pub struct RbacAuthorizer { /* private fields */ }Expand description
Role-based authorizer backed by a role -> permissions map.
支持角色层级继承(v0.2.3 新增):通过 with_role_parent 配置父角色后,
子角色自动继承父角色的所有权限。继承链支持多级(如 admin -> editor -> viewer),
并自动检测循环引用。
Implementations§
Source§impl RbacAuthorizer
impl RbacAuthorizer
Sourcepub fn new() -> RbacAuthorizer
pub fn new() -> RbacAuthorizer
Creates a new authorizer with the admin role granted the * wildcard.
Sourcepub fn with_role_permission(
self,
role: &str,
permission: &str,
) -> RbacAuthorizer
pub fn with_role_permission( self, role: &str, permission: &str, ) -> RbacAuthorizer
Grants permission to role. Returns self for chaining.
Sourcepub fn with_role_parent(self, role: &str, parent: &str) -> RbacAuthorizer
pub fn with_role_parent(self, role: &str, parent: &str) -> RbacAuthorizer
配置角色的父角色(继承关系),返回 self 用于链式调用。
子角色将继承父角色的全部权限。支持多级继承(如 editor -> viewer, admin -> editor),查询时会沿继承链递归向上查找。
§循环检测
如果配置后形成循环(如 A -> B -> A),此方法会忽略该配置并发出警告, 不会 panic。
Sourcepub fn revoke(&mut self, role: &str, permission: &str)
pub fn revoke(&mut self, role: &str, permission: &str)
Revokes permission from role if present.
Sourcepub fn role_parent(&self, role: &str) -> Option<&str>
pub fn role_parent(&self, role: &str) -> Option<&str>
返回角色的父角色(如果有)。
用于查询角色继承关系。
Sourcepub fn role_ancestors(&self, role: &str) -> Vec<String>
pub fn role_ancestors(&self, role: &str) -> Vec<String>
返回角色的所有祖先角色(沿继承链向上,包括自身)。
例如继承链 admin -> editor -> viewer,则 ancestors("admin")
返回 ["admin", "editor", "viewer"]。
Sourcepub fn role_has_permission(&self, role: &str, permission: &str) -> bool
pub fn role_has_permission(&self, role: &str, permission: &str) -> bool
Returns true if role has been granted permission (or the wildcard),
including permissions inherited from parent roles.
Sourcepub fn permissions_for_role(&self, role: &str) -> Vec<String>
pub fn permissions_for_role(&self, role: &str) -> Vec<String>
Returns all permissions currently attached to role (excluding inherited).
Sourcepub fn effective_permissions_for_role(&self, role: &str) -> Vec<String>
pub fn effective_permissions_for_role(&self, role: &str) -> Vec<String>
Returns all effective permissions for role, including inherited from ancestors.
v0.2.3 新增:沿继承链收集所有祖先角色的权限并合并去重。
Trait Implementations§
Source§impl Authorizer for RbacAuthorizer
impl Authorizer for RbacAuthorizer
Source§impl Default for RbacAuthorizer
impl Default for RbacAuthorizer
Source§fn default() -> RbacAuthorizer
fn default() -> RbacAuthorizer
Auto Trait Implementations§
impl Freeze for RbacAuthorizer
impl RefUnwindSafe for RbacAuthorizer
impl Send for RbacAuthorizer
impl Sync for RbacAuthorizer
impl Unpin for RbacAuthorizer
impl UnsafeUnpin for RbacAuthorizer
impl UnwindSafe for RbacAuthorizer
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more