bitwarden_organizations/lib.rs
1#![doc = include_str!("../README.md")]
2
3#[cfg(feature = "uniffi")]
4uniffi::setup_scaffolding!();
5#[cfg(feature = "uniffi")]
6mod uniffi_support;
7
8use bitwarden_uuid::uuid_newtype;
9use chrono::{DateTime, Utc};
10use serde::{Deserialize, Serialize};
11use serde_repr::{Deserialize_repr, Serialize_repr};
12use uuid::Uuid;
13
14uuid_newtype!(pub OrganizationUserId);
15
16/// The membership status of a user within an organization.
17#[derive(PartialEq, Serialize_repr, Deserialize_repr, Debug, Clone)]
18#[cfg_attr(feature = "uniffi", derive(uniffi::Enum))]
19#[bitwarden_ffi::wasm_object]
20#[repr(i8)]
21pub enum OrganizationUserStatusType {
22 /// The user's access has been revoked. This may occur at any time from any other status.
23 Revoked = -1,
24 /// The user has been invited but has not yet accepted.
25 Invited = 0,
26 /// The user has accepted the invitation but has not yet been confirmed by an admin.
27 Accepted = 1,
28 /// The user has been confirmed by an admin and has full access.
29 Confirmed = 2,
30 /// The user has been staged for provisioning but has not yet been invited.
31 Staged = 3,
32}
33
34/// The role of a user within an organization.
35#[derive(PartialEq, Serialize_repr, Deserialize_repr, Debug, Clone)]
36#[cfg_attr(feature = "uniffi", derive(uniffi::Enum))]
37#[bitwarden_ffi::wasm_object]
38#[repr(u8)]
39pub enum OrganizationUserType {
40 /// Full administrative control over the organization.
41 Owner = 0,
42 /// Administrative access with most management capabilities.
43 Admin = 1,
44 /// Standard organization member.
45 User = 2,
46 // 3 was Manager, which has been permanently deleted
47 /// User with a customized set of permissions as indicated by
48 /// [`ProfileOrganization::permissions`].
49 Custom = 4,
50}
51
52/// The type of provider.
53#[derive(Serialize_repr, Deserialize_repr, Debug, Clone)]
54#[cfg_attr(feature = "uniffi", derive(uniffi::Enum))]
55#[bitwarden_ffi::wasm_object]
56#[repr(u8)]
57pub enum ProviderType {
58 /// Managed Service Provider - sells and manages its clients' Bitwarden organizations.
59 Msp = 0,
60 /// Reseller partner - sells Bitwarden to its clients but does not have any administrative
61 /// access.
62 Reseller = 1,
63 /// Business unit provider - used to manage multiple organizations which form part of a single
64 /// large enterprise.
65 BusinessUnit = 2,
66}
67
68/// The method used to decrypt organization member data.
69#[derive(Serialize_repr, Deserialize_repr, Debug, Clone)]
70#[cfg_attr(feature = "uniffi", derive(uniffi::Enum))]
71#[bitwarden_ffi::wasm_object]
72#[repr(u8)]
73pub enum MemberDecryptionType {
74 /// Decryption using the user's master password.
75 MasterPassword = 0,
76 /// Decryption via Key Connector.
77 KeyConnector = 1,
78 /// Decryption via Trusted Device Encryption.
79 TrustedDeviceEncryption = 2,
80}
81
82/// The subscription tier of an organization.
83#[derive(Serialize_repr, Deserialize_repr, Debug, Clone)]
84#[cfg_attr(feature = "uniffi", derive(uniffi::Enum))]
85#[bitwarden_ffi::wasm_object]
86#[repr(u8)]
87pub enum ProductTierType {
88 /// Free tier with limited features.
89 Free = 0,
90 /// Families plan for personal use.
91 Families = 1,
92 /// Teams plan for small organizations.
93 Teams = 2,
94 /// Enterprise plan with full features.
95 Enterprise = 3,
96 /// Starter tier for small teams.
97 TeamsStarter = 4,
98}
99
100/// Custom administrative permissions for an organization member with the
101/// [`OrganizationUserType::Custom`] role.
102#[derive(Default, Serialize, Deserialize, Debug, Clone)]
103#[cfg_attr(feature = "uniffi", derive(uniffi::Record))]
104#[bitwarden_ffi::wasm_record]
105#[serde(rename_all = "camelCase", default)]
106pub struct Permissions {
107 /// Can view the organization's event logs.
108 pub access_event_logs: bool,
109 /// Can import and export organization vault data.
110 pub access_import_export: bool,
111 /// Can access organization reports.
112 pub access_reports: bool,
113 /// Can create new collections.
114 pub create_new_collections: bool,
115 /// Can edit any collection, including those they are not assigned to.
116 pub edit_any_collection: bool,
117 /// Can delete any collection, including those they are not assigned to.
118 pub delete_any_collection: bool,
119 /// Can manage groups within the organization.
120 pub manage_groups: bool,
121 /// Can manage SSO configuration.
122 pub manage_sso: bool,
123 /// Can manage organization policies.
124 pub manage_policies: bool,
125 /// Can manage organization members.
126 pub manage_users: bool,
127 /// Can manage the account recovery (password reset) feature.
128 pub manage_reset_password: bool,
129 /// Can manage SCIM (System for Cross-domain Identity Management) configuration.
130 pub manage_scim: bool,
131}
132
133/// Organization membership details from the user's profile sync.
134///
135/// Contains the full set of entitlements, plan features, and metadata for a single
136/// organization that the current user belongs to.
137#[derive(Serialize, Deserialize, Debug, Clone)]
138#[cfg_attr(feature = "uniffi", derive(uniffi::Record))]
139#[bitwarden_ffi::wasm_record]
140#[serde(rename_all = "camelCase")]
141pub struct ProfileOrganization {
142 /// Unique identifier for the organization.
143 pub id: Uuid,
144 /// Display name of the organization.
145 pub name: String,
146 /// The user's membership status in the organization.
147 pub status: OrganizationUserStatusType,
148 /// The user's role in the organization.
149 pub r#type: OrganizationUserType,
150 /// Whether the organization is currently enabled.
151 pub enabled: bool,
152 /// Whether the organization has access to policies features.
153 pub use_policies: bool,
154 /// Whether the organization has access to groups features.
155 pub use_groups: bool,
156 /// Whether the organization has access to directory sync features.
157 pub use_directory: bool,
158 /// Whether the organization has access to event logging features.
159 pub use_events: bool,
160 /// Whether the organization can enforce TOTP for members.
161 pub use_totp: bool,
162 /// Whether the organization has access to two-factor authentication features.
163 pub use_2fa: bool,
164 /// Whether the organization has access to the Bitwarden Public API.
165 pub use_api: bool,
166 /// Whether the organization has access to SSO features.
167 pub use_sso: bool,
168 /// Whether the organization can manage verified domains.
169 pub use_organization_domains: bool,
170 /// Whether the organization uses Key Connector for decryption.
171 pub use_key_connector: bool,
172 /// Whether the organization has access to SCIM provisioning.
173 pub use_scim: bool,
174 /// Whether the organization can use the [`OrganizationUserType::Custom`] role.
175 pub use_custom_permissions: bool,
176 /// Whether the organization has access to the account recovery (admin password reset) feature.
177 pub use_reset_password: bool,
178 /// Whether the organization has access to Secrets Manager.
179 pub use_secrets_manager: bool,
180 /// Whether the organization has access to Password Manager.
181 pub use_password_manager: bool,
182 /// Whether the organization can use the activate autofill policy.
183 pub use_activate_autofill_policy: bool,
184 /// Whether the organization can automatically confirm new members without manual admin
185 /// approval.
186 pub use_automatic_user_confirmation: bool,
187 /// Whether the organization can create a license file for a self-hosted instance.
188 pub self_host: bool,
189 /// Whether organization members receive premium features.
190 pub users_get_premium: bool,
191 /// The number of licensed seats for the organization.
192 pub seats: Option<u32>,
193 /// The maximum number of collections the organization can create.
194 pub max_collections: Option<u32>,
195 /// The maximum encrypted storage in gigabytes, if limited.
196 pub max_storage_gb: Option<u32>,
197 /// Whether the current user's account is bound to this organization via SSO.
198 pub sso_bound: bool,
199 /// The organization's SSO identifier.
200 pub identifier: Option<String>,
201 /// The current user's custom permissions, relevant when [`OrganizationUserType::Custom`] is
202 /// the user's `type`.
203 pub permissions: Permissions,
204 /// Whether the current user is enrolled in account recovery for this organization.
205 pub reset_password_enrolled: bool,
206 /// The current user's personal user ID.
207 pub user_id: Option<Uuid>,
208 /// The current user's organization membership ID.
209 pub organization_user_id: Option<Uuid>,
210 /// Whether the organization has both a public and private key configured.
211 pub has_public_and_private_keys: bool,
212 /// The ID of the provider managing this organization, if any.
213 pub provider_id: Option<Uuid>,
214 /// The name of the provider managing this organization, if any.
215 pub provider_name: Option<String>,
216 /// The type of provider managing this organization, if any.
217 pub provider_type: Option<ProviderType>,
218 /// Whether the current user accesses this organization through a provider.
219 pub is_provider_user: bool,
220 /// Whether the current user is a direct member of this organization (as opposed to
221 /// provider-only access).
222 pub is_member: bool,
223 /// The friendly name of a pending families sponsorship, if any.
224 pub family_sponsorship_friendly_name: Option<String>,
225 /// Whether the organization can sponsor a families plan for the current user.
226 pub family_sponsorship_available: bool,
227 /// The subscription tier of the organization.
228 pub product_tier_type: ProductTierType,
229 /// Whether Key Connector is enabled for this organization.
230 pub key_connector_enabled: bool,
231 /// The URL of the Key Connector service, if enabled.
232 pub key_connector_url: Option<String>,
233 /// The date the families sponsorship was last synced, if applicable.
234 pub family_sponsorship_last_sync_date: Option<DateTime<Utc>>,
235 /// The date the families sponsorship expires, if applicable.
236 pub family_sponsorship_valid_until: Option<DateTime<Utc>>,
237 /// Whether the families sponsorship is scheduled for deletion.
238 pub family_sponsorship_to_delete: Option<bool>,
239 /// Whether the current user has access to Secrets Manager for this organization.
240 pub access_secrets_manager: bool,
241 /// Whether collection creation is restricted to owners and admins only.
242 ///
243 /// When `false`, any member can create collections and automatically receives manage
244 /// permissions over collections they create.
245 pub limit_collection_creation: bool,
246 /// Whether collection deletion is restricted to owners and admins only.
247 ///
248 /// When `true`, regular users cannot delete collections that they manage.
249 pub limit_collection_deletion: bool,
250 /// Whether item deletion is restricted to members with the Manage collection permission.
251 ///
252 /// When `false`, members with Edit permission can also delete items within their collections.
253 pub limit_item_deletion: bool,
254 /// Whether owners and admins have implicit manage permissions over all collections.
255 ///
256 /// When `true`, owners and admins can alter items, groups, and permissions across all
257 /// collections without requiring explicit collection assignments.
258 /// When `false`, admins can only access collections where they have been explicitly assigned.
259 pub allow_admin_access_to_all_collection_items: bool,
260 /// Whether the current user's account is managed by this organization.
261 pub user_is_managed_by_organization: bool,
262 /// Whether the organization has access to Access Intelligence features.
263 pub use_access_intelligence: bool,
264 /// Whether the organization can sponsor families plans for members (Families For Enterprises).
265 pub use_admin_sponsored_families: bool,
266 /// Whether Secrets Manager ads are disabled for users.
267 #[serde(rename = "useDisableSMAdsForUsers")]
268 pub use_disable_sm_ads_for_users: bool,
269 /// Whether the organization's Families For Enterprises sponsorship was initiated by an admin.
270 pub is_admin_initiated: bool,
271 /// Whether SSO login is currently enabled for this organization.
272 pub sso_enabled: bool,
273 /// The decryption type used for SSO members, if SSO is enabled.
274 pub sso_member_decryption_type: Option<MemberDecryptionType>,
275 /// Whether the organization has access to phishing blocker features.
276 pub use_phishing_blocker: bool,
277 /// Whether the organization has access to the My Items collection feature.
278 /// This allows users to store personal items in the organization vault
279 /// if the Centralize Organization Ownership policy is enabled.
280 pub use_my_items: bool,
281}
282
283impl Default for ProfileOrganization {
284 fn default() -> Self {
285 ProfileOrganization {
286 id: Uuid::nil(),
287 name: String::new(),
288 status: OrganizationUserStatusType::Confirmed,
289 r#type: OrganizationUserType::User,
290 enabled: true,
291 use_policies: false,
292 use_groups: false,
293 use_directory: false,
294 use_events: false,
295 use_totp: false,
296 use_2fa: false,
297 use_api: false,
298 use_sso: false,
299 use_organization_domains: false,
300 use_key_connector: false,
301 use_scim: false,
302 use_custom_permissions: false,
303 use_reset_password: false,
304 use_secrets_manager: false,
305 use_password_manager: false,
306 use_activate_autofill_policy: false,
307 use_automatic_user_confirmation: false,
308 self_host: false,
309 users_get_premium: false,
310 seats: Some(10),
311 max_collections: None,
312 max_storage_gb: None,
313 sso_bound: false,
314 identifier: None,
315 permissions: Permissions::default(),
316 reset_password_enrolled: false,
317 user_id: None,
318 organization_user_id: None,
319 has_public_and_private_keys: false,
320 provider_id: None,
321 provider_name: None,
322 provider_type: None,
323 is_provider_user: false,
324 is_member: true,
325 family_sponsorship_friendly_name: None,
326 family_sponsorship_available: false,
327 product_tier_type: ProductTierType::Free,
328 key_connector_enabled: false,
329 key_connector_url: None,
330 family_sponsorship_last_sync_date: None,
331 family_sponsorship_valid_until: None,
332 family_sponsorship_to_delete: None,
333 access_secrets_manager: false,
334 limit_collection_creation: false,
335 limit_collection_deletion: false,
336 limit_item_deletion: false,
337 allow_admin_access_to_all_collection_items: false,
338 user_is_managed_by_organization: false,
339 use_access_intelligence: false,
340 use_admin_sponsored_families: false,
341 use_disable_sm_ads_for_users: false,
342 is_admin_initiated: false,
343 sso_enabled: false,
344 sso_member_decryption_type: None,
345 use_phishing_blocker: false,
346 use_my_items: false,
347 }
348 }
349}