pub struct ConsumerRestrictionPlugin {
restriction_type: RestrictionType,
whitelist: Vec<String>,
blacklist: Vec<String>,
allowed_by_methods: Vec<AllowedByMethod>,
rejected_code: u16,
rejected_msg: Option<String>,
}Expand description
Restricts access based on the attached consumer’s name or group.
Evaluation mirrors APISIX: the blacklist is checked first (a match
rejects), then the whitelist (a non-match rejects), then — only for
consumers not already cleared by the whitelist — allowed_by_methods. When
no consumer is attached the request is rejected 401; list rejections use
rejected_code (default 403). All rejections carry error code
CONSUMER_RESTRICTED.
Fields§
§restriction_type: RestrictionTypeWhich consumer attribute the lists match (consumer_name / consumer_group_id).
whitelist: Vec<String>When non-empty, the value must be present or the request is rejected.
blacklist: Vec<String>When non-empty, a matching value is rejected.
allowed_by_methods: Vec<AllowedByMethod>Per-consumer HTTP-method allowlists.
rejected_code: u16HTTP status used for list rejections.
rejected_msg: Option<String>Optional custom rejection message.
Implementations§
Source§impl ConsumerRestrictionPlugin
impl ConsumerRestrictionPlugin
Sourcepub fn from_config(config: &HashMap<String, Value>) -> Result<Self, String>
pub fn from_config(config: &HashMap<String, Value>) -> Result<Self, String>
Builds the plugin from node config, failing fast on invalid combinations.
Accepted keys:
type(string, default"consumer_name"): the consumer attribute the lists match. Supported:consumer_name(matchesconsumer.name) andconsumer_group_id(matchesconsumer.group).service_idandroute_idexist in APISIX but have no featherbit analogue and are rejected at config load.whitelist(array of strings): values allowed through; a consumer whose value is absent is rejected. Mutually exclusive withblacklist.blacklist(array of strings): values rejected on match.allowed_by_methods(array of{ user, methods }): restricts the named consumer to the listed HTTP methods.- At least one of
whitelist/blacklist/allowed_by_methodsis required. rejected_code(integer, default403): status for list rejections.rejected_msg(string, optional): custom rejection message.
type: consumer-restriction
config:
type: consumer_name
whitelist: ["alice", "bob"]
allowed_by_methods:
- user: alice
methods: ["GET", "POST"]
rejected_code: 403
rejected_msg: "You shall not pass"Sourcefn value_key(&self) -> &'static str
fn value_key(&self) -> &'static str
The context.message key holding the value this instance matches on.
Sourcefn type_label(&self) -> &'static str
fn type_label(&self) -> &'static str
Human label for the configured type, used in default messages.
Sourcefn reject(
&self,
ctx: Context,
status: u16,
message: String,
) -> Result<PluginOutput, PluginExecutionError>
fn reject( &self, ctx: Context, status: u16, message: String, ) -> Result<PluginOutput, PluginExecutionError>
Builds a rejection carrying the context so the graph routes the error port.
Trait Implementations§
Source§impl Plugin for ConsumerRestrictionPlugin
impl Plugin for ConsumerRestrictionPlugin
Source§fn plugin_type(&self) -> &str
fn plugin_type(&self) -> &str
Source§fn execute<'life0, 'life1, 'async_trait>(
&'life0 self,
ctx: Context,
_named_inputs: &'life1 HashMap<String, Value>,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn execute<'life0, 'life1, 'async_trait>(
&'life0 self,
ctx: Context,
_named_inputs: &'life1 HashMap<String, Value>,
) -> Pin<Box<dyn Future<Output = Result<PluginOutput, PluginExecutionError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Auto Trait Implementations§
impl Freeze for ConsumerRestrictionPlugin
impl RefUnwindSafe for ConsumerRestrictionPlugin
impl Send for ConsumerRestrictionPlugin
impl Sync for ConsumerRestrictionPlugin
impl Unpin for ConsumerRestrictionPlugin
impl UnsafeUnpin for ConsumerRestrictionPlugin
impl UnwindSafe for ConsumerRestrictionPlugin
Blanket Implementations§
§impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedExplicit<'a, E> for Twhere
T: 'a,
§impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
impl<'a, T, E> AsTaggedImplicit<'a, E> for Twhere
T: 'a,
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
§impl<T> Instrument for T
impl<T> Instrument for T
§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more