Skip to main content

bitwarden_organizations/
lib.rs

1#![doc = include_str!("../README.md")]
2
3#[cfg(feature = "uniffi")]
4uniffi::setup_scaffolding!();
5#[cfg(feature = "uniffi")]
6mod uniffi_support;
7
8use bitwarden_uuid::uuid_newtype;
9use chrono::{DateTime, Utc};
10use serde::{Deserialize, Serialize};
11use serde_repr::{Deserialize_repr, Serialize_repr};
12use uuid::Uuid;
13
14uuid_newtype!(pub OrganizationUserId);
15
16/// The membership status of a user within an organization.
17#[derive(PartialEq, Serialize_repr, Deserialize_repr, Debug, Clone)]
18#[cfg_attr(feature = "uniffi", derive(uniffi::Enum))]
19#[bitwarden_ffi::wasm_object]
20#[repr(i8)]
21pub enum OrganizationUserStatusType {
22    /// The user's access has been revoked. This may occur at any time from any other status.
23    Revoked = -1,
24    /// The user has been invited but has not yet accepted.
25    Invited = 0,
26    /// The user has accepted the invitation but has not yet been confirmed by an admin.
27    Accepted = 1,
28    /// The user has been confirmed by an admin and has full access.
29    Confirmed = 2,
30    /// The user has been staged for provisioning but has not yet been invited.
31    Staged = 3,
32}
33
34/// The role of a user within an organization.
35#[derive(PartialEq, Serialize_repr, Deserialize_repr, Debug, Clone)]
36#[cfg_attr(feature = "uniffi", derive(uniffi::Enum))]
37#[bitwarden_ffi::wasm_object]
38#[repr(u8)]
39pub enum OrganizationUserType {
40    /// Full administrative control over the organization.
41    Owner = 0,
42    /// Administrative access with most management capabilities.
43    Admin = 1,
44    /// Standard organization member.
45    User = 2,
46    // 3 was Manager, which has been permanently deleted
47    /// User with a customized set of permissions as indicated by
48    /// [`ProfileOrganization::permissions`].
49    Custom = 4,
50}
51
52/// The type of provider.
53#[derive(Serialize_repr, Deserialize_repr, Debug, Clone)]
54#[cfg_attr(feature = "uniffi", derive(uniffi::Enum))]
55#[bitwarden_ffi::wasm_object]
56#[repr(u8)]
57pub enum ProviderType {
58    /// Managed Service Provider - sells and manages its clients' Bitwarden organizations.
59    Msp = 0,
60    /// Reseller partner - sells Bitwarden to its clients but does not have any administrative
61    /// access.
62    Reseller = 1,
63    /// Business unit provider - used to manage multiple organizations which form part of a single
64    /// large enterprise.
65    BusinessUnit = 2,
66}
67
68/// The method used to decrypt organization member data.
69#[derive(Serialize_repr, Deserialize_repr, Debug, Clone)]
70#[cfg_attr(feature = "uniffi", derive(uniffi::Enum))]
71#[bitwarden_ffi::wasm_object]
72#[repr(u8)]
73pub enum MemberDecryptionType {
74    /// Decryption using the user's master password.
75    MasterPassword = 0,
76    /// Decryption via Key Connector.
77    KeyConnector = 1,
78    /// Decryption via Trusted Device Encryption.
79    TrustedDeviceEncryption = 2,
80}
81
82/// The subscription tier of an organization.
83#[derive(Serialize_repr, Deserialize_repr, Debug, Clone)]
84#[cfg_attr(feature = "uniffi", derive(uniffi::Enum))]
85#[bitwarden_ffi::wasm_object]
86#[repr(u8)]
87pub enum ProductTierType {
88    /// Free tier with limited features.
89    Free = 0,
90    /// Families plan for personal use.
91    Families = 1,
92    /// Teams plan for small organizations.
93    Teams = 2,
94    /// Enterprise plan with full features.
95    Enterprise = 3,
96    /// Starter tier for small teams.
97    TeamsStarter = 4,
98}
99
100/// Custom administrative permissions for an organization member with the
101/// [`OrganizationUserType::Custom`] role.
102#[derive(Default, Serialize, Deserialize, Debug, Clone)]
103#[cfg_attr(feature = "uniffi", derive(uniffi::Record))]
104#[bitwarden_ffi::wasm_record]
105#[serde(rename_all = "camelCase", default)]
106pub struct Permissions {
107    /// Can view the organization's event logs.
108    pub access_event_logs: bool,
109    /// Can import and export organization vault data.
110    pub access_import_export: bool,
111    /// Can access organization reports.
112    pub access_reports: bool,
113    /// Can create new collections.
114    pub create_new_collections: bool,
115    /// Can edit any collection, including those they are not assigned to.
116    pub edit_any_collection: bool,
117    /// Can delete any collection, including those they are not assigned to.
118    pub delete_any_collection: bool,
119    /// Can manage groups within the organization.
120    pub manage_groups: bool,
121    /// Can manage SSO configuration.
122    pub manage_sso: bool,
123    /// Can manage organization policies.
124    pub manage_policies: bool,
125    /// Can manage organization members.
126    pub manage_users: bool,
127    /// Can manage the account recovery (password reset) feature.
128    pub manage_reset_password: bool,
129    /// Can manage SCIM (System for Cross-domain Identity Management) configuration.
130    pub manage_scim: bool,
131}
132
133/// Organization membership details from the user's profile sync.
134///
135/// Contains the full set of entitlements, plan features, and metadata for a single
136/// organization that the current user belongs to.
137#[derive(Serialize, Deserialize, Debug, Clone)]
138#[cfg_attr(feature = "uniffi", derive(uniffi::Record))]
139#[bitwarden_ffi::wasm_record]
140#[serde(rename_all = "camelCase")]
141pub struct ProfileOrganization {
142    /// Unique identifier for the organization.
143    pub id: Uuid,
144    /// Display name of the organization.
145    pub name: String,
146    /// The user's membership status in the organization.
147    pub status: OrganizationUserStatusType,
148    /// The user's role in the organization.
149    pub r#type: OrganizationUserType,
150    /// Whether the organization is currently enabled.
151    pub enabled: bool,
152    /// Whether the organization has access to policies features.
153    pub use_policies: bool,
154    /// Whether the organization has access to groups features.
155    pub use_groups: bool,
156    /// Whether the organization has access to directory sync features.
157    pub use_directory: bool,
158    /// Whether the organization has access to event logging features.
159    pub use_events: bool,
160    /// Whether the organization can enforce TOTP for members.
161    pub use_totp: bool,
162    /// Whether the organization has access to two-factor authentication features.
163    pub use_2fa: bool,
164    /// Whether the organization has access to the Bitwarden Public API.
165    pub use_api: bool,
166    /// Whether the organization has access to SSO features.
167    pub use_sso: bool,
168    /// Whether the organization can manage verified domains.
169    pub use_organization_domains: bool,
170    /// Whether the organization uses Key Connector for decryption.
171    pub use_key_connector: bool,
172    /// Whether the organization has access to SCIM provisioning.
173    pub use_scim: bool,
174    /// Whether the organization can use the [`OrganizationUserType::Custom`] role.
175    pub use_custom_permissions: bool,
176    /// Whether the organization has access to the account recovery (admin password reset) feature.
177    pub use_reset_password: bool,
178    /// Whether the organization has access to Secrets Manager.
179    pub use_secrets_manager: bool,
180    /// Whether the organization has access to Password Manager.
181    pub use_password_manager: bool,
182    /// Whether the organization can use the activate autofill policy.
183    pub use_activate_autofill_policy: bool,
184    /// Whether the organization can automatically confirm new members without manual admin
185    /// approval.
186    pub use_automatic_user_confirmation: bool,
187    /// Whether the organization can create a license file for a self-hosted instance.
188    pub self_host: bool,
189    /// Whether organization members receive premium features.
190    pub users_get_premium: bool,
191    /// The number of licensed seats for the organization.
192    pub seats: Option<u32>,
193    /// The maximum number of collections the organization can create.
194    pub max_collections: Option<u32>,
195    /// The maximum encrypted storage in gigabytes, if limited.
196    pub max_storage_gb: Option<u32>,
197    /// Whether the current user's account is bound to this organization via SSO.
198    pub sso_bound: bool,
199    /// The organization's SSO identifier.
200    pub identifier: Option<String>,
201    /// The current user's custom permissions, relevant when [`OrganizationUserType::Custom`] is
202    /// the user's `type`.
203    pub permissions: Permissions,
204    /// Whether the current user is enrolled in account recovery for this organization.
205    pub reset_password_enrolled: bool,
206    /// The current user's personal user ID.
207    pub user_id: Option<Uuid>,
208    /// The current user's organization membership ID.
209    pub organization_user_id: Option<Uuid>,
210    /// Whether the organization has both a public and private key configured.
211    pub has_public_and_private_keys: bool,
212    /// The ID of the provider managing this organization, if any.
213    pub provider_id: Option<Uuid>,
214    /// The name of the provider managing this organization, if any.
215    pub provider_name: Option<String>,
216    /// The type of provider managing this organization, if any.
217    pub provider_type: Option<ProviderType>,
218    /// Whether the current user accesses this organization through a provider.
219    pub is_provider_user: bool,
220    /// Whether the current user is a direct member of this organization (as opposed to
221    /// provider-only access).
222    pub is_member: bool,
223    /// The friendly name of a pending families sponsorship, if any.
224    pub family_sponsorship_friendly_name: Option<String>,
225    /// Whether the organization can sponsor a families plan for the current user.
226    pub family_sponsorship_available: bool,
227    /// The subscription tier of the organization.
228    pub product_tier_type: ProductTierType,
229    /// Whether Key Connector is enabled for this organization.
230    pub key_connector_enabled: bool,
231    /// The URL of the Key Connector service, if enabled.
232    pub key_connector_url: Option<String>,
233    /// The date the families sponsorship was last synced, if applicable.
234    pub family_sponsorship_last_sync_date: Option<DateTime<Utc>>,
235    /// The date the families sponsorship expires, if applicable.
236    pub family_sponsorship_valid_until: Option<DateTime<Utc>>,
237    /// Whether the families sponsorship is scheduled for deletion.
238    pub family_sponsorship_to_delete: Option<bool>,
239    /// Whether the current user has access to Secrets Manager for this organization.
240    pub access_secrets_manager: bool,
241    /// Whether collection creation is restricted to owners and admins only.
242    ///
243    /// When `false`, any member can create collections and automatically receives manage
244    /// permissions over collections they create.
245    pub limit_collection_creation: bool,
246    /// Whether collection deletion is restricted to owners and admins only.
247    ///
248    /// When `true`, regular users cannot delete collections that they manage.
249    pub limit_collection_deletion: bool,
250    /// Whether item deletion is restricted to members with the Manage collection permission.
251    ///
252    /// When `false`, members with Edit permission can also delete items within their collections.
253    pub limit_item_deletion: bool,
254    /// Whether owners and admins have implicit manage permissions over all collections.
255    ///
256    /// When `true`, owners and admins can alter items, groups, and permissions across all
257    /// collections without requiring explicit collection assignments.
258    /// When `false`, admins can only access collections where they have been explicitly assigned.
259    pub allow_admin_access_to_all_collection_items: bool,
260    /// Whether the current user's account is managed by this organization.
261    pub user_is_managed_by_organization: bool,
262    /// Whether the organization has access to Access Intelligence features.
263    pub use_access_intelligence: bool,
264    /// Whether the organization can sponsor families plans for members (Families For Enterprises).
265    pub use_admin_sponsored_families: bool,
266    /// Whether Secrets Manager ads are disabled for users.
267    #[serde(rename = "useDisableSMAdsForUsers")]
268    pub use_disable_sm_ads_for_users: bool,
269    /// Whether the organization's Families For Enterprises sponsorship was initiated by an admin.
270    pub is_admin_initiated: bool,
271    /// Whether SSO login is currently enabled for this organization.
272    pub sso_enabled: bool,
273    /// The decryption type used for SSO members, if SSO is enabled.
274    pub sso_member_decryption_type: Option<MemberDecryptionType>,
275    /// Whether the organization has access to phishing blocker features.
276    pub use_phishing_blocker: bool,
277    /// Whether the organization has access to the My Items collection feature.
278    /// This allows users to store personal items in the organization vault
279    /// if the Centralize Organization Ownership policy is enabled.
280    pub use_my_items: bool,
281}
282
283impl Default for ProfileOrganization {
284    fn default() -> Self {
285        ProfileOrganization {
286            id: Uuid::nil(),
287            name: String::new(),
288            status: OrganizationUserStatusType::Confirmed,
289            r#type: OrganizationUserType::User,
290            enabled: true,
291            use_policies: false,
292            use_groups: false,
293            use_directory: false,
294            use_events: false,
295            use_totp: false,
296            use_2fa: false,
297            use_api: false,
298            use_sso: false,
299            use_organization_domains: false,
300            use_key_connector: false,
301            use_scim: false,
302            use_custom_permissions: false,
303            use_reset_password: false,
304            use_secrets_manager: false,
305            use_password_manager: false,
306            use_activate_autofill_policy: false,
307            use_automatic_user_confirmation: false,
308            self_host: false,
309            users_get_premium: false,
310            seats: Some(10),
311            max_collections: None,
312            max_storage_gb: None,
313            sso_bound: false,
314            identifier: None,
315            permissions: Permissions::default(),
316            reset_password_enrolled: false,
317            user_id: None,
318            organization_user_id: None,
319            has_public_and_private_keys: false,
320            provider_id: None,
321            provider_name: None,
322            provider_type: None,
323            is_provider_user: false,
324            is_member: true,
325            family_sponsorship_friendly_name: None,
326            family_sponsorship_available: false,
327            product_tier_type: ProductTierType::Free,
328            key_connector_enabled: false,
329            key_connector_url: None,
330            family_sponsorship_last_sync_date: None,
331            family_sponsorship_valid_until: None,
332            family_sponsorship_to_delete: None,
333            access_secrets_manager: false,
334            limit_collection_creation: false,
335            limit_collection_deletion: false,
336            limit_item_deletion: false,
337            allow_admin_access_to_all_collection_items: false,
338            user_is_managed_by_organization: false,
339            use_access_intelligence: false,
340            use_admin_sponsored_families: false,
341            use_disable_sm_ads_for_users: false,
342            is_admin_initiated: false,
343            sso_enabled: false,
344            sso_member_decryption_type: None,
345            use_phishing_blocker: false,
346            use_my_items: false,
347        }
348    }
349}