Skip to main content

keycloak_authenticated_service

Attribute Macro keycloak_authenticated_service 

Source
#[keycloak_authenticated_service]
Expand description

Attribute macro applied to impl Trait for Type blocks that injects Keycloak role-checking guards into methods annotated with #[roles(...)].

Re-exported here so consumers can write #[rust_grpc_lib::authenticated_service] without a direct dependency on grpc-macro. Attribute macro applied to an impl Trait for Type block that injects Keycloak role-checking guards into methods annotated with #[roles(...)].

§Role check variants

  • #[roles(any("r1", "r2"))] — at least one of the listed roles must be present in the JWT claims.
  • #[roles(all("r1", "r2"))] — every listed role must be present.
  • No #[roles(...)] attribute — the method is left untouched (a valid JWT is still required by the JwtValidationLayer, but no role check is injected by this macro).

§Generated code shape

ⓘ
async fn set_data(&self, request: Request<SetDataRequest>)
    -> Result<Response<SetDataResponse>, Status>
{
    {
        let __claims = request
            .extensions()
            .get::<::rust_grpc_lib::auth::KeycloakClaims>()
            .ok_or_else(|| ::tonic::Status::internal(
                "JWT claims not populated; ensure JwtValidationLayer is installed",
            ))?;
        if !["operator", "admin"].iter().any(|r| __claims.has_role(r)) {
            return Err(::tonic::Status::permission_denied("required role not present"));
        }
    }
    // original body …
}