Expand description
Authenticates panel users and gates panel routes.
Gates panels by default; installs PasswordAuth or a custom Authenticator.
Reads the signed-in user through user and require_user. Stores sessions in
AuthSession for every authenticator, scoped to the issuing panel.
Structs§
- Admin
User - Shipped credential model with unique email, Argon2id PHC hash, display name, and active flag; belongs to no tenant.
- Auth
- The panel’s authentication configuration (ADR-0013).
- Auth
Session - Shipped server-side session record: the SHA-256 hash of the client token, the user it authenticates, the panel that signed the user in, and its expiry. The raw token is never stored.
- Password
Auth - Shipped default authenticator: Argon2id verification against
AdminUser.
Constants§
- LOGIN_
FIELD - Form field carrying the login identifier (the shipped default reads it as an email address).
- NEXT_
FIELD - Hidden form field carrying the validated post-login destination.
- PASSWORD_
FIELD - Form field carrying the password.
- SESSION_
LIFETIME - How long a session stays valid: seven days, fixed (ADR-0013).
- TENANT_
FIELD - Form field carrying the tenant the tenant switch selects.
Traits§
- Authenticator
- How a panel loads its users (ADR-0013).
- Panel
User - A signed-in user, as the panel knows it (ADR-0013).
Functions§
- enforced
- Whether the request’s panel requires a signed-in user.
- guard
- Require a signed-in user when the request’s panel requires sign-in.
- hash_
password - Hashes a password with Argon2id into a PHC string for storage; never stores the plaintext.
- membership
- The signed-in user’s membership the request acts under: the tenant the
session selected while it is still one of the user’s
tenants, else the first.Nonewithout a signed-in user, for a user with no tenant, and when aTenantoverride names a tenant the user is not a member of. - require_
user - Require the signed-in user, as the app’s own user type.
- revoke_
sessions_ for_ user - Revokes every live session of
user_idfor the current panel, or on every panel outside any panel; call it whenever a credential changes. - signed_
in - Whether a user is signed in to the request’s panel.
- user
- The signed-in user, as the app’s own user type.
- verify_
password - Verifies a password against an Argon2id PHC hash, or
Nonefor an unknown account; unknown accounts verify against a dummy hash so response times do not reveal which accounts exist.