Skip to main content

ProviderRegistry

Struct ProviderRegistry 

pub struct ProviderRegistry { /* private fields */ }
Expand description

The configured set of providers, consulted in order. Default-deny: if no provider accepts-and-authenticates the credential, the outcome is AuthOutcome::Denied. An empty registry rejects everything.

Implementations§

Source§

impl ProviderRegistry

Source

pub fn new() -> Self

Source

pub fn register(&mut self, provider: Arc<dyn AuthProvider>)

Register a provider (boot-time wiring).

Source

pub fn is_empty(&self) -> bool

true if no provider is configured (default-deny will reject all).

Source

pub fn advertised_methods(&self) -> Vec<AuthMethod>

The methods this registry advertises (for the handshake authMethods).

Source

pub fn names(&self) -> Vec<&str>

The configured provider names, in registration order — the enumeration surface exposes over RPC (no hardcoded provider lists).

Source

pub async fn resolve(&self, credential: &Credential) -> AuthOutcome

Resolve a presented credential to an AuthOutcome, default-deny and authoritative-deny.

The first accepting provider that authenticates wins. The key safety rule: a provider that accepts a credential but rejects it with a specific DenyReason (anything other than the generic DenyReason::BadCredential — e.g. DenyReason::MfaRequired, DenyReason::TokenExpired, DenyReason::Misconfigured, DenyReason::AliasNotEntitled) is authoritative: that outcome is returned immediately so a later, more broadly-accepting provider can NOT authenticate the same presented credential past it (e.g. an OIDC provider returning MfaRequired for a bearer token can’t be bypassed by a later catch-all bearer provider). Only the generic BadCredential (“not my credential / wrong secret”) lets the registry fall through to the next accepting provider. None is denied before any provider runs. An empty registry denies everything.

Trait Implementations§

Source§

impl Default for ProviderRegistry

Source§

fn default() -> ProviderRegistry

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> PolicyExt for T
where T: ?Sized,

§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] only if self and other return Action::Follow. Read more
§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns [Action::Follow] if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,