, ViaParts>>::Rejection>>
fn from_request( req: Request<Body>, state: &S, ) -> impl Future<Output = Result<T, <T as FromRequest<S, ViaParts>>::Rejection>>
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more