650ed50c21
Rooms can now require a Kanidm group (via the `groups` OIDC claim, mapped by `oauth2 update-claim-map` server-side) - dev/ops require `developers`, enforced at every message path (send, history, SSE). Adds a minimal WebRTC mesh call feature scoped to the lobby room, signaled over a separate `call.room.*` NATS subject kept out of the chat archive: public STUN only, no TURN, no SFU - small groups on friendly networks, by design.
30 lines
990 B
Rust
30 lines
990 B
Rust
use leptos::prelude::*;
|
|
use serde::{Deserialize, Serialize};
|
|
|
|
/// The authenticated user, as established by the Kanidm OIDC flow and
|
|
/// stored in the server-side session.
|
|
#[derive(Clone, Debug, PartialEq, Eq, Serialize, Deserialize)]
|
|
pub struct User {
|
|
pub sub: String,
|
|
pub username: String,
|
|
pub display_name: String,
|
|
/// Kanidm group membership, from the `groups` OIDC claim (see
|
|
/// `oauth2 update-claim-map`). Fixed at login time - not re-checked
|
|
/// live, so a group change only takes effect on the next login.
|
|
#[serde(default)]
|
|
pub groups: Vec<String>,
|
|
}
|
|
|
|
pub const SESSION_USER_KEY: &str = "user";
|
|
|
|
/// Returns the currently signed-in user, if any.
|
|
#[server]
|
|
pub async fn current_user() -> Result<Option<User>, ServerFnError> {
|
|
let session: tower_sessions::Session = leptos_axum::extract().await?;
|
|
let user = session
|
|
.get::<User>(SESSION_USER_KEY)
|
|
.await
|
|
.map_err(|e| ServerFnError::new(e.to_string()))?;
|
|
Ok(user)
|
|
}
|