pub struct RbacAuthorizer { /* private fields */ }Expand description
Role-based authorizer backed by a role -> permissions map.
支持角色层级继承(v0.2.3 新增):通过 with_role_parent 配置父角色后,
子角色自动继承父角色的所有权限。继承链支持多级(如 admin -> editor -> viewer),
并自动检测循环引用。
Implementations§
Source§impl RbacAuthorizer
impl RbacAuthorizer
Sourcepub fn with_role_permission(self, role: &str, permission: &str) -> Self
pub fn with_role_permission(self, role: &str, permission: &str) -> Self
Grants permission to role. Returns self for chaining.
Sourcepub fn with_role_parent(self, role: &str, parent: &str) -> Self
pub fn with_role_parent(self, role: &str, parent: &str) -> Self
配置角色的父角色(继承关系),返回 self 用于链式调用。
子角色将继承父角色的全部权限。支持多级继承(如 editor -> viewer, admin -> editor),查询时会沿继承链递归向上查找。
§循环检测
如果配置后形成循环(如 A -> B -> A),此方法会忽略该配置并发出警告, 不会 panic。
Sourcepub fn revoke(&mut self, role: &str, permission: &str)
pub fn revoke(&mut self, role: &str, permission: &str)
Revokes permission from role if present.
Sourcepub fn role_parent(&self, role: &str) -> Option<&str>
pub fn role_parent(&self, role: &str) -> Option<&str>
返回角色的父角色(如果有)。
用于查询角色继承关系。
Sourcepub fn role_ancestors(&self, role: &str) -> Vec<String>
pub fn role_ancestors(&self, role: &str) -> Vec<String>
返回角色的所有祖先角色(沿继承链向上,包括自身)。
例如继承链 admin -> editor -> viewer,则 ancestors("admin")
返回 ["admin", "editor", "viewer"]。
Sourcepub fn role_has_permission(&self, role: &str, permission: &str) -> bool
pub fn role_has_permission(&self, role: &str, permission: &str) -> bool
Returns true if role has been granted permission (or the wildcard),
including permissions inherited from parent roles.
Sourcepub fn permissions_for_role(&self, role: &str) -> Vec<String>
pub fn permissions_for_role(&self, role: &str) -> Vec<String>
Returns all permissions currently attached to role (excluding inherited).
Sourcepub fn effective_permissions_for_role(&self, role: &str) -> Vec<String>
pub fn effective_permissions_for_role(&self, role: &str) -> Vec<String>
Returns all effective permissions for role, including inherited from ancestors.
v0.2.3 新增:沿继承链收集所有祖先角色的权限并合并去重。