pub struct UserStore { /* private fields */ }Implementations§
Source§impl UserStore
impl UserStore
pub fn new() -> Self
pub fn len(&self) -> usize
pub fn is_empty(&self) -> bool
pub fn contains(&self, name: &str) -> bool
Sourcepub fn get(&self, name: &str) -> Option<&UserRecord>
pub fn get(&self, name: &str) -> Option<&UserRecord>
Stable iteration in name order — used by SHOW USERS and the
snapshot writer.
v7.17.0 Phase 3.P0-71: look up a user by name. Returns
None for unknown names; the caller decides whether to
surface “Access Denied” or “User not found” (the
MySQL-wire shim picks the former to avoid leaking user
existence to unauthenticated clients).
pub fn iter(&self) -> impl Iterator<Item = (&str, &UserRecord)>
pub fn create( &mut self, name: &str, password: &str, role: Role, salt: [u8; 16], ) -> Result<(), UserError>
Sourcepub fn set_attributes(
&mut self,
name: &str,
can_login: bool,
inherit: bool,
superuser: bool,
)
pub fn set_attributes( &mut self, name: &str, can_login: bool, inherit: bool, superuser: bool, )
v7.39 (read01 round 58) — set the PG role attributes on a freshly
created role. CREATE ROLE (no LOGIN) lands here right after create.
Sourcepub fn set_password_declared(&mut self, name: &str, declared: bool)
pub fn set_password_declared(&mut self, name: &str, declared: bool)
v7.39 (round 548) — record whether the caller actually declared
a password (see UserRecord::password_declared).
Sourcepub fn add_member(&mut self, role: &str, member: &str)
pub fn add_member(&mut self, role: &str, member: &str)
v7.39 (read01 round 58) — GRANT <role> TO <member>.
Sourcepub fn drop_member(&mut self, role: &str, member: &str)
pub fn drop_member(&mut self, role: &str, member: &str)
v7.39 (read01 round 58) — REVOKE <role> FROM <member>.
Sourcepub fn memberships_of_transitive(&self, member: &str) -> BTreeSet<String>
pub fn memberships_of_transitive(&self, member: &str) -> BTreeSet<String>
The roles member directly belongs to.
v7.39 (round 202) — transitive role membership closure (PG
role inheritance: a policy TO grp applies to a member of
grp, including through nested grants). BFS with a seen-set
so a grant cycle can’t loop. Names are stored as given; the
caller compares case-insensitively.
pub fn memberships_of(&self, member: &str) -> Vec<String>
Sourcepub fn all_memberships(&self) -> impl Iterator<Item = (&str, &str)>
pub fn all_memberships(&self) -> impl Iterator<Item = (&str, &str)>
Every (member, role) pair — pg_auth_members.
Sourcepub fn effective_roles(&self, role: &str) -> BTreeSet<String>
pub fn effective_roles(&self, role: &str) -> BTreeSet<String>
v7.39 (read01 round 58) — every role whose privileges role effectively
holds: itself, plus (transitively) every role it INHERITs from. A
NOINHERIT role holds only its own — it must SET ROLE to the others.
Cycles cannot happen (PG rejects them) but the visited set guards anyway.
pub fn drop(&mut self, name: &str) -> Result<(), UserError>
Sourcepub fn set_password(
&mut self,
name: &str,
password: Option<&str>,
salt: [u8; 16],
) -> Result<(), UserError>
pub fn set_password( &mut self, name: &str, password: Option<&str>, salt: [u8; 16], ) -> Result<(), UserError>
v4.8: attach SCRAM-SHA-256 verifier to an existing user.
Called by the engine right after create so new users have
both auth paths (legacy BLAKE3 + SCRAM) available. The salt
here is independent of the BLAKE3 hash salt — they serve
different purposes.
v7.39 (round 750) — rotate a role’s credential in place: every
derived form (legacy hash, both MySQL hashes) re-derives from
the new password; the caller re-derives SCRAM separately (it
owns the salt source). None = PASSWORD NULL: the credential
clears — the record keeps existing but nothing verifies.