Skip to main content

Authenticator

Struct Authenticator 

Source
pub struct Authenticator { /* private fields */ }
Expand description

A server that issues digest challenges and checks the answers.

Nonces are self-describing: each carries its issue time and a MAC over it, so this can recognise its own nonce and read its expiry without a table of every nonce ever issued. The only table is the replay window, which is bounded and holds nothing that has not been used.

Implementations§

Source§

impl Authenticator

Source

pub fn new(realm: impl Into<String>, secret: [u8; 32]) -> Self

A server for a protection space.

secret keys the nonce MAC. It must be stable across restarts if in-flight nonces are to survive one, and not shared with another realm, or a nonce issued for one protection space is accepted in the other.

Source

pub fn with_random_secret(realm: impl Into<String>) -> Self

A server with a freshly generated secret.

Convenient, and it means every restart invalidates every outstanding nonce — which clients recover from with stale=true, so it costs a round trip and not a login.

Source

pub fn with_algorithm(self, algorithm: Algorithm) -> Self

Challenge with this algorithm.

SHA-256 by default rather than MD5. RFC 8760 §2 exists because MD5 should not be the only thing on offer, and a server choosing the default is the only place that choice can be made — a client can only answer what it is asked.

Source

pub fn with_lifetime(self, lifetime: Duration) -> Self

How long an issued nonce stays valid.

Source

pub fn realm(&self) -> &str

The protection space.

Source

pub fn challenge_header(proxy: bool) -> HeaderName

The header a challenge goes in: WWW-Authenticate, or Proxy-Authenticate for a proxy.

Source

pub fn challenge(&self, stale: bool) -> String

Mint a challenge value, as it goes in the header.

stale says the previous credentials were right and only the nonce was old.

Source

pub fn challenge_at(&self, stale: bool, now: u64) -> String

Authenticator::challenge with the clock supplied, so a test can pin it.

Source

pub fn verify( &mut self, presented: &Presented, method: &str, password: &str, ) -> Verdict

Check the credentials a request presented.

password is the one this server holds for presented.username; looking it up is the caller’s job, because a credential store is not this crate’s business. method is the request’s, since the digest covers it.

Source

pub fn verify_at( &mut self, presented: &Presented, method: &str, password: &str, now: u64, ) -> Verdict

Authenticator::verify with the clock supplied.

Trait Implementations§

Source§

impl Debug for Authenticator

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

§

impl<T> Instrument for T

§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided [Span], returning an Instrumented wrapper. Read more
§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> IntoEither for T

Source§

fn into_either(self, into_left: bool) -> Either<Self, Self>

Converts self into a Left variant of Either<Self, Self> if into_left is true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
Source§

fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
where F: FnOnce(&Self) -> bool,

Converts self into a Left variant of Either<Self, Self> if into_left(&self) returns true. Converts self into a Right variant of Either<Self, Self> otherwise. Read more
§

impl<T> Pointable for T

§

const ALIGN: usize

The alignment of pointer.
§

type Init = T

The type for initializers.
§

unsafe fn init(init: <T as Pointable>::Init) -> usize

Initializes a with the given initializer. Read more
§

unsafe fn deref<'a>(ptr: usize) -> &'a T

Dereferences the given pointer. Read more
§

unsafe fn deref_mut<'a>(ptr: usize) -> &'a mut T

Mutably dereferences the given pointer. Read more
§

unsafe fn drop(ptr: usize)

Drops the object pointed to by the given pointer. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

§

fn vzip(self) -> V

§

impl<T> WithSubscriber for T

§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a [WithDispatch] wrapper. Read more
§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,