Skip to main content

RbacAuthorizer

Struct RbacAuthorizer 

Source
pub struct RbacAuthorizer { /* private fields */ }
Expand description

Role-based authorizer backed by a role -> permissions map.

支持角色层级继承(v0.2.3 新增):通过 with_role_parent 配置父角色后, 子角色自动继承父角色的所有权限。继承链支持多级(如 admin -> editor -> viewer), 并自动检测循环引用。

Implementations§

Source§

impl RbacAuthorizer

Source

pub fn new() -> Self

Creates a new authorizer with the admin role granted the * wildcard.

Source

pub fn with_role_permission(self, role: &str, permission: &str) -> Self

Grants permission to role. Returns self for chaining.

Source

pub fn with_role_parent(self, role: &str, parent: &str) -> Self

配置角色的父角色(继承关系),返回 self 用于链式调用。

子角色将继承父角色的全部权限。支持多级继承(如 editor -> viewer, admin -> editor),查询时会沿继承链递归向上查找。

§循环检测

如果配置后形成循环(如 A -> B -> A),此方法会忽略该配置并发出警告, 不会 panic。

Source

pub fn grant(&mut self, role: &str, permission: &str)

Grants permission to role in place.

Source

pub fn revoke(&mut self, role: &str, permission: &str)

Revokes permission from role if present.

Source

pub fn role_parent(&self, role: &str) -> Option<&str>

返回角色的父角色(如果有)。

用于查询角色继承关系。

Source

pub fn role_ancestors(&self, role: &str) -> Vec<String>

返回角色的所有祖先角色(沿继承链向上,包括自身)。

例如继承链 admin -> editor -> viewer,则 ancestors("admin") 返回 ["admin", "editor", "viewer"]

Source

pub fn role_has_permission(&self, role: &str, permission: &str) -> bool

Returns true if role has been granted permission (or the wildcard), including permissions inherited from parent roles.

Source

pub fn permissions_for_role(&self, role: &str) -> Vec<String>

Returns all permissions currently attached to role (excluding inherited).

Source

pub fn effective_permissions_for_role(&self, role: &str) -> Vec<String>

Returns all effective permissions for role, including inherited from ancestors.

v0.2.3 新增:沿继承链收集所有祖先角色的权限并合并去重。

Trait Implementations§

Source§

impl Authorizer for RbacAuthorizer

Source§

fn can( &self, user: &User, action: &str, resource: &str, ) -> Result<bool, AuthError>

Returns Ok(true) if user is allowed to perform action on resource.
Source§

impl Default for RbacAuthorizer

Source§

fn default() -> Self

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V