Skip to main content

RbacConfig

Struct RbacConfig 

Source
#[non_exhaustive]
pub struct RbacConfig { pub enabled: bool, pub roles: Vec<RoleConfig>, pub allow_operation_matching: AllowOperationMatching, pub global_deny: Vec<String>, pub redaction_salt: Option<SecretString>, }
Expand description

Top-level RBAC configuration (deserializable from TOML).

Fields (Non-exhaustive)§

This struct is marked as non-exhaustive
Non-exhaustive structs could have additional fields added in future. Therefore, non-exhaustive structs cannot be constructed in external crates using the traditional Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.
§enabled: bool

Master switch – when false, the RBAC middleware is not installed.

§roles: Vec<RoleConfig>

Role definitions available to identities.

§allow_operation_matching: AllowOperationMatching

How RoleConfig::allow entries are matched. Defaults to AllowOperationMatching::Legacy (exact match) so that enabling glob support is always a deliberate operator decision.

§global_deny: Vec<String>

Server-wide operation kill switch, evaluated before any role is consulted and applied regardless of what a role’s allow grants – including allow = ["*"].

Entries are always glob-matched, independent of RbacConfig::allow_operation_matching. This list can only ever remove capability, never add it.

Two scope limits apply. It is gated on RbacConfig::enabled: when RBAC is disabled every check short-circuits to RbacDecision::Allow before the kill switch is consulted. And it governs invocation only – like the rest of this engine it is enforced on tools/call, so a denied tool may still appear in a tools/list response unless the handler filters it.

§redaction_salt: Option<SecretString>

Optional stable HMAC key (any length) used to redact argument values in deny logs. When set, redacted hashes are stable across process restarts (useful for log correlation across deploys). When None, a random 32-byte key is generated per process at first use; redacted hashes change every restart.

The key is wrapped in SecretString so it never leaks via Debug/Display/serde and is zeroized on drop.

Implementations§

Source§

impl RbacConfig

Source

pub fn with_roles(roles: Vec<RoleConfig>) -> Self

Create an enabled RBAC config with the given roles.

Source

pub fn with_global_deny(self, global_deny: Vec<String>) -> Self

Set the server-wide operation kill switch. Entries are glob-matched.

Source

pub fn with_allow_operation_matching(self, mode: AllowOperationMatching) -> Self

Opt into glob matching for RoleConfig::allow entries.

Source§

impl RbacConfig

Source

pub fn apply_env_overrides( &mut self, ) -> Result<Vec<EnvOverride>, RmcpServerKitError>

Applies RMCP_SERVER_KIT__RBAC__* environment overrides.

Supports direct redaction_salt and _FILE secret indirection. Report entries for the secret target always redact the value. File-based secrets are treated as text: exactly one terminal line ending is removed (\r\n, \n, or \r) while other whitespace is preserved.

§Errors

Returns RmcpServerKitError::Config when both direct and file-based salt variables are set or when the _FILE target cannot be read.

§Examples

The full config-file pipeline lives in examples/config_file_server.rs.

use rmcp_server_kit::rbac::RbacConfig;

let mut rbac = RbacConfig::default();
// Do not set process env in doctests: rustdoc examples share a process.
let report = rbac.apply_env_overrides()?;
let _secret_targets: Vec<&str> = report
    .iter()
    .filter(|entry| entry.value.is_none())
    .map(|entry| entry.target_field.as_str())
    .collect();

Trait Implementations§

Source§

impl Clone for RbacConfig

Source§

fn clone(&self) -> RbacConfig

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for RbacConfig

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for RbacConfig

Source§

fn default() -> RbacConfig

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for RbacConfig

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<'a, T, E> AsTaggedExplicit<'a, E> for T
where T: 'a,

Source§

fn explicit(self, class: Class, tag: u32) -> TaggedParser<'a, Explicit, Self, E>

Source§

impl<'a, T, E> AsTaggedImplicit<'a, E> for T
where T: 'a,

Source§

fn implicit( self, class: Class, constructed: bool, tag: u32, ) -> TaggedParser<'a, Implicit, Self, E>

Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more