calternal-auth
Authentication and session authority for a calternal instance
Instance authentication authority. Security state lives only in SQLite.
The server mounts router and supplies the same session authority to every client.
Source: crates/calternal-auth/src/lib.rs
Structs
Section titled “Structs”Account
Section titled “Account”pub struct Account;No doc comment.
Implements: ScopeMarker
Source: crates/calternal-auth/src/api.rs:313
pub struct Admin;No doc comment.
Implements: ScopeMarker
Source: crates/calternal-auth/src/api.rs:314
AppPassword
Section titled “AppPassword”pub struct AppPasswordNo doc comment.
Fields
pub id: Uuidpub name: Stringpub created_at: i64pub scopes: Vec<AppPasswordScope>pub home_prefix: Option<String>pub plugin_scope: Option<AppPasswordPluginScope>pub expires_at: Option<i64>pub last_used_at: Option<i64>pub last_used_protocol: Option<AppPasswordProtocol>pub last_used_ip: Option<String>
Implements: Debug, Clone, Serialize, Deserialize, ToSchema
AppPassword::allows
Section titled “AppPassword::allows”pub fn allows(&self, protocol: AppPasswordProtocol, access: AppPasswordAccess) -> boolNo doc comment.
Source: crates/calternal-auth/src/store.rs:510
AppPasswordAuthority
Section titled “AppPasswordAuthority”pub struct AppPasswordAuthorityNo doc comment.
Fields
pub user: Userpub app_password: AppPassword
Implements: Debug, Clone
Source: crates/calternal-auth/src/store.rs:532
AppPasswordCacheChange
Section titled “AppPasswordCacheChange”pub struct AppPasswordCacheChangeHold cache admission closed for an authority transaction. The server uses this guard for deletion transactions owned outside AuthStore (#512, §21).
Implements: Drop
Source: crates/calternal-auth/src/store.rs:564
AppPasswordOptions
Section titled “AppPasswordOptions”pub struct AppPasswordOptionsNo doc comment.
Fields
pub scopes: Vec<AppPasswordScope>pub home_prefix: Option<String>pub plugin_scope: Option<AppPasswordPluginScope>pub expires_at: Option<i64>
Implements: Debug, Clone, PartialEq, Eq, Serialize, Deserialize, ToSchema, Default
AppPasswordOptions::validated
Section titled “AppPasswordOptions::validated”pub fn validated(mut self) -> AuthResult<Self>Validate and canonicalize the metadata before it becomes Security state.
Source: crates/calternal-auth/src/store.rs:405
AppPasswordPluginScope
Section titled “AppPasswordPluginScope”pub struct AppPasswordPluginScopeOptional authority for one Plugin, with an optional stable resource ID.
Fields
pub plugin: Stringpub access: Vec<AppPasswordPluginAccess>pub resource_id: Option<Uuid>
Implements: Debug, Clone, PartialEq, Eq, Serialize, Deserialize, ToSchema
Source: crates/calternal-auth/src/store.rs:398
AppPasswordScope
Section titled “AppPasswordScope”pub struct AppPasswordScopeNo doc comment.
Fields
pub protocol: AppPasswordProtocolpub access: AppPasswordAccess
Implements: Debug, Clone, PartialEq, Eq, Serialize, Deserialize, ToSchema
Source: crates/calternal-auth/src/store.rs:384
AuthConfig
Section titled “AuthConfig”pub struct AuthConfigNo doc comment.
Fields
pub rp_id: Stringpub rp_origin: Stringpub setup_base_url: Stringpub web_idle_secs: i64pub installation_idle_secs: i64pub absolute_secs: i64pub trusted_proxies: Vec<IpNet>pub notes_imap_port: u16: Published implicit-TLS Notes port; defaults to 993 (#428 profiles).pub notes_submission_port: u16: Published implicit-TLS non-sending submission port for Apple validation (#428).
Implements: Clone
AuthConfig::new
Section titled “AuthConfig::new”pub fn new( rp_id: String, rp_origin: String, setup_base_url: String, web_idle_secs: i64, installation_idle_secs: i64, absolute_secs: i64, ) -> SelfTrusted proxies are opt-in. Without them only the TCP peer identifies a client.
AuthConfig::validate
Section titled “AuthConfig::validate”pub fn validate(&self) -> AuthResult<()>Reject non-positive session lifetimes and a setup URL without HTTPS. HTTP is allowed only for loopback hosts so local passkey tests can run in a secure browser context (DESIGN §7; #905).
Source: crates/calternal-auth/src/api.rs:78
AuthState
Section titled “AuthState”pub struct AuthState<S: AuthStore>No doc comment.
Fields
pub store: Spub passkeys: PasskeyService<S>pub config: AuthConfig
Implements: Clone
AuthState::new
Section titled “AuthState::new”pub async fn new( store: S, config: AuthConfig, providers: Vec<OidcProvider<S>>, ) -> AuthResult<Self>Build one Instance authority with a shared ceremony budget, including all discovered providers. Clones share admission and pending state (#737).
AuthState::set_profile_signer
Section titled “AuthState::set_profile_signer”pub async fn set_profile_signer(&self, signer: Option<ProfileSigner>)Replace the in-memory signer after secure startup loading or a validated server configuration update.
AuthState::profile_signing_status
Section titled “AuthState::profile_signing_status”pub async fn profile_signing_status(&self) -> ProfileSigningStatusReport only safe signer metadata. The Developer ID team ID and key are never returned from the auth state.
AuthState::bootstrap
Section titled “AuthState::bootstrap”pub async fn bootstrap(&self) -> AuthResult<()>No doc comment.
AuthState::replace_oidc_providers
Section titled “AuthState::replace_oidc_providers”pub async fn replace_oidc_providers(&self, providers: Vec<OidcProvider<S>>) -> AuthResult<()>Replace discovered providers after a validated instance config edit. Replacement providers reuse the Instance ceremony budget; existing clones retain their state and its leases until completion (#737).
AuthState::limit
Section titled “AuthState::limit”pub async fn limit(&self, key: String, budget: u32) -> AuthResult<()>Share the bounded authentication limiter with protocol listeners (#428). Keys are server-owned surface/IP identities, never credential bytes. Count and key length stay bounded even for refused requests (#737).
AuthState::check_app_password_attempt
Section titled “AuthState::check_app_password_attempt”pub async fn check_app_password_attempt(&self, peer: &str) -> AuthResult<()>Block repeated failures without throttling valid CalDAV sync bursts.
AuthState::record_app_password_failure
Section titled “AuthState::record_app_password_failure”pub async fn record_app_password_failure(&self, peer: &str)No doc comment.
AuthState::record_app_password_denial
Section titled “AuthState::record_app_password_denial”pub async fn record_app_password_denial( &self, authority: &AppPasswordAuthority, protocol: AppPasswordProtocol, ) -> AuthResult<()>Audit out-of-scope use with a per-credential limit so a stolen or misconfigured client cannot grow Security state without bound.
Source: crates/calternal-auth/src/api.rs:140
CurrentUser
Section titled “CurrentUser”pub struct CurrentUser(pub User, pub SessionAuthority);No doc comment.
Implements: FromRequestParts<AuthState<S>>
Source: crates/calternal-auth/src/api.rs:310
pub struct Data;No doc comment.
Implements: ScopeMarker
Source: crates/calternal-auth/src/api.rs:319
Invite
Section titled “Invite”pub struct InviteNo doc comment.
Fields
pub token: Stringpub role: Rolepub expires_at: i64pub quota_override_bytes: Option<u64>
Implements: Debug, Clone, Serialize, ToSchema
Source: crates/calternal-auth/src/store.rs:330
InviteSummary
Section titled “InviteSummary”pub struct InviteSummaryAdmin view of an invite. id is the lowercase hex of the token hash: it
names the row for revocation but cannot be redeemed, because only the
token itself (shown once at creation) passes consume_invite.
Fields
pub id: Stringpub role: Rolepub expires_at: i64pub created_by: Uuidpub consumed_at: Option<i64>pub consumed_by: Option<Uuid>pub quota_override_bytes: Option<u64>:Noneinherits the Instance default;Some(0)means unlimited.
Implements: Debug, Clone, Serialize, ToSchema
Source: crates/calternal-auth/src/store.rs:311
OidcConfig
Section titled “OidcConfig”pub struct OidcConfigNo doc comment.
Fields
pub name: Stringpub issuer: Stringpub client_id: Stringpub client_secret: Stringpub redirect_uri: Stringpub groups_claim: Stringpub admin_group: Stringpub guest_group: Stringpub groups_authoritative: bool
Implements: Clone, Debug, Deserialize
Source: crates/calternal-auth/src/oidc.rs:25
OidcProvider
Section titled “OidcProvider”pub struct OidcProvider<S: AuthStore>No doc comment.
Implements: Clone
OidcProvider::issuer
Section titled “OidcProvider::issuer”pub fn issuer(&self) -> &strNo doc comment.
OidcProvider::discover
Section titled “OidcProvider::discover”pub async fn discover(config: OidcConfig, store: S) -> AuthResult<Self>No doc comment.
OidcProvider::name
Section titled “OidcProvider::name”pub fn name(&self) -> &strNo doc comment.
OidcProvider::role_for_groups
Section titled “OidcProvider::role_for_groups”pub fn role_for_groups(&self, groups: &[String]) -> RoleNo doc comment.
OidcProvider::start
Section titled “OidcProvider::start”pub async fn start(&self, link_user: Option<(Uuid, Vec<u8>)>) -> AuthResult<OidcStart>No doc comment.
OidcProvider::start_reauth
Section titled “OidcProvider::start_reauth”pub async fn start_reauth( &self, user_id: Uuid, session_hash: Vec<u8>, ) -> AuthResult<OidcStart>No doc comment.
OidcProvider::purpose
Section titled “OidcProvider::purpose”pub async fn purpose(&self, state: &str) -> Option<OidcPurpose>Read a pending flow’s purpose without consuming it. Unknown or expired state gives None.
OidcProvider::abandon
Section titled “OidcProvider::abandon”pub async fn abandon(&self, state: &str)Drop a pending flow that failed before completion, so its state cannot be replayed with a different code.
OidcProvider::complete
Section titled “OidcProvider::complete”pub async fn complete(&self, callback: OidcCallback) -> AuthResult<User>Consume bounded, unexpired state once and validate signed provider claims. Elevation records the provider’s recent authentication time on the initiating session, never the callback time (DESIGN §21, #735/#737).
Source: crates/calternal-auth/src/oidc.rs:41
PasskeyRecord
Section titled “PasskeyRecord”pub struct PasskeyRecordPasskey metadata without the stored credential JSON.
Fields
pub id: Vec<u8>pub name: Stringpub created_at: i64pub last_used_at: Option<i64>
Implements: Debug, Clone
Source: crates/calternal-auth/src/store.rs:323
PasskeyService
Section titled “PasskeyService”pub struct PasskeyService<S: AuthStore>No doc comment.
Implements: Clone
PasskeyService::new
Section titled “PasskeyService::new”pub fn new(store: S, rp_id: &str, rp_origin: &str) -> AuthResult<Self>No doc comment.
PasskeyService::begin_registration
Section titled “PasskeyService::begin_registration”pub async fn begin_registration( &self, username: String, display_name: String, grant: RegistrationGrant, ) -> AuthResult<Challenge<CreationChallengeResponse>>Start a library ceremony in the shared fallback-IP bucket. HTTP starts use the resolved IP; grant validation applies to both callers (#737).
PasskeyService::finish_registration
Section titled “PasskeyService::finish_registration”pub async fn finish_registration( &self, input: RegistrationFinish, ) -> AuthResult<(User, Option<String>)>No doc comment.
PasskeyService::begin_login
Section titled “PasskeyService::begin_login”pub async fn begin_login(&self) -> AuthResult<Challenge<RequestChallengeResponse>>Start library sign-in in the fallback-IP bucket; reserve before building its discoverable-credential challenge (DESIGN §21, #737).
PasskeyService::finish_login
Section titled “PasskeyService::finish_login”pub async fn finish_login( &self, input: AssertionFinish, kind: SessionKind, name: Option<&str>, idle_secs: i64, absolute_secs: i64, ) -> AuthResult<(User, String)>Consume and verify one login challenge, then issue a fresh session only if its credential is still present at the write boundary (#1043, DESIGN §21).
PasskeyService::begin_assertion
Section titled “PasskeyService::begin_assertion”pub async fn begin_assertion( &self, user_id: Uuid, remove: Option<Vec<u8>>, session_hash: Vec<u8>, ) -> AuthResult<Challenge<RequestChallengeResponse>>Start library elevation with the same admission bound as HTTP; keep the initiating session binding through completion (§21, #737).
PasskeyService::finish_assertion
Section titled “PasskeyService::finish_assertion”pub async fn finish_assertion( &self, input: AssertionFinish, session_hash: &[u8], ) -> AuthResult<()>Verify the selected key’s User, user verification and initiating live session before marking freshness or removing a key. Discovery preserves these checks for larger legacy sets (DESIGN §21, #734 R2). Verify the initiating session’s assertion and bind freshness to the credential’s current ownership before an authority change (#1043, DESIGN §21).
Source: crates/calternal-auth/src/passkey.rs:25
PendingUserDeletion
Section titled “PendingUserDeletion”pub struct PendingUserDeletionDurable deletion work which the server resumes after a crash.
Fields
pub user_id: Uuidpub actor_user_id: Uuidpub action: UserDeletionActionpub transfer_id: Option<Uuid>: Random stable folder identity for a transfer, present only for that policy.
Implements: Debug, Clone, PartialEq, Eq
Source: crates/calternal-auth/src/store.rs:833
ProfileSigner
Section titled “ProfileSigner”pub struct ProfileSigner(Arc<ProfileSignerInner>);No doc comment.
Implements: Clone
ProfileSigner::from_pem
Section titled “ProfileSigner::from_pem”pub fn from_pem( certificate_pem: &[u8], private_key_pem: &[u8], chain_pem: &[u8], ) -> Result<Self, ProfileSigningError>Parse and validate the leaf certificate, matching private key and ordered intermediate chain. Callers must check the key file mode before passing its bytes here.
ProfileSigner::sign
Section titled “ProfileSigner::sign”pub fn sign(&self, content: &[u8]) -> Result<Vec<u8>, ProfileSigningError>Create attached CMS SignedData as DER. The certificate and configured intermediate certificates travel with the body for Apple verification.
ProfileSigner::status
Section titled “ProfileSigner::status”pub fn status(&self) -> ProfileSigningStatusNo doc comment.
Source: crates/calternal-auth/src/profile_signing.rs:27
ProfileSigningStatus
Section titled “ProfileSigningStatus”pub struct ProfileSigningStatusNo doc comment.
Fields
pub enabled: bool: True when the certificate and chain are currently valid.pub display_name: Option<String>: The company name from the Developer ID common name, with its team ID removed.pub expires_at: Option<i64>: The earliest expiry time in the signer certificate chain, in Unix seconds.pub expires_soon: bool: True when the earliest expiry is within 30 days.
Implements: Clone, Debug, Default, Eq, PartialEq, Serialize, ToSchema
Source: crates/calternal-auth/src/profile_signing.rs:38
RequireScope
Section titled “RequireScope”pub struct RequireScope<T>(pub SessionAuthority, PhantomData<T>);Route-level scope guard for server and plugin APIs.
Implements: FromRequestParts<AuthState<S>>
Source: crates/calternal-auth/src/api.rs:312
ScopeSet
Section titled “ScopeSet”pub struct ScopeSet(u8);Server-enforced scopes. Agent containers receive DATA; Ask Agent containers also receive READ_ONLY, which the request authority enforces for writes.
Implements: Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize, ToSchema
ScopeSet::ACCOUNT
Section titled “ScopeSet::ACCOUNT”pub const ACCOUNT: SelfNo doc comment.
ScopeSet::ADMIN
Section titled “ScopeSet::ADMIN”pub const ADMIN: SelfNo doc comment.
ScopeSet::DATA
Section titled “ScopeSet::DATA”pub const DATA: SelfNo doc comment.
ScopeSet::READ_ONLY
Section titled “ScopeSet::READ_ONLY”pub const READ_ONLY: SelfNo doc comment.
ScopeSet::DATA_READ_ONLY
Section titled “ScopeSet::DATA_READ_ONLY”pub const DATA_READ_ONLY: SelfNo doc comment.
ScopeSet::HUMAN
Section titled “ScopeSet::HUMAN”pub const HUMAN: SelfNo doc comment.
ScopeSet::HUMAN_NO_ADMIN
Section titled “ScopeSet::HUMAN_NO_ADMIN”pub const HUMAN_NO_ADMIN: SelfNo doc comment.
ScopeSet::contains
Section titled “ScopeSet::contains”pub fn contains(self, other: Self) -> boolNo doc comment.
Source: crates/calternal-auth/src/store.rs:242
Session
Section titled “Session”pub struct SessionNo doc comment.
Fields
pub id: Stringpub user_id: Uuidpub kind: SessionKindpub scopes: ScopeSetpub resource_scope: Option<ResourceScope>pub installation_name: Option<String>pub created_at: i64pub last_seen_at: i64pub expires_at: i64pub revoked: boolpub current: bool: True only for the session that made this request.
Implements: Debug, Clone, Serialize, ToSchema
Source: crates/calternal-auth/src/store.rs:278
SessionAuthority
Section titled “SessionAuthority”pub struct SessionAuthorityNo doc comment.
Fields
pub user: Userpub token_hash: Vec<u8>pub actor: SessionActor: Who holds this session; set by the store from the session row.pub scopes: ScopeSetpub resource_scope: Option<ResourceScope>pub asserted_at: Option<i64>
Implements: Debug, Clone
SessionAuthority::fresh
Section titled “SessionAuthority::fresh”pub fn fresh(&self) -> boolNo doc comment.
Source: crates/calternal-auth/src/store.rs:262
SqliteAuthStore
Section titled “SqliteAuthStore”pub struct SqliteAuthStoreNo doc comment.
Implements: Clone, AuthStore
SqliteAuthStore::invalidate_app_password_cache
Section titled “SqliteAuthStore::invalidate_app_password_cache”pub fn invalidate_app_password_cache(&self)Discard positive entries after a trusted out-of-band fixture change. Production transactions use the change guard before their first write (#512, DESIGN §21).
SqliteAuthStore::begin_app_password_change
Section titled “SqliteAuthStore::begin_app_password_change”pub fn begin_app_password_change(&self) -> AppPasswordCacheChangeGuard an external Security state transaction before its first write.
Commit with commit_app_password_change so request cancellation cannot
reopen the cache while SQLite is still committing (#512, DESIGN §21).
SqliteAuthStore::commit_app_password_change
Section titled “SqliteAuthStore::commit_app_password_change”pub async fn commit_app_password_change( &self, tx: Transaction<'static, Sqlite>, change: AppPasswordCacheChange, ) -> AuthResult<()>Keep the change guard alive in an owned task until commit finishes. Dropping the request only detaches the task; its final generation bump still rejects old verifiers. Errors also discard positive entries (#512).
SqliteAuthStore::set_app_password_options
Section titled “SqliteAuthStore::set_app_password_options”pub async fn set_app_password_options( &self, user_id: Uuid, id: Uuid, options: AppPasswordOptions, ) -> AuthResult<()>Change restrictions and retire the old App Password atomically. A User must issue a new credential for the new scopes. This trusted store hook is not an additional HTTP endpoint (#512 round 2, DESIGN §21).
SqliteAuthStore::apply_instance_open_signup
Section titled “SqliteAuthStore::apply_instance_open_signup”pub async fn apply_instance_open_signup(&self, enabled: bool) -> AuthResult<()>Apply the server-owned instance file’s signup policy after validation. The file can be edited by the host, so this path has no user actor.
SqliteAuthStore::begin_user_deletion
Section titled “SqliteAuthStore::begin_user_deletion”pub async fn begin_user_deletion( &self, tx: &mut Transaction<'_, Sqlite>, actor_user_id: Uuid, user_id: Uuid, requested: UserDeletionAction, ) -> AuthResult<PendingUserDeletion>Mark a user for deletion inside the server’s grant-revocation transaction. The stored action makes filesystem work resumable after a process crash.
SqliteAuthStore::pending_user_deletions
Section titled “SqliteAuthStore::pending_user_deletions”pub async fn pending_user_deletions(&self) -> AuthResult<Vec<PendingUserDeletion>>Return durable deletion work in a stable order for startup recovery.
SqliteAuthStore::finish_user_deletion
Section titled “SqliteAuthStore::finish_user_deletion”pub async fn finish_user_deletion(&self, user_id: Uuid) -> AuthResult<()>Remove a user row after its persisted Home action has completed.
SqliteAuthStore::revoke_session_for_recovery
Section titled “SqliteAuthStore::revoke_session_for_recovery”pub async fn revoke_session_for_recovery(&self, user: Uuid, hash: &[u8]) -> AuthResult<()>Revoke a recovery credential, accepting an already revoked/missing row. Trusted server cleanup must survive a crash after FULL revocation but before binding deletion. A live session of another User is denied (#824, DESIGN §2). Public revocation keeps its strict InvalidToken response.
SqliteAuthStore::connect
Section titled “SqliteAuthStore::connect”pub async fn connect(url: &str) -> AuthResult<Self>Open and migrate the security-state Index (DESIGN §2; #905). File-backed stores use WAL and at most eight connections; memory stores use one connection. Pool acquisition times out after two seconds, so request handlers can return 503 instead of waiting without a bound.
SqliteAuthStore::from_pool
Section titled “SqliteAuthStore::from_pool”pub fn from_pool(pool: SqlitePool) -> SelfNo doc comment.
SqliteAuthStore::from_pools
Section titled “SqliteAuthStore::from_pools”pub fn from_pools(pool: SqlitePool, read_pool: SqlitePool) -> SelfBuild the authority store with separate pools for writes and reads. Activity shares the authority policy for compatibility. The server uses from_pools_with_activity to keep request telemetry NORMAL (#824, DESIGN §2).
SqliteAuthStore::from_pools_with_cache_key
Section titled “SqliteAuthStore::from_pools_with_cache_key”pub fn from_pools_with_cache_key( pool: SqlitePool, read_pool: SqlitePool, key: [u8; 32], ) -> SelfBuild the server store with the secret loaded once from the existing Index secret store. The fallback constructors use restart-random keys for isolated stores and tests; production persists its key (#512).
SqliteAuthStore::from_pools_with_activity
Section titled “SqliteAuthStore::from_pools_with_activity”pub fn from_pools_with_activity( pool: SqlitePool, read_pool: SqlitePool, activity_pool: SqlitePool, ) -> SelfUse FULL for authority, read-only readers, and a distinct NORMAL activity pool. The activity pool must be the server’s one-connection ordinary writer. It permits metadata-only writes and a nonblocking checkout before session refresh; holding it excludes a competing ordinary transaction (#824, DESIGN §2).
SqliteAuthStore::for_index
Section titled “SqliteAuthStore::for_index”pub fn for_index(db: &calternal_db::Db) -> SelfBuild the production Auth store for one Index (#824, DESIGN §2).
This is the only place that maps Index pools to Auth roles: the FULL authority connection for Security state, the read-only readers, and the NORMAL ordinary writer for App Password activity only. The server, the durability harness and repository tests all use it, so a test of this constructor is a test of the production selection.
SqliteAuthStore::for_index_with_cache_key
Section titled “SqliteAuthStore::for_index_with_cache_key”pub fn for_index_with_cache_key(db: &calternal_db::Db, key: [u8; 32]) -> SelfApply the persisted verification key after the production pool mapping. Cache setup must never select a NORMAL authority pool (#512, #824, DESIGN §§2, 21); both server startup and durability tests use for_index.
SqliteAuthStore::ensure_durable_authority
Section titled “SqliteAuthStore::ensure_durable_authority”pub async fn ensure_durable_authority(&self) -> AuthResult<()>Refuse to serve when Security state writes would not sync each commit.
SQLite reports synchronous per connection: 2 is FULL and 3 is EXTRA.
NORMAL (1) in WAL mode can lose an acknowledged revocation on power loss
(#824). The server calls this once at startup, before any route runs.
Source: crates/calternal-auth/src/store.rs:1131
pub struct UserNo doc comment.
Fields
pub id: Uuidpub username: Stringpub display_name: Stringpub role: Rolepub disabled: bool
Implements: Debug, Clone, Serialize, Deserialize, ToSchema
Source: crates/calternal-auth/src/store.rs:182
UserSummary
Section titled “UserSummary”pub struct UserSummaryAdmin view of a User. It has no credential or session material.
Fields
pub id: Uuidpub username: Stringpub display_name: Stringpub role: Rolepub disabled: boolpub deletion_pending: bool: True while the server drains the durable Home deletion action.pub created_at: i64pub quota_override_bytes: Option<u64>:Noneinherits the Instance default;Some(0)means unlimited.
Implements: Debug, Clone, Serialize, ToSchema
Source: crates/calternal-auth/src/store.rs:295
AppPasswordAccess
Section titled “AppPasswordAccess”pub enum AppPasswordAccessNo doc comment.
Variants
ReadWriteUploadOnlyFull
Implements: Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize, ToSchema
Source: crates/calternal-auth/src/store.rs:376
AppPasswordPluginAccess
Section titled “AppPasswordPluginAccess”pub enum AppPasswordPluginAccessNo doc comment.
Variants
ReadWrite
Implements: Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize, ToSchema
Source: crates/calternal-auth/src/store.rs:391
AppPasswordProtocol
Section titled “AppPasswordProtocol”pub enum AppPasswordProtocolNo doc comment.
Variants
CalDavNotes: Apple Notes IMAP bridge credentials (#428); independent of CalDAV.Mail: Internal Mail grant in the shared device preset (#486, DESIGN §53).WebDavApiMcp
Implements: Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize, ToSchema
AppPasswordProtocol::as_str
Section titled “AppPasswordProtocol::as_str”pub fn as_str(self) -> &'static strNo doc comment.
Source: crates/calternal-auth/src/store.rs:338
AuthError
Section titled “AuthError”pub enum AuthErrorNo doc comment.
Variants
UnauthenticatedForbiddenOutOfScopeInvalidTokenInvalidRequestConflictRateLimitedInternalUnavailable
Implements: Debug, Error, IntoResponse
Source: crates/calternal-auth/src/error.rs:14
OidcPurpose
Section titled “OidcPurpose”pub enum OidcPurposeWhat a pending flow does when it completes. The browser callback reads it before completion to choose where to send the browser.
Variants
SignInLinkReauth
Implements: Clone, Copy, Debug, PartialEq, Eq
Source: crates/calternal-auth/src/oidc.rs:59
ProfileSigningError
Section titled “ProfileSigningError”pub enum ProfileSigningErrorNo doc comment.
Variants
InvalidCertificateInvalidPrivateKeyUnsupportedKeyKeyMismatchInvalidChainCertificateNotYetValidCertificateExpiredInvalidCommonNameSignFailed
Implements: Clone, Copy, Debug, Eq, PartialEq, std::fmt::Display, std::error::Error
ProfileSigningError::reason
Section titled “ProfileSigningError::reason”pub fn reason(self) -> &'static strReturn a safe reason for startup logs. OpenSSL errors can include implementation details, so they are not logged with certificate data.
Source: crates/calternal-auth/src/profile_signing.rs:50
RegistrationGrant
Section titled “RegistrationGrant”pub enum RegistrationGrantNo doc comment.
Variants
Setup(String)Invite(String)Existing(Uuid, Vec<u8>)Recovery(Uuid, String)Reenrol(Uuid, String)OpenSignup
Implements: Clone
Source: crates/calternal-auth/src/passkey.rs:60
ResourceScope
Section titled “ResourceScope”pub enum ResourceScopeThe files layer must intersect this limit with the User’s current shares.
Variants
HomeAndShared { user_id: Uuid }
Implements: Debug, Clone, PartialEq, Eq, Serialize, Deserialize, ToSchema
Source: crates/calternal-auth/src/store.rs:258
pub enum RoleNo doc comment.
Variants
OwnerAdminMemberGuest
Implements: Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize, ToSchema
Role::as_str
Section titled “Role::as_str”pub fn as_str(self) -> &'static strNo doc comment.
Role::can_admin
Section titled “Role::can_admin”pub fn can_admin(self) -> boolNo doc comment.
Source: crates/calternal-auth/src/store.rs:143
SessionActor
Section titled “SessionActor”pub enum SessionActorWhich kind of actor holds a session (#980).
The row stores it in installation_type at issuance, and every request
carries it to the Plugin context. Routes that must never serve a container
(for example the AI routes, which would let a turn start more turns or read
the User’s other prompts) check this value. They never infer it from the
scopes, because scopes describe what a session may touch, not who holds it.
Variants
User: The User’s own session: a browser cookie or a human Installation token such as the CLI.Agent: The token handed to an Agent turn’s container.Ask: The read-only token handed to an Ask turn’s container.
Implements: Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize, ToSchema
Source: crates/calternal-auth/src/store.rs:212
SessionKind
Section titled “SessionKind”pub enum SessionKindNo doc comment.
Variants
WebInstallation
Implements: Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize, ToSchema
Source: crates/calternal-auth/src/store.rs:191
UserDeletionAction
Section titled “UserDeletionAction”pub enum UserDeletionActionThe action an administrator selected for a pending Home deletion.
Variants
Archive { expires_at: i64 }Transfer { target_user_id: Uuid }Purge
Implements: Debug, Clone, PartialEq, Eq
Source: crates/calternal-auth/src/store.rs:825
Traits
Section titled “Traits”AuthStore
Section titled “AuthStore”pub trait AuthStore: Clone + Send + Sync + 'staticNo doc comment.
AuthStore::create_app_password
Section titled “AuthStore::create_app_password”async fn create_app_password( &self, user: Uuid, name: &str, options: AppPasswordOptions, ) -> AuthResult<(AppPassword, String)>;No doc comment.
AuthStore::list_app_passwords
Section titled “AuthStore::list_app_passwords”async fn list_app_passwords(&self, user: Uuid) -> AuthResult<Vec<AppPassword>>;No doc comment.
AuthStore::active_app_password
Section titled “AuthStore::active_app_password”async fn active_app_password(&self, user: Uuid, id: Uuid) -> AuthResult<Option<AppPassword>>;Return the current grant only while its User and credential are active. Long-lived protocols must use this, not the Settings listing (#787, §21).
AuthStore::revoke_app_password
Section titled “AuthStore::revoke_app_password”async fn revoke_app_password(&self, user: Uuid, id: Uuid) -> AuthResult<()>;No doc comment.
AuthStore::verify_app_password
Section titled “AuthStore::verify_app_password”async fn verify_app_password( &self, username: Option<&str>, secret: &str, ) -> AuthResult<Option<AppPasswordAuthority>>;Verify the secret and return its current User authority. The SQLite store shares a short-lived result across DAV and MCP callers (#512).
AuthStore::record_app_password_use
Section titled “AuthStore::record_app_password_use”async fn record_app_password_use( &self, id: Uuid, protocol: AppPasswordProtocol, coarse_ip: &str, ) -> AuthResult<()>;No doc comment.
AuthStore::record_app_password_denial
Section titled “AuthStore::record_app_password_denial”async fn record_app_password_denial( &self, user: Uuid, id: Uuid, protocol: AppPasswordProtocol, ) -> AuthResult<()>;No doc comment.
AuthStore::user
Section titled “AuthStore::user”async fn user(&self, id: Uuid) -> AuthResult<Option<User>>;No doc comment.
AuthStore::user_by_username
Section titled “AuthStore::user_by_username”async fn user_by_username(&self, username: &str) -> AuthResult<Option<User>>;No doc comment.
AuthStore::users
Section titled “AuthStore::users”async fn users(&self) -> AuthResult<Vec<User>>;No doc comment.
AuthStore::count_users
Section titled “AuthStore::count_users”async fn count_users(&self) -> AuthResult<i64>;No doc comment.
AuthStore::update_profile
Section titled “AuthStore::update_profile”async fn update_profile( &self, user_id: Uuid, username: &str, display_name: &str, ) -> AuthResult<User>;No doc comment.
AuthStore::set_role
Section titled “AuthStore::set_role”async fn set_role(&self, actor: Uuid, user_id: Uuid, role: Role) -> AuthResult<()>;No doc comment.
AuthStore::set_disabled
Section titled “AuthStore::set_disabled”async fn set_disabled(&self, actor: Uuid, user_id: Uuid, disabled: bool) -> AuthResult<()>;No doc comment.
AuthStore::set_quota_override
Section titled “AuthStore::set_quota_override”async fn set_quota_override( &self, actor: Uuid, user_id: Uuid, quota_override_bytes: Option<u64>, ) -> AuthResult<()>;No doc comment.
AuthStore::prepare_setup
Section titled “AuthStore::prepare_setup”async fn prepare_setup(&self) -> AuthResult<Option<String>>;No doc comment.
AuthStore::setup_redeemable
Section titled “AuthStore::setup_redeemable”async fn setup_redeemable(&self, token: &str) -> AuthResult<bool>;Check the one-time setup grant before allocating a ceremony. The consume transaction must still recheck it (DESIGN §7, #737).
AuthStore::consume_setup
Section titled “AuthStore::consume_setup”async fn consume_setup( &self, token: &str, id: Uuid, username: &str, display_name: &str, credential_id: &[u8], credential_name: &str, credential_json: &str, ) -> AuthResult<User>;Keep token consumption and its bounded initial credential atomic (DESIGN §7, #734 R2). Failed insertion leaves the grant usable.
AuthStore::list_users
Section titled “AuthStore::list_users”async fn list_users(&self) -> AuthResult<Vec<UserSummary>>;No doc comment.
AuthStore::create_invite
Section titled “AuthStore::create_invite”async fn create_invite( &self, actor: Uuid, role: Role, ttl_secs: i64, quota_override_bytes: Option<u64>, ) -> AuthResult<Invite>;No doc comment.
AuthStore::list_invites
Section titled “AuthStore::list_invites”async fn list_invites(&self) -> AuthResult<Vec<InviteSummary>>;No doc comment.
AuthStore::invite_redeemable
Section titled “AuthStore::invite_redeemable”async fn invite_redeemable(&self, token: &str) -> AuthResult<bool>;Whether an invite token can still be redeemed. Only a hint for the
start step; consume_invite re-checks inside its transaction.
AuthStore::revoke_invite
Section titled “AuthStore::revoke_invite”async fn revoke_invite(&self, actor: Uuid, id_hex: &str) -> AuthResult<()>;Delete an unconsumed invite. A consumed invite is history, not authority.
AuthStore::consume_invite
Section titled “AuthStore::consume_invite”async fn consume_invite( &self, token: &str, id: Uuid, username: &str, display_name: &str, credential_id: &[u8], credential_name: &str, credential_json: &str, ) -> AuthResult<User>;Commit the initial credential, counted admission and item grant together. BEGIN IMMEDIATE serializes completion with revoke and policy changes (§54, #1035).
AuthStore::consume_open_signup
Section titled “AuthStore::consume_open_signup”async fn consume_open_signup( &self, id: Uuid, username: &str, display_name: &str, credential_id: &[u8], credential_name: &str, credential_json: &str, ) -> AuthResult<User>;Create an enabled local-signup User and a supported initial key in one transaction; no partial account can survive refusal (§7, #734 R2).
AuthStore::invite_destination
Section titled “AuthStore::invite_destination”async fn invite_destination(&self, user_id: Uuid) -> AuthResult<Option<String>>;Post-enrolment destination for a new User, fixed by the owner (#1035).
AuthStore::share_invites_enabled
Section titled “AuthStore::share_invites_enabled”async fn share_invites_enabled(&self) -> AuthResult<bool>;Instance switch for share invitations (DESIGN §54).
AuthStore::set_share_invites_enabled
Section titled “AuthStore::set_share_invites_enabled”async fn set_share_invites_enabled(&self, actor: Uuid, enabled: bool) -> AuthResult<()>;Only an active admin may change who can create share invitations (#1035).
AuthStore::open_signup
Section titled “AuthStore::open_signup”async fn open_signup(&self) -> AuthResult<bool>;No doc comment.
AuthStore::set_open_signup
Section titled “AuthStore::set_open_signup”async fn set_open_signup(&self, actor: Uuid, value: bool) -> AuthResult<()>;No doc comment.
AuthStore::record_security_event
Section titled “AuthStore::record_security_event”async fn record_security_event(&self, actor: Uuid, event: &str, detail: &str) -> AuthResult<()>;Add a bounded, admin-attributed security event for a server operation.
AuthStore::issue_session
Section titled “AuthStore::issue_session”async fn issue_session( &self, user_id: Uuid, kind: SessionKind, name: Option<&str>, idle_secs: i64, absolute_secs: i64, ) -> AuthResult<String>;No doc comment.
AuthStore::issue_passkey_session
Section titled “AuthStore::issue_passkey_session”async fn issue_passkey_session( &self, user_id: Uuid, credential_id: &[u8], kind: SessionKind, name: Option<&str>, idle_secs: i64, absolute_secs: i64, ) -> AuthResult<String>;Issue a fresh human session only while the verified credential belongs to this User. Check presence in the insert transaction (#1043, DESIGN §21).
AuthStore::mark_passkey_asserted
Section titled “AuthStore::mark_passkey_asserted”async fn mark_passkey_asserted( &self, hash: &[u8], user_id: Uuid, credential_id: &[u8], ) -> AuthResult<()>;Mark the initiating session fresh only while its verified credential still belongs to this User at the write boundary (#1043, DESIGN §21).
AuthStore::authenticate_session
Section titled “AuthStore::authenticate_session”async fn authenticate_session( &self, token: &str, kind: SessionKind, idle_secs: i64, ) -> AuthResult<Option<User>>;No doc comment.
AuthStore::session_authority
Section titled “AuthStore::session_authority”async fn session_authority( &self, token: &str, kind: SessionKind, idle_secs: i64, ) -> AuthResult<Option<SessionAuthority>>;No doc comment.
AuthStore::mark_asserted
Section titled “AuthStore::mark_asserted”async fn mark_asserted(&self, hash: &[u8]) -> AuthResult<()>;No doc comment.
AuthStore::mark_asserted_at
Section titled “AuthStore::mark_asserted_at”async fn mark_asserted_at(&self, hash: &[u8], authenticated_at: i64) -> AuthResult<()>;Preserve provider authentication time so callback receipt cannot renew the five-minute authority window (DESIGN §21, #735).
AuthStore::require_live_session
Section titled “AuthStore::require_live_session”async fn require_live_session(&self, hash: &[u8], user_id: Uuid) -> AuthResult<()>;Recheck the session’s User, revocation and both expiry bounds for retained authority (#788, DESIGN §21).
AuthStore::require_fresh
Section titled “AuthStore::require_fresh”async fn require_fresh(&self, hash: &[u8], user_id: Uuid) -> AuthResult<()>;No doc comment.
AuthStore::issue_agent_session
Section titled “AuthStore::issue_agent_session”async fn issue_agent_session(&self, user_id: Uuid, name: &str) -> AuthResult<String>;No doc comment.
AuthStore::issue_ask_agent_session
Section titled “AuthStore::issue_ask_agent_session”async fn issue_ask_agent_session(&self, user_id: Uuid, name: &str) -> AuthResult<String>;No doc comment.
AuthStore::renew_agent_session
Section titled “AuthStore::renew_agent_session”async fn renew_agent_session(&self, token: &str) -> AuthResult<String>;No doc comment.
AuthStore::revoke_all
Section titled “AuthStore::revoke_all”async fn revoke_all( &self, actor: Uuid, current_hash: &[u8], keep_current: bool, ) -> AuthResult<u64>;No doc comment.
AuthStore::list_sessions
Section titled “AuthStore::list_sessions”async fn list_sessions(&self, user_id: Uuid) -> AuthResult<Vec<Session>>;No doc comment.
AuthStore::revoke_session
Section titled “AuthStore::revoke_session”async fn revoke_session(&self, actor: Uuid, token_hash_hex: &str) -> AuthResult<()>;No doc comment.
AuthStore::put_passkey_bound
Section titled “AuthStore::put_passkey_bound”async fn put_passkey_bound( &self, user_id: Uuid, session_hash: &[u8], credential_id: &[u8], name: &str, json: &str, ) -> AuthResult<()>;Add only to the initiating live, fresh session. The insertion checks the resulting key set in the same transaction (DESIGN §21, #734 R2).
AuthStore::put_passkey
Section titled “AuthStore::put_passkey”async fn put_passkey( &self, user_id: Uuid, credential_id: &[u8], name: &str, json: &str, ) -> AuthResult<()>;Insert a supported key set for library callers; every grant uses the same insertion invariant and audit transaction (DESIGN §7, #734 R2).
AuthStore::passkey
Section titled “AuthStore::passkey”async fn passkey(&self, credential_id: &[u8]) -> AuthResult<Option<(Uuid, String)>>;No doc comment.
AuthStore::passkeys
Section titled “AuthStore::passkeys”async fn passkeys(&self, user_id: Uuid) -> AuthResult<Vec<(Vec<u8>, String, String)>>;No doc comment.
AuthStore::passkey_set_fits
Section titled “AuthStore::passkey_set_fits”async fn passkey_set_fits(&self, user_id: Uuid) -> AuthResult<bool>Check the shared key-set bound before loading ceremony state (#734 R2).
AuthStore::passkey_records
Section titled “AuthStore::passkey_records”async fn passkey_records(&self, user_id: Uuid) -> AuthResult<Vec<PasskeyRecord>>;No doc comment.
AuthStore::rename_passkey
Section titled “AuthStore::rename_passkey”async fn rename_passkey( &self, user_id: Uuid, credential_id: &[u8], name: &str, ) -> AuthResult<PasskeyRecord>;Change only the label of the User’s own passkey. A label carries no authority, so this needs no fresh assertion.
AuthStore::update_passkey
Section titled “AuthStore::update_passkey”async fn update_passkey(&self, credential_id: &[u8], json: &str) -> AuthResult<()>;No doc comment.
AuthStore::remove_passkey
Section titled “AuthStore::remove_passkey”async fn remove_passkey( &self, user_id: Uuid, session_hash: &[u8], credential_id: &[u8], ) -> AuthResult<()>;No doc comment.
AuthStore::oidc_user
Section titled “AuthStore::oidc_user”async fn oidc_user(&self, issuer: &str, subject: &str) -> AuthResult<Option<User>>;No doc comment.
AuthStore::reconcile_oidc_role
Section titled “AuthStore::reconcile_oidc_role”async fn reconcile_oidc_role(&self, user_id: Uuid, role: Role) -> AuthResult<User>;No doc comment.
AuthStore::create_oidc_user
Section titled “AuthStore::create_oidc_user”async fn create_oidc_user( &self, issuer: &str, subject: &str, username: &str, display_name: &str, role: Role, ) -> AuthResult<User>;No doc comment.
AuthStore::link_oidc
Section titled “AuthStore::link_oidc”async fn link_oidc(&self, user_id: Uuid, issuer: &str, subject: &str) -> AuthResult<()>;No doc comment.
AuthStore::unlink_oidc
Section titled “AuthStore::unlink_oidc”async fn unlink_oidc(&self, user_id: Uuid, issuer: &str) -> AuthResult<()>;No doc comment.
AuthStore::oidc_issuers
Section titled “AuthStore::oidc_issuers”async fn oidc_issuers(&self, user_id: Uuid) -> AuthResult<Vec<String>>;Issuers linked to the User. Subjects stay in the store.
AuthStore::legacy_recovery_codes
Section titled “AuthStore::legacy_recovery_codes”async fn legacy_recovery_codes(&self, user_id: Uuid) -> AuthResult<u32>;Unconsumed recovery codes from before the single recovery key.
AuthStore::recovery_codes
Section titled “AuthStore::recovery_codes”async fn recovery_codes(&self, user_id: Uuid) -> AuthResult<Vec<String>>;No doc comment.
AuthStore::issue_recovery_key
Section titled “AuthStore::issue_recovery_key”async fn issue_recovery_key( &self, user_id: Uuid, session_hash: Option<&[u8]>, ) -> AuthResult<String>;No doc comment.
AuthStore::has_recovery_key
Section titled “AuthStore::has_recovery_key”async fn has_recovery_key(&self, user_id: Uuid) -> AuthResult<bool>;No doc comment.
AuthStore::verify_recovery
Section titled “AuthStore::verify_recovery”async fn verify_recovery(&self, user_id: Uuid, code: &str) -> AuthResult<bool>;No doc comment.
AuthStore::enroll_recovery_key
Section titled “AuthStore::enroll_recovery_key”async fn enroll_recovery_key( &self, user_id: Uuid, phrase: &str, credential_id: &[u8], name: &str, json: &str, ) -> AuthResult<String>;Rotate the recovery key, revoke sessions and insert the bounded new credential atomically. Refusal preserves the old key (§7, #734 R2).
AuthStore::enroll_recovery
Section titled “AuthStore::enroll_recovery”async fn enroll_recovery( &self, user_id: Uuid, code: &str, credential_id: &[u8], name: &str, json: &str, ) -> AuthResult<String>;Redeem a legacy code only with a supported resulting key set. Its consumption and session revocation roll back on refusal (§7, #734 R2).
AuthStore::issue_reenrol
Section titled “AuthStore::issue_reenrol”async fn issue_reenrol(&self, actor: Uuid, user_id: Uuid, ttl_secs: i64) -> AuthResult<String>;No doc comment.
AuthStore::reenrol_target
Section titled “AuthStore::reenrol_target”async fn reenrol_target(&self, token: &str) -> AuthResult<Option<Uuid>>;No doc comment.
AuthStore::enroll_reenrol
Section titled “AuthStore::enroll_reenrol”async fn enroll_reenrol( &self, token: &str, user_id: Uuid, credential_id: &[u8], name: &str, json: &str, ) -> AuthResult<()>;No doc comment.
Source: crates/calternal-auth/src/store.rs:859
Type aliases
Section titled “Type aliases”AuthResult
Section titled “AuthResult”pub type AuthResult<T> = Result<T, AuthError>;No doc comment.
Source: crates/calternal-auth/src/error.rs:11
Functions
Section titled “Functions”client_ip
Section titled “client_ip”pub fn client_ip(peer: IpAddr, forwarded: Option<&str>, trusted: &[IpNet]) -> IpAddrResolve a client address only through configured trusted proxies.
Source: crates/calternal-auth/src/api.rs:705
decode_token_hash
Section titled “decode_token_hash”pub fn hex_decode(s: &str) -> Option<Vec<u8>>Decode a 32-byte hash id. Works on bytes: slicing a str by byte offset
panics inside a multi-byte character, and ids come straight from URLs.
Source: crates/calternal-auth/src/store.rs:3850
encode_token_hash
Section titled “encode_token_hash”pub fn hex_encode(bytes: &[u8]) -> StringEncode a hash-only management ID shared by admin and item invites (§54, #1035).
Source: crates/calternal-auth/src/store.rs:3845
extract_authority
Section titled “extract_authority”pub async fn extract_authority<S: AuthStore>( parts: &mut Parts, state: &AuthState<S>,) -> AuthResult<SessionAuthority>Resolve the same cookie or bearer session used by auth route guards. Server middleware uses this for plugin request context.
Source: crates/calternal-auth/src/api.rs:364
is_trusted_proxy
Section titled “is_trusted_proxy”pub fn is_trusted_proxy(peer: IpAddr, trusted: &[IpNet]) -> boolReturn whether a TCP peer is allowed to supply forwarded client addresses.
Source: crates/calternal-auth/src/api.rs:700
new_token
Section titled “new_token”pub fn new_token() -> StringNo doc comment.
Source: crates/calternal-auth/src/token.rs:6
openapi
Section titled “openapi”pub fn openapi() -> utoipa::openapi::OpenApiOpenAPI fragment to merge into the server’s instance API document.
Source: crates/calternal-auth/src/api.rs:2487
router
Section titled “router”pub fn router<S: AuthStore>(state: AuthState<S>) -> RouterNo doc comment.
Source: crates/calternal-auth/src/api.rs:613
token_hash
Section titled “token_hash”pub fn token_hash(token: &str) -> Vec<u8>No doc comment.
Source: crates/calternal-auth/src/token.rs:12
Constants
Section titled “Constants”SESSION_COOKIE_CLEAR
Section titled “SESSION_COOKIE_CLEAR”pub const SESSION_COOKIE_CLEAR: &strExpires the session cookie. Sent on sign-out, and by the server when a browser presents a cookie whose session no longer resolves.