Skip to main content

Auth

Struct Auth 

Source
pub struct Auth { /* private fields */ }
Expand description

Login, registration, password reset and email verification pages, and the users, password_reset_tokens and personal_access_tokens tables.

Routes: login, register (unless without_registration), logout, password.request, password.email, password.reset, password.update, password.confirm, verification.notice, verification.verify and verification.send. Auth::account adds account.show, account.profile, account.password, account.logout_others and account.destroy; Auth::notifications adds the notifications.* routes. docs/authorization.md lists each one’s method and address. The pages live in renox/auth/*.html, inside renox/auth/layout.html; create a file with the same name under your views to replace one.

Failed logins lock out 5 tries per email and IP a minute, 20 per email in 15 minutes from any IP, and 50 per IP in 15 minutes for any email (set TRUSTED_PROXIES behind a proxy). Logging out ends this device’s session only; a new password or a password reset ends the other sessions.

Implementations§

Source§

impl Auth

Source

pub fn new() -> Self

Registration on, account pages and email verification off, the default Password policy.

Source

pub fn notifications(self) -> Self

Turns on the in-app notification list for the UI kit’s notification_bell: the notifications.* routes (a page that is also the bell’s panel, mark read or unread, delete, and a stream of Server-Sent Events for new ones), and unread_notifications (the logged-in user’s unread count) in every view.

App::new().module(Auth::new().notifications())
Source

pub fn registration_rules( self, rules: impl Fn(&Registration, &mut Validator) + Send + Sync + 'static, ) -> Self

Validates fields the app adds to the registration form, with the built-in ones. Their errors show next to the inputs like any other.

Auth::new()
    .registration_rules(|form, v| {
        v.field("phone", &form.get("phone")).required().max(20);
    })
    .on_registered(|mut user, form, state| async move {
        // `phone` and `role` are columns the app added to `users`.
        user.set(&state.db, "phone", form.get("phone")).await?;
        let first = User::query().count(&state.db).await? == 1;
        user.set(&state.db, "role", if first { "admin" } else { "member" }).await
    })
Source

pub fn on_registered<F, Fut>(self, hook: F) -> Self
where F: Fn(User, Registration, AppState) -> Fut + Send + Sync + 'static, Fut: Future<Output = Result> + Send + 'static,

Runs after a new user is saved and before they’re logged in, e.g. to save the app’s own fields or give a role. If it fails, the user is deleted again and the visitor gets the error, so they can try again.

Source

pub fn verify_email(self) -> Self

Emails new users a verification link. Guard routes that need a verified address with Routes::require_verified().

Source

pub fn password_rules(self, policy: Password) -> Self

What passwords must contain on the register, reset and account forms; Password::min(8) by default.

use renox::validation::Password;
Auth::new().password_rules(Password::min(12).mixed_case().numbers())
Source

pub fn account(self) -> Self

Adds the account page (/account, route account.show): change name and email (a new email must be verified again with verify_email), change the password, log out other devices, delete the account. The last two ask for the password. Override the page at resources/views/renox/auth/account.html.

Source

pub fn without_registration(self) -> Self

Hides /register, e.g. for back-office apps where an admin adds users.

Source

pub fn redirect_to(self, path: &str) -> Self

Where to go after logging in or registering when no page asked for the login. Defaults to the home route, or /.

Trait Implementations§

Source§

impl Clone for Auth

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Default for Auth

Source§

fn default() -> Self

Returns the “default value” for a type. Read more
Source§

impl Module for Auth

Source§

fn name(&self) -> &'static str

The module’s name, shown by route:list.
Source§

fn migrations(&self) -> &'static [Migration]

Migrations this module owns, e.g. renox::migrations!("src/app/products/migrations").
Source§

fn register(&self, app: &mut Registry)

Registers the module’s jobs, event listeners and scheduled tasks. Read more
Source§

fn routes(&self) -> Routes

The module’s routes; none by default.

Auto Trait Implementations§

§

impl !RefUnwindSafe for Auth

§

impl !UnwindSafe for Auth

§

impl Freeze for Auth

§

impl Send for Auth

§

impl Sync for Auth

§

impl Unpin for Auth

§

impl UnsafeUnpin for Auth

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> Fake for T

Source§

fn fake<U>(&self) -> U
where Self: FakeBase<U>,

Source§

fn fake_with_rng<U, R>(&self, rng: &mut R) -> U
where R: RngExt + ?Sized, Self: FakeBase<U>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more