Skip to main content

Module auth

Module auth 

Source
Expand description

Authenticates panel users and gates panel routes.

Gates panels by default; installs PasswordAuth or a custom Authenticator. Reads the signed-in user through user and require_user. Stores sessions in AuthSession for every authenticator, scoped to the issuing panel.

Structs§

AdminUser
Shipped credential model with unique email, Argon2id PHC hash, display name, and active flag; belongs to no tenant.
Auth
The panel’s authentication configuration (ADR-0013).
AuthSession
Shipped server-side session record: the SHA-256 hash of the client token, the user it authenticates, the panel that signed the user in, and its expiry. The raw token is never stored.
PasswordAuth
Shipped default authenticator: Argon2id verification against AdminUser.

Constants§

LOGIN_FIELD
Form field carrying the login identifier (the shipped default reads it as an email address).
NEXT_FIELD
Hidden form field carrying the validated post-login destination.
PASSWORD_FIELD
Form field carrying the password.
SESSION_LIFETIME
How long a session stays valid: seven days, fixed (ADR-0013).
TENANT_FIELD
Form field carrying the tenant the tenant switch selects.

Traits§

Authenticator
How a panel loads its users (ADR-0013).
PanelUser
A signed-in user, as the panel knows it (ADR-0013).

Functions§

enforced
Whether the request’s panel requires a signed-in user.
guard
Require a signed-in user when the request’s panel requires sign-in.
hash_password
Hashes a password with Argon2id into a PHC string for storage; never stores the plaintext.
membership
The signed-in user’s membership the request acts under: the tenant the session selected while it is still one of the user’s tenants, else the first. None without a signed-in user, for a user with no tenant, and when a Tenant override names a tenant the user is not a member of.
require_user
Require the signed-in user, as the app’s own user type.
revoke_sessions_for_user
Revokes every live session of user_id for the current panel, or on every panel outside any panel; call it whenever a credential changes.
signed_in
Whether a user is signed in to the request’s panel.
user
The signed-in user, as the app’s own user type.
verify_password
Verifies a password against an Argon2id PHC hash, or None for an unknown account; unknown accounts verify against a dummy hash so response times do not reveal which accounts exist.