Behaviour for credential backends used by Sovite.SASL.Server.
A backend implements what it can:
verify_password/3enablesPLAINandLOGIN.scram_credentials/2enablesSCRAM-SHA-256.verify_token/3enablesOAUTHBEARER.
Every callback gets the backend's options last, as given in the
{module, opts} tuple. The identity returned on success is the
canonical user name, which may differ from the one the client typed
(for example lower-cased).
Errors:
:invalid- wrong password or token, or unknown user. Backends should not tell these apart to the client.:unknown_user- the user does not exist. Treated like:invalid;Sovite.SASL.Serveruses it only to hide the difference.:unavailable- the user exists but has no credentials for this mechanism, such as a crypt hash forSCRAM-SHA-256.{:temporary, reason}- the backend cannot answer now (database down, timeout). The client is told to try again later.
Summary
Callbacks
Checks an OAuth 2.0 bearer token. username is the authorization
identity the client named, or nil; when given, the token must belong
to that user.
Types
@type error() :: :invalid | :unknown_user | :unavailable | {:temporary, term()}
Callbacks
@callback scram_credentials(username :: String.t(), opts :: keyword()) :: {:ok, Sovite.SASL.Password.scram(), identity :: String.t()} | {:error, error()}
@callback verify_token( username :: String.t() | nil, token :: String.t(), opts :: keyword() ) :: {:ok, identity :: String.t()} | {:error, error()}
Checks an OAuth 2.0 bearer token. username is the authorization
identity the client named, or nil; when given, the token must belong
to that user.