Sign in

    q2316367743/open-list/auth does not have a README file

    Auth

    pub struct Auth {
    // private fields
    }

    认证域。

    两种认证方式都由 core 的 Client 统一处理:

    • 直接给永久 token(create_open_list_client_with_token)——此时 login 不必要,is_logged_in() 一开始就是 true;
    • 给账号密码(Credentials::password)——客户端在第一个需要认证的请求 前自动登录换限时 token,token 过期(401)时自动重登一次。

    因此业务代码不需要自己调 login;只在「想立刻验证密码是否正确」或 「想自己控制登录时机」时才手动调用,login 会顺手把 token 存进共享状态。

    Auth::generate_2fa

    生成两步验证密钥与二维码(POST /api/auth/2fa/generate)。

    需要已登录。真正的开启动作是随后调用 verify_2fa。

    Auth::is_logged_in

    fn Auth::is_logged_in(self : Auth) -> Bool

    是否已持有 token。

    Auth::login

    async fn Auth::login(self : Auth, username : String, password : String, otp_code? : String) -> String raise
    OpenListError

    用账号密码登录(POST /api/auth/login)。

    服务端会对请求里的密码做静态哈希后再校验,所以这里传明文密码。 返回并记住换来的限时 token。常见失败:401 用户名或密码错误、 402 两步验证码错误、429 失败次数过多(同一 IP 5 次后锁 5 分钟)。

    Auth::login_hash

    async fn Auth::login_hash(self : Auth, username : String, hashed_password : String, otp_code? : String) -> String raise
    OpenListError

    用「前端已做静态哈希」的密码登录(POST /api/auth/login/hash)。

    服务端不会再哈希,因此 hashed_password 必须是 SHA256(密码 + "-" + salt) 形式的结果;本模块不实现哈希算法,需要的话在调用方算好再传进来。

    Auth::login_ldap

    async fn Auth::login_ldap(self : Auth, username : String, password : String, otp_code? : String) -> String raise
    OpenListError

    用 LDAP 账号登录(POST /api/auth/login/ldap)。

    Auth::logout

    退出登录(GET /api/auth/logout):让服务端作废当前 token,并清空本地状态。

    本来就没登录时直接返回,不发请求。服务端即使报错(例如 token 已失效) 本地状态同样会被清空——退出登录不该因为网络问题而失败在半途。

    Auth::new

    由根包创建(每个域模块的构造器都是这样,使用者拿不到伪造状态的机会)。

    Auth::set_token

    fn Auth::set_token(self : Auth, token : String?) -> Unit

    直接设置 token(从外部持久化状态恢复会话,或主动作废)。

    Auth::token

    fn Auth::token(self : Auth) -> String?

    当前 token;永久 token 一开始就有,账号密码凭证则是登录后才有。

    Auth::verify_2fa

    async fn Auth::verify_2fa(self : Auth, code : String, secret : String) -> Unit raise
    OpenListError

    用验证器上的 6 位码开启两步验证(POST /api/auth/2fa/verify)。

    LoginBody

    pub struct LoginBody {
    username : String
    password : String
    otp_code : String?
    } derive(ToJson)

    登录请求体。

    LoginBody::to_json

    fn LoginBody::to_json(LoginBody) -> Json

    显式声明 derive 出来的 ToJson 实现以普通方法暴露(消除隐式提升告警)。

    TwoFactorAuth

    pub struct TwoFactorAuth {
    qr : String
    secret : String
    }

    两步验证的初始化结果(POST /api/auth/2fa/generate)。

    TwoFactorAuth::from_json

    显式声明手写的 FromJson 实现以普通方法暴露。

    VerifyTwoFactorRequest

    pub struct VerifyTwoFactorRequest {
    code : String
    secret : String
    } derive(ToJson)

    两步验证码校验请求体(POST /api/auth/2fa/verify)。

    VerifyTwoFactorRequest::to_json

    显式声明 derive 出来的 ToJson 实现以普通方法暴露。

    Source Files