pub struct SecurityPolicy { /* private fields */ }Expand description
An immutable, validated mapping. Publish verification and authorization together; rotating one without the other would temporarily assign old credentials new roles.
Implementations§
Source§impl SecurityPolicy
impl SecurityPolicy
Sourcepub fn with_bearer(
self,
verifier: Arc<dyn CredentialVerifier + Send + Sync>,
identities: impl IntoIterator<Item = (Principal, ControlIdentity)>,
) -> Result<Self, SecurityError>
pub fn with_bearer( self, verifier: Arc<dyn CredentialVerifier + Send + Sync>, identities: impl IntoIterator<Item = (Principal, ControlIdentity)>, ) -> Result<Self, SecurityError>
Adds a bearer scheme: verifier authenticates the presented token,
and identities maps each principal it verifies as to an identity.
A request’s bearer token is offered to every scheme. It is refused
with 401 if no scheme verifies it, if a verifying scheme’s evidence
is no longer reusable at the server’s current time, or if two schemes
resolve it to different identities. A verified principal with no
mapping in its scheme is refused with 403 (INVARIANTS.md 32).
§Errors
Returns a SecurityError if identities names a principal twice.
Sourcepub fn with_certificate(
self,
fingerprint: [u8; 32],
identity: ControlIdentity,
) -> Result<Self, SecurityError>
pub fn with_certificate( self, fingerprint: [u8; 32], identity: ControlIdentity, ) -> Result<Self, SecurityError>
The SHA-256 fingerprint of the leaf DER certificate, verified by TLS.