Skip to main content

SessionCredential

Struct SessionCredential 

Source
pub struct SessionCredential { /* private fields */ }
Expand description

Authentication state whose lifetime is exactly one session.

A “session” is whatever the embedder binds this to — an accepted TCP connection, a TLS session, an HTTP/2 stream. This crate deliberately does not know: binding it is transport-specific, and the mechanism is not.

What this is for. Verifying a credential costs real work — on one machine ~800 ns for an HMAC-backed scheme, against ~107 ns for an entire quota admission. Left per-request it dominates everything the rest of the stack does. Doing it once per session and comparing thereafter brings the per-request cost to ~16 ns.

What it must never become. A cached credential proves identity, never authorization. A hit skips the verifier and nothing else: the caller still runs admission against the current snapshot, so status, staleness, permissions, rate and quota are decided fresh every request. Revocation stays bounded by snapshot refresh exactly as it is without this cache.

A cached answer is also bounded by whatever validity the verifier attached to it (Verified::reusable_until), so an expiring scheme — PASETO, JWT, a client certificate — does not get to outlive its own expiry just because the session stayed open.

Clones share one slot, so concurrent requests on a multiplexed session authenticate independently without a lock.

Implementations§

Source§

impl SessionCredential

Source

pub fn new() -> Self

An empty cache. Give each session its own.

Source

pub fn authenticate<V: CredentialVerifier + ?Sized>( &self, credential: Option<&[u8]>, verifier: &V, now: Timestamp, ) -> Option<Principal>

Resolve credential to a Principal as of now, verifying it only when this session has not already verified exactly these bytes, or when the previous answer is no longer reusable.

credential is the credential itself, with any transport framing already removed — the Bearer prefix, the header name, the cookie attributes. Pass the same bytes you would pass to CredentialVerifier::verify; this compares and verifies the same slice, so there is no second value to fall out of step with it.

now is supplied by the caller rather than read here, because this runs on the request path and the request path does not read clocks (INVARIANTS.md GL-5).

None means the session presented nothing, and clears any prior proof.

The ordering below is load bearing: a credential that does not match the cached one invalidates the cache before its replacement is verified, so a failed verification can never leave the previous principal reusable. Failed verification is never cached.

Source

pub fn is_authenticated(&self) -> bool

Whether this session currently holds a verified credential. For tests and diagnostics; the credential itself is never exposed.

Trait Implementations§

Source§

impl Clone for SessionCredential

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for SessionCredential

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for SessionCredential

Source§

fn default() -> Self

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.