pub struct JwtClaims {Show 20 fields
pub sub: String,
pub iat: i64,
pub exp: i64,
pub nbf: Option<i64>,
pub iss: String,
pub aud: Vec<JwtAudience>,
pub jti: String,
pub scope: Vec<Permission>,
pub username: String,
pub email: String,
pub user_type: UserType,
pub roles: Vec<String>,
pub attributes: BTreeMap<String, Value>,
pub client_id: Option<ClientId>,
pub token_type: TokenType,
pub auth_time: i64,
pub session_id: Option<SessionId>,
pub rate_limit_tier: Option<RateLimitTier>,
pub plugin_id: Option<String>,
pub act: Option<ActClaim>,
}Expand description
Self-issued JWT claim shape.
Fields are grouped by who consumes them downstream. The platform runs
authorization in three layers (see internal/guides/authz.md); each
attribute field below is the transport for one of those layers. Do not
delete a field without first removing its readers.
Fields§
§sub: String§iat: i64§exp: i64§nbf: Option<i64>§iss: String§aud: Vec<JwtAudience>§jti: String§scope: Vec<Permission>PBAC scope: the Permission set this principal is granted. Enforced
at every route via with_auth(scope); the first element is the
privilege level used by UserType::from_permissions.
username: String§email: String§user_type: UserType§roles: Vec<String>RBAC attribute: role strings minted from the user row at OAuth
issuance. Consumed by authz::resolver::resolve for the core RBAC
check against access_control_rules (rule_type = role) and
forwarded into every AuthzDecisionHook::evaluate call. The only
first-class identity vector core inspects; everything else is
extension-defined via attributes.
attributes: BTreeMap<String, Value>Opaque ABAC attribute bag. The token issuer mints whatever
namespaced facts the extension authz hook needs (e.g.
"acme.desk": "fixed-income", "boeing.clearance": "ts/sci").
Core never interprets values — keys SHOULD be dotted-namespaced.
Forwarded verbatim into AuthzRequest.attributes.
client_id: Option<ClientId>§token_type: TokenType§auth_time: i64§session_id: Option<SessionId>§rate_limit_tier: Option<RateLimitTier>Rate-limit attribute: minted from UserType::rate_tier so the tier is
committed at issuance rather than re-derived per request. Read at the
rate-limit middleware via RequestContext::rate_limit_tier().
plugin_id: Option<String>Hook attribute: the plugin id this token was minted for. Validated by
the hook-token validator in systemprompt_security::auth::hook_token —
a hook request whose plugin_id claim disagrees with the URL path’s
plugin_id is rejected.
act: Option<ActClaim>Implementations§
Source§impl JwtClaims
impl JwtClaims
pub fn has_permission(&self, permission: Permission) -> bool
pub fn permissions(&self) -> &[Permission]
pub fn get_permissions(&self) -> Vec<Permission>
pub fn get_scopes(&self) -> Vec<String>
pub fn is_admin(&self) -> bool
pub fn is_registered_user(&self) -> bool
pub fn is_anonymous(&self) -> bool
pub fn has_audience(&self, aud: &JwtAudience) -> bool
pub fn has_role(&self, role: &str) -> bool
pub fn roles(&self) -> &[String]
Trait Implementations§
Source§impl<'de> Deserialize<'de> for JwtClaims
impl<'de> Deserialize<'de> for JwtClaims
Source§fn deserialize<__D>(
__deserializer: __D,
) -> Result<JwtClaims, <__D as Deserializer<'de>>::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(
__deserializer: __D,
) -> Result<JwtClaims, <__D as Deserializer<'de>>::Error>where
__D: Deserializer<'de>,
Source§impl Serialize for JwtClaims
impl Serialize for JwtClaims
Source§fn serialize<__S>(
&self,
__serializer: __S,
) -> Result<<__S as Serializer>::Ok, <__S as Serializer>::Error>where
__S: Serializer,
fn serialize<__S>(
&self,
__serializer: __S,
) -> Result<<__S as Serializer>::Ok, <__S as Serializer>::Error>where
__S: Serializer,
Auto Trait Implementations§
impl Freeze for JwtClaims
impl RefUnwindSafe for JwtClaims
impl Send for JwtClaims
impl Sync for JwtClaims
impl Unpin for JwtClaims
impl UnsafeUnpin for JwtClaims
impl UnwindSafe for JwtClaims
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> DeserializeOwned for Twhere
T: for<'de> Deserialize<'de>,
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more