pub struct Auth { /* private fields */ }Expand description
Login, registration, password reset and email verification pages, and
the users, password_reset_tokens and personal_access_tokens tables.
Routes: login, register (unless without_registration), logout,
password.request, password.email, password.reset,
password.update, password.confirm, verification.notice,
verification.verify and verification.send. Auth::account adds
account.show, account.profile, account.password,
account.logout_others and account.destroy;
Auth::notifications adds the notifications.* routes.
docs/authorization.md lists each one’s method and address.
The pages live in renox/auth/*.html, inside renox/auth/layout.html;
create a file with the same name under your views to replace one.
Failed logins lock out 5 tries per email and IP a minute, 20 per email in
15 minutes from any IP, and 50 per IP in 15 minutes for any email (set
TRUSTED_PROXIES behind a proxy). Logging out ends this device’s
session only; a new password or a password reset ends the other sessions.
Implementations§
Source§impl Auth
impl Auth
Sourcepub fn new() -> Self
pub fn new() -> Self
Registration on, account pages and email verification off, the default Password policy.
Sourcepub fn notifications(self) -> Self
pub fn notifications(self) -> Self
Turns on the in-app notification list for the UI kit’s
notification_bell: the notifications.* routes (a page that is
also the bell’s panel, mark read or unread, delete, and a stream of
Server-Sent Events for new ones), and unread_notifications (the
logged-in user’s unread count) in every view.
App::new().module(Auth::new().notifications())Sourcepub fn registration_rules(
self,
rules: impl Fn(&Registration, &mut Validator) + Send + Sync + 'static,
) -> Self
pub fn registration_rules( self, rules: impl Fn(&Registration, &mut Validator) + Send + Sync + 'static, ) -> Self
Validates fields the app adds to the registration form, with the built-in ones. Their errors show next to the inputs like any other.
Auth::new()
.registration_rules(|form, v| {
v.field("phone", &form.get("phone")).required().max(20);
})
.on_registered(|mut user, form, state| async move {
// `phone` and `role` are columns the app added to `users`.
user.set(&state.db, "phone", form.get("phone")).await?;
let first = User::query().count(&state.db).await? == 1;
user.set(&state.db, "role", if first { "admin" } else { "member" }).await
})Sourcepub fn on_registered<F, Fut>(self, hook: F) -> Self
pub fn on_registered<F, Fut>(self, hook: F) -> Self
Runs after a new user is saved and before they’re logged in, e.g. to save the app’s own fields or give a role. If it fails, the user is deleted again and the visitor gets the error, so they can try again.
Sourcepub fn verify_email(self) -> Self
pub fn verify_email(self) -> Self
Emails new users a verification link. Guard routes that need a
verified address with Routes::require_verified().
Sourcepub fn password_rules(self, policy: Password) -> Self
pub fn password_rules(self, policy: Password) -> Self
What passwords must contain on the register, reset and account
forms; Password::min(8) by default.
use renox::validation::Password;
Auth::new().password_rules(Password::min(12).mixed_case().numbers())Sourcepub fn account(self) -> Self
pub fn account(self) -> Self
Adds the account page (/account, route account.show): change
name and email (a new email must be verified again with
verify_email), change the password, log out other devices, delete
the account. The last two ask for the password. Override the page at
resources/views/renox/auth/account.html.
Sourcepub fn without_registration(self) -> Self
pub fn without_registration(self) -> Self
Hides /register, e.g. for back-office apps where an admin adds users.
Sourcepub fn redirect_to(self, path: &str) -> Self
pub fn redirect_to(self, path: &str) -> Self
Where to go after logging in or registering when no page asked for
the login. Defaults to the home route, or /.
Trait Implementations§
Auto Trait Implementations§
impl !RefUnwindSafe for Auth
impl !UnwindSafe for Auth
impl Freeze for Auth
impl Send for Auth
impl Sync for Auth
impl Unpin for Auth
impl UnsafeUnpin for Auth
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more