refactor(dpop): apply clippy
This commit is contained in:
@@ -21,6 +21,29 @@ use uuid::Uuid;
|
||||
|
||||
use crate::domain::entities::session::Session;
|
||||
|
||||
/// Authenticated-caller context — the caller's identity + session-
|
||||
/// bound signals a service method might key off. Constructed at the
|
||||
/// handler boundary from `AuthUser` and passed through unchanged;
|
||||
/// keeps service signatures flat instead of accumulating parallel
|
||||
/// `caller_id`, `caller_jkt`, `caller_ip` parameters. Every
|
||||
/// caller-context field lives here, one place to extend.
|
||||
///
|
||||
/// Not admin-specific — any handler that needs caller context can
|
||||
/// build one from `AuthUser`. Admin methods just happen to be the
|
||||
/// first callers (sessions panel's `is_current` comparison and
|
||||
/// audit lines).
|
||||
#[derive(Debug, Clone)]
|
||||
pub struct SessionCaller<'a> {
|
||||
/// AuthZ subject — used by `require_admin_caller` and audit lines.
|
||||
pub id: Uuid,
|
||||
/// Caller's own DPoP thumbprint from the JWT `cnf.jkt` claim.
|
||||
/// Enables the sessions panel's "you are here" highlight
|
||||
/// ([`SessionSummaryDto::is_current`]) — `None` when the caller
|
||||
/// logged in via an unbound path (legacy password without DPoP,
|
||||
/// pre-bind OIDC redirect, etc.).
|
||||
pub dpop_jkt: Option<&'a str>,
|
||||
}
|
||||
|
||||
/// Wire shape for `GET /api/admin/sessions`. Contains everything the
|
||||
/// admin table renders and **nothing the raw session entity would
|
||||
/// leak** (refresh token, OIDC ID-token, full DPoP thumbprint).
|
||||
@@ -75,9 +98,7 @@ impl SessionSummaryDto {
|
||||
let is_revoked = s.is_revoked();
|
||||
let is_expired = s.is_expired();
|
||||
let jkt = s.dpop_jkt().map(|s| s.to_owned());
|
||||
let dpop_jkt_prefix = jkt
|
||||
.as_ref()
|
||||
.map(|t| t.chars().take(8).collect::<String>());
|
||||
let dpop_jkt_prefix = jkt.as_ref().map(|t| t.chars().take(8).collect::<String>());
|
||||
let is_current = match (jkt.as_deref(), caller_jkt) {
|
||||
(Some(row), Some(caller)) => row == caller,
|
||||
_ => false,
|
||||
|
||||
@@ -2962,14 +2962,13 @@ impl AuthApplicationService {
|
||||
pub async fn admin_list_sessions_with_perms<A: AuthorizationEngine>(
|
||||
&self,
|
||||
authorization: &A,
|
||||
caller_id: Uuid,
|
||||
caller_dpop_jkt: Option<&str>,
|
||||
caller: crate::application::dtos::session_dto::SessionCaller<'_>,
|
||||
user_id_filter: Option<Uuid>,
|
||||
include_revoked: bool,
|
||||
limit: i64,
|
||||
offset: i64,
|
||||
) -> Result<Vec<crate::application::dtos::session_dto::SessionSummaryDto>, DomainError> {
|
||||
self.require_admin_caller(authorization, caller_id).await?;
|
||||
self.require_admin_caller(authorization, caller.id).await?;
|
||||
let sessions = self
|
||||
.session_storage
|
||||
.list_sessions_paginated(user_id_filter, include_revoked, limit, offset)
|
||||
@@ -2979,7 +2978,7 @@ impl AuthApplicationService {
|
||||
.map(|s| {
|
||||
crate::application::dtos::session_dto::SessionSummaryDto::from_session(
|
||||
s,
|
||||
caller_dpop_jkt,
|
||||
caller.dpop_jkt,
|
||||
)
|
||||
})
|
||||
.collect())
|
||||
@@ -2994,10 +2993,10 @@ impl AuthApplicationService {
|
||||
pub async fn admin_revoke_session_with_perms<A: AuthorizationEngine>(
|
||||
&self,
|
||||
authorization: &A,
|
||||
caller_id: Uuid,
|
||||
caller: crate::application::dtos::session_dto::SessionCaller<'_>,
|
||||
session_id: Uuid,
|
||||
) -> Result<(), DomainError> {
|
||||
self.require_admin_caller(authorization, caller_id).await?;
|
||||
self.require_admin_caller(authorization, caller.id).await?;
|
||||
// Resolve target user for the audit line before revocation —
|
||||
// once the session row is revoked the user_id is still readable
|
||||
// but the ORDER is stable this way.
|
||||
@@ -3011,7 +3010,7 @@ impl AuthApplicationService {
|
||||
tracing::info!(
|
||||
target: "audit",
|
||||
event = "admin.session_revoked",
|
||||
caller_id = %caller_id,
|
||||
caller_id = %caller.id,
|
||||
session_id = %session_id,
|
||||
target_user_id = target_user_id.map(|u| u.to_string()).unwrap_or_default(),
|
||||
"👮🏻♂️ Admin revoked session",
|
||||
|
||||
Reference in New Issue
Block a user