Skip to main content

UserStore

Struct UserStore 

Source
pub struct UserStore { /* private fields */ }

Implementations§

Source§

impl UserStore

Source

pub fn new() -> Self

Source

pub fn len(&self) -> usize

Source

pub fn is_empty(&self) -> bool

Source

pub fn contains(&self, name: &str) -> bool

Source

pub fn get(&self, name: &str) -> Option<&UserRecord>

Stable iteration in name order — used by SHOW USERS and the snapshot writer. v7.17.0 Phase 3.P0-71: look up a user by name. Returns None for unknown names; the caller decides whether to surface “Access Denied” or “User not found” (the MySQL-wire shim picks the former to avoid leaking user existence to unauthenticated clients).

Source

pub fn iter(&self) -> impl Iterator<Item = (&str, &UserRecord)>

Source

pub fn create( &mut self, name: &str, password: &str, role: Role, salt: [u8; 16], ) -> Result<(), UserError>

Source

pub fn set_attributes( &mut self, name: &str, can_login: bool, inherit: bool, superuser: bool, )

v7.39 (read01 round 58) — set the PG role attributes on a freshly created role. CREATE ROLE (no LOGIN) lands here right after create.

Source

pub fn set_password_declared(&mut self, name: &str, declared: bool)

v7.39 (round 548) — record whether the caller actually declared a password (see UserRecord::password_declared).

Source

pub fn add_member(&mut self, role: &str, member: &str)

v7.39 (read01 round 58) — GRANT <role> TO <member>.

Source

pub fn drop_member(&mut self, role: &str, member: &str)

v7.39 (read01 round 58) — REVOKE <role> FROM <member>.

Source

pub fn memberships_of_transitive(&self, member: &str) -> BTreeSet<String>

The roles member directly belongs to. v7.39 (round 202) — transitive role membership closure (PG role inheritance: a policy TO grp applies to a member of grp, including through nested grants). BFS with a seen-set so a grant cycle can’t loop. Names are stored as given; the caller compares case-insensitively.

Source

pub fn memberships_of(&self, member: &str) -> Vec<String>

Source

pub fn all_memberships(&self) -> impl Iterator<Item = (&str, &str)>

Every (member, role) pair — pg_auth_members.

Source

pub fn effective_roles(&self, role: &str) -> BTreeSet<String>

v7.39 (read01 round 58) — every role whose privileges role effectively holds: itself, plus (transitively) every role it INHERITs from. A NOINHERIT role holds only its own — it must SET ROLE to the others. Cycles cannot happen (PG rejects them) but the visited set guards anyway.

Source

pub fn drop(&mut self, name: &str) -> Result<(), UserError>

Source

pub fn set_password( &mut self, name: &str, password: Option<&str>, salt: [u8; 16], ) -> Result<(), UserError>

v4.8: attach SCRAM-SHA-256 verifier to an existing user. Called by the engine right after create so new users have both auth paths (legacy BLAKE3 + SCRAM) available. The salt here is independent of the BLAKE3 hash salt — they serve different purposes. v7.39 (round 750) — rotate a role’s credential in place: every derived form (legacy hash, both MySQL hashes) re-derives from the new password; the caller re-derives SCRAM separately (it owns the salt source). None = PASSWORD NULL: the credential clears — the record keeps existing but nothing verifies.

Source

pub fn enable_scram( &mut self, name: &str, password: &str, salt: [u8; 16], iters: u32, ) -> Result<(), UserError>

Source

pub fn verify(&self, name: &str, password: &str) -> Option<Role>

Trait Implementations§

Source§

impl Clone for UserStore

Source§

fn clone(&self) -> UserStore

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for UserStore

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for UserStore

Source§

fn default() -> UserStore

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> ErasedDestructor for T
where T: 'static,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.