Skip to main content

Authenticator

Trait Authenticator 

Source
pub trait Authenticator:
    Send
    + Sync
    + 'static {
    type User: PanelUser;

    // Required methods
    fn verify(
        &self,
        cx: &Cx,
        login: &str,
        password: &str,
    ) -> impl Future<Output = Result<Option<Self::User>>> + Send;
    fn find_by_id(
        &self,
        cx: &Cx,
        id: &str,
    ) -> impl Future<Output = Result<Option<Self::User>>> + Send;
}
Expand description

How a panel loads its users (ADR-0013).

The default PasswordAuth implements it against the shipped AdminUser model; an app with an existing user table implements it and passes the value to Panel::auth via Auth::custom. Sessions are the framework’s, so an implementation only maps credentials to a user and a stored id back to one.

Every credential failure must return Ok(None), never a distinguishable error: the login response is one generic message for all of them. An infrastructure failure is not a credential verdict, so an implementation that cannot reach its store returns the driver’s error instead — the login handler maps it to the opaque outage page, which keeps a database outage from rendering as a rejected password. An implementation’s own error keeps its own mapping.

Required Associated Types§

Source

type User: PanelUser

The app’s user type.

Required Methods§

Source

fn verify( &self, cx: &Cx, login: &str, password: &str, ) -> impl Future<Output = Result<Option<Self::User>>> + Send

Verify login/password, returning the user on success.

Implementations must run comparable work for unknown accounts so timing does not leak account existence; verify_password does, given None for an unknown account.

Source

fn find_by_id( &self, cx: &Cx, id: &str, ) -> impl Future<Output = Result<Option<Self::User>>> + Send

Load the session’s user by PanelUser::user_id, with everything the request reads from it — its tenants included.

It runs on every request, which is what makes deactivation, revocation and a removed membership take effect immediately; return None when the user no longer authenticates.

Dyn Compatibility§

This trait is not dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementors§