Skip to main content

AuthUser

Struct AuthUser 

Source
pub struct AuthUser { /* private fields */ }
Expand description

The logged-in user. Requests without one are sent to the login route (HTMX requests via HX-Redirect) or get 401 when they want JSON. Use Option<AuthUser> where logging in is optional.

Implementations§

Source§

impl AuthUser

Source

pub fn token_id(&self) -> Option<i64>

The id of the API token this request logged in with (Authorization: Bearer), or None for a session login. Revoke just that token on “log out” from an app: user.revoke_token(&db, id).

Source

pub fn token_can(&self, ability: &str) -> bool

Whether the API token this request logged in with may do ability (create_token_with(.., &["orders:read"], ..)). Sessions, and tokens made without a list, may do everything.

Source

pub fn has_role(&self, role: &str) -> bool

Whether the user has role (the Permissions module): a global role, or one given in the request’s scope (permissions::set_scope), within its dates.

Source

pub fn has_permission(&self, permission: &str) -> bool

Whether one of the user’s roles grants permission (the Permissions module; the same roles as has_role). allows(permission) also asks App::gate_before.

Source

pub fn has_role_in(&self, role: &str, scope: &Scope) -> bool

Whether the user has role globally or in scope (the record’s, not the request’s), within its dates.

Source

pub fn has_permission_in(&self, permission: &str, scope: &Scope) -> bool

Whether a global role of the user, or one given in scope (the record’s, not the request’s), grants permission now; for policies and handlers that work on one record.

Source

pub fn scopes_with<M: Model>(&self, permission: &str) -> Scopes<M::Key>

The records of model M in which the user holds permission: Scopes::All when a global role grants it, else their keys. See User::scopes_with.

Source

pub fn role_names(&self) -> &[String]

The user’s roles (the Permissions module) in effect: the global ones plus those in the request’s scope, sorted, as they were the first time this was asked.

Source

pub fn can(&self, ability: &str, target: &impl Policy) -> bool

Whether the policy of target allows ability (after App::gate_before).

Source

pub fn authorize(&self, ability: &str, target: &impl Policy) -> Result

Like can, but a refusal becomes a 403 response.

Source

pub fn allows(&self, gate: &str) -> bool

Whether the gate named gate lets this user through: gate_before, then the gate, then the user’s permissions of that name. Unknown names deny.

Source

pub fn gate(&self, gate: &str) -> Result

Like allows, but a refusal becomes a 403 response.

Source

pub async fn allows_async(&self, gate: &str) -> Result<bool>

Whether the gate named gate lets this user through, for gates made with App::gate_async (which may query the database) as well as plain ones. Unknown gates deny.

Source

pub async fn gate_async(&self, gate: &str) -> Result

Like allows_async, but a refusal becomes a 403 response.

Source

pub fn user(&self) -> &User

The logged-in user.

Methods from Deref<Target = User>§

Source

pub async fn delete_account(&self, db: &Db) -> Result

Deletes the user (their tokens, notifications and sessions go with the row) and their data grid preferences. The account page’s “delete account” does this.

Source

pub async fn notifications( &self, db: &Db, limit: u32, ) -> Result<Vec<DatabaseNotification>>

The user’s notifications, newest first.

Source

pub async fn notifications_before( &self, db: &Db, before: i64, limit: u32, ) -> Result<Vec<DatabaseNotification>>

The user’s notifications older than the one with id before, newest first: the next page after a list ending at before.

Source

pub async fn notification( &self, db: &Db, id: i64, ) -> Result<Option<DatabaseNotification>>

One of the user’s notifications, or None if it isn’t theirs.

Source

pub async fn unread_notifications( &self, db: &Db, ) -> Result<Vec<DatabaseNotification>>

The user’s unread notifications, newest first.

Source

pub async fn unread_notification_count(&self, db: &Db) -> Result<i64>

How many of the user’s notifications are unread.

Source

pub async fn mark_notification_read(&self, db: &Db, id: i64) -> Result<bool>

Marks one of the user’s notifications read; returns whether it was theirs.

Source

pub async fn mark_notification_unread(&self, db: &Db, id: i64) -> Result<bool>

Marks one of the user’s notifications unread again; returns whether it was theirs.

Source

pub async fn delete_notification(&self, db: &Db, id: i64) -> Result<bool>

Deletes one of the user’s notifications; returns whether it was theirs.

Source

pub async fn delete_notifications(&self, db: &Db) -> Result<u64>

Deletes all the user’s notifications; returns how many there were.

Source

pub async fn mark_all_notifications_read(&self, db: &Db) -> Result<u64>

Marks all the user’s unread notifications read; returns how many there were.

Source

pub async fn assign_role(&self, db: &Db, role: &str) -> Result

Gives the user the existing role role (see permissions::define_role) everywhere and for good.

Source

pub fn assign_role_in<'a>( &self, db: &'a Db, role: &'a str, scope: &Scope, ) -> AssignRole<'a>

Gives the user the existing role role in scope (a store, a team), optionally from / until a date; .await it: user.assign_role_in(&db, "manager", &Scope::of(&store)).until(end).await?. It counts when that scope is the request’s (set_scope) and for User::has_permission_in on that scope. With Scope::global, it is a global role with dates.

Source

pub async fn remove_role(&self, db: &Db, role: &str) -> Result

Takes the global role role away from the user (roles given in a scope stay; see User::remove_role_in).

Source

pub async fn remove_role_in(&self, db: &Db, role: &str, scope: &Scope) -> Result

Takes the role role in scope away from the user.

Source

pub async fn sync_roles(&self, db: &Db, roles: &[&str]) -> Result

Makes the user’s global roles exactly roles (each must exist); roles given in a scope stay.

Source

pub async fn sync_roles_in( &self, db: &Db, roles: &[&str], scope: &Scope, ) -> Result

Makes the user’s roles in scope exactly roles (each must exist), with no dates; other scopes stay.

Source

pub async fn roles(&self, db: &Db) -> Result<Vec<String>>

The names of the user’s roles in effect now, sorted: the global ones plus those in the request’s scope (set_scope), within their dates.

Source

pub async fn permissions(&self, db: &Db) -> Result<Vec<String>>

The permissions the user’s roles in effect now grant, sorted (the same roles as User::roles).

Source

pub async fn assignments(&self, db: &Db) -> Result<Vec<Assignment>>

Every role the user was given, with where and when, ordered by role and scope; ended ones too until permissions:prune deletes them. For account and admin pages.

Source

pub fn has_role_in(&self, role: &str, scope: &Scope) -> bool

Whether this user has role globally or in scope, within its dates, from the roles loaded for the current request (like User::has_role); scope is the record’s, not the request’s.

Source

pub fn has_permission_in(&self, permission: &str, scope: &Scope) -> bool

Whether a global role of this user, or one given in scope, grants permission now: for policies, which check the record’s scope (Scope::of_id::<Store>(order.store_id)) rather than the request’s. Answered from the roles loaded for the current request (like User::has_permission): false for another user and outside a request.

Source

pub fn scopes_with<M: Model>(&self, permission: &str) -> Scopes<M::Key>

The records of model M in which this user holds permission now: Scopes::All when a global role grants it, else the keys of the records whose roles do. For filtering lists (Scopes::apply). Answered from the roles loaded for the current request; nothing for another user and outside a request.

Source

pub async fn create_token( &self, db: &Db, name: &str, expires_at: Option<DateTime>, ) -> Result<NewToken>

Creates an API token that may do everything the user may, optionally expiring at expires_at.

Source

pub async fn create_token_with( &self, db: &Db, name: &str, abilities: &[&str], expires_at: Option<DateTime>, ) -> Result<NewToken>

Creates an API token limited to abilities (checked with AuthUser::token_can or Routes::require_ability), e.g. a read-only token: create_token_with(&db, "reports", &["orders:read"], None). "*" allows everything.

Source

pub async fn tokens(&self, db: &Db) -> Result<Vec<AccessToken>>

The user’s API tokens, newest first.

Source

pub async fn revoke_token(&self, db: &Db, token_id: i64) -> Result<bool>

Revokes one of the user’s tokens; returns whether it existed.

Source

pub async fn revoke_tokens(&self, db: &Db) -> Result<u64>

Revokes all of the user’s tokens.

Source

pub fn get<T: DeserializeOwned>(&self, column: &str) -> Option<T>

One of the app’s own columns (see extra), e.g. user.get::<String>("role"); None if missing, null or of another type. A BOOLEAN column reads as bool on SQLite too, where it is stored as 0 or 1.

Source

pub async fn revoke_sessions(&self, db: &Db) -> Result

Ends every session of the user, e.g. on logout or when an account may be compromised. API tokens stay; see User::revoke_tokens.

Source

pub fn has_password(&self) -> bool

Whether the user has a password. Users made by a social login (auth::register_verified, the renox-oauth crate) don’t: their password is empty, which no typed password matches, until they choose one with “Forgot your password?”.

Source

pub async fn check_password(&self, password: &str) -> bool

Whether password matches the stored hash (Argon2id or an imported bcrypt one).

Source

pub fn can(&self, ability: &str, target: &impl Policy) -> bool

Whether target’s Policy allows this user ability.

Source

pub fn authorize(&self, ability: &str, target: &impl Policy) -> Result

Like User::can, but a refusal becomes a 403 error.

Source

pub fn has_role(&self, role: &str) -> bool

Whether this user has role (the Permissions module), answered from the roles loaded for the current request, so it works in Policy::allows and App::gate_before (“admins may do anything”). It is false for any other user, and outside a request (a job, a command): use the async user.roles(&db) there.

Global roles count, plus those given in the request’s scope (permissions::set_scope), within their dates.

Source

pub fn has_permission(&self, permission: &str) -> bool

Like User::has_role, for a permission granted by one of the user’s roles.

Trait Implementations§

Source§

impl Clone for AuthUser

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Deref for AuthUser

Source§

type Target = User

The resulting type after dereferencing.
Source§

fn deref(&self) -> &User

Dereferences the value.
Source§

impl From<&AuthUser> for Recipient

Source§

fn from(user: &AuthUser) -> Self

Converts to this type from the input type.
Source§

impl<S: Send + Sync> FromRequestParts<S> for AuthUser

Source§

type Rejection = Response<Body>

If the extractor fails it’ll use this “rejection” type. A rejection is a kind of error that can be converted into a response.
Source§

async fn from_request_parts(parts: &mut Parts, _: &S) -> Result<Self, Response>

Perform the extraction.
Source§

impl<S: Send + Sync> OptionalFromRequestParts<S> for AuthUser

Source§

type Rejection = !

If the extractor fails, it will use this “rejection” type. Read more
Source§

async fn from_request_parts( parts: &mut Parts, _: &S, ) -> Result<Option<Self>, Infallible>

Perform the extraction.
Source§

impl Viewer for AuthUser

Source§

fn as_user(&self) -> &User

The user the policy is asked about.
Source§

fn before(&self, ability: &str) -> Option<bool>

App::gate_before’s answer, if any.

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> Fake for T

Source§

fn fake<U>(&self) -> U
where Self: FakeBase<U>,

Source§

fn fake_with_rng<U, R>(&self, rng: &mut R) -> U
where R: RngExt + ?Sized, Self: FakeBase<U>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<S, T> FromRequest<S, ViaParts> for T
where S: Send + Sync, T: FromRequestParts<S>,

Source§

type Rejection = <T as FromRequestParts<S>>::Rejection

If the extractor fails it’ll use this “rejection” type. A rejection is a kind of error that can be converted into a response.
Source§

fn from_request( req: Request<Body>, state: &S, ) -> impl Future<Output = Result<T, <T as FromRequest<S, ViaParts>>::Rejection>>

Perform the extraction.
Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<P, T> Receiver for P
where P: Deref<Target = T> + ?Sized, T: ?Sized,

Source§

type Target = T

🔬This is a nightly-only experimental API. (arbitrary_self_types)
The target type on which the method may be called.
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more