A11 (C++ runtime)
Native C++ implementation of the A11 streaming action runtime
Loading...
Searching...
No Matches
authorization.h File Reference
#include <cstdint>
#include <functional>
#include <memory>
#include <optional>
#include <string>
#include <string_view>
#include <vector>
#include <absl/status/status.h>
#include <absl/status/statusor.h>
#include <absl/time/time.h>
#include <nlohmann/json.hpp>
This graph shows which files directly or indirectly include this file:

Go to the source code of this file.

Classes

struct  a11::actions::AuthorizationEnvelope
 A versioned ordered sequence of compact signed delegation statements. More...
 
struct  a11::actions::VerifiedAuthorization
 Identity and effective authority returned by an application verifier. More...
 
struct  a11::actions::AuthorizationContext
 Result of installing a verified connection context. More...
 
class  a11::actions::AuthorizationContextStore
 Bounded verified contexts scoped to the receiving Session and stream. More...
 

Namespaces

namespace  a11
 
namespace  a11::actions
 

Typedefs

using a11::actions::AuthorizationVerifier = std::function< absl::StatusOr< VerifiedAuthorization >(std::string_view)>
 

Functions

ActionSchema a11::actions::AuthorizationActionSchema ()
 Schema of the transport-independent connection authorizing action.
 
absl::StatusOr< std::shared_ptr< AuthorizationContextStore > > a11::actions::InstallAuthorizer (const std::shared_ptr< ActionRegistry > &registry, AuthorizationVerifier verifier, std::shared_ptr< AuthorizationContextStore > contexts=nullptr)
 Register __authorize__ for a native verifier and context store.
 
absl::StatusOr< std::string > a11::actions::EncodeAuthorization (const AuthorizationEnvelope &envelope)
 Validate and canonically encode an authorization envelope as MessagePack.
 
absl::StatusOr< AuthorizationEnvelope > a11::actions::DecodeAuthorization (std::string_view value)
 Decode a canonical, bounded native authorization value.
 
absl::StatusOr< std::string > a11::actions::AuthorizationToText (const AuthorizationEnvelope &envelope)
 Convert a native value to an ASCII physical HTTP header.
 
absl::StatusOr< std::string > a11::actions::AuthorizationFingerprint (const AuthorizationEnvelope &envelope)
 Return an unpadded base64url SHA-256 identifier for the exact envelope.
 
absl::StatusOr< AuthorizationEnvelope > a11::actions::AuthorizationFromText (std::string_view value)
 Convert an ASCII physical HTTP header to the native envelope.
 
absl::StatusOr< std::optional< AuthorizationEnvelope > > a11::actions::GetAuthorization (const Action &action)
 Decode the complete authorization on an action, when present.
 
absl::Status a11::actions::SetAuthorization (const std::shared_ptr< Action > &action, const std::optional< AuthorizationEnvelope > &envelope)
 Set or remove a complete authorization and clear any context reference.
 
absl::StatusOr< std::optional< std::string > > a11::actions::GetAuthorizationReference (const Action &action)
 Read the receiver-issued raw 128-bit context reference, when present.
 
absl::Status a11::actions::SetAuthorizationReference (const std::shared_ptr< Action > &action, const std::optional< std::string > &context_id)
 Set or remove a raw 128-bit context reference and clear any full proof.
 

Variables

constexpr std::string_view a11::actions::kAuthorizationHeader = "x-a11-auth"
 
constexpr std::string_view a11::actions::kAuthorizationReferenceHeader
 
constexpr std::string_view a11::actions::kAuthorizationDefaultHeader
 
constexpr std::string_view a11::actions::kAuthorizationReplaceHeader
 
constexpr std::string_view a11::actions::kAuthorizeAction = "__authorize__"
 
constexpr int a11::actions::kAuthorizationVersion = 1
 
constexpr size_t a11::actions::kMaxAuthorizationBytes = 16 * 1024
 
constexpr size_t a11::actions::kMaxAuthorizationHops = 8