acme_proxy_protocol/extractors/mod.rs
1//! Request extraction and JWS verification — the security core of the crate.
2//!
3//! [`acme`] holds the shared `verify_jws` routine and the three extractors
4//! built on it: `AcmeRequest<T>` (a decoded payload), `AcmePostAsGet` (an empty
5//! payload, per RFC 8555 §6.3) and `AcmeOptionalPayload<T>` (either, which the
6//! authorization resource needs because one URL serves both a read and a
7//! §7.5.2 deactivation).
8//!
9//! Hoisting the protocol checks here is deliberate: the media type, any `crit`
10//! header, the signature, the JWS `url` (§6.4) and the nonce (§6.5) are all
11//! verified before a handler runs, so the guarantees are structural rather than
12//! a convention each handler has to observe.
13//!
14//! The wire types and the cryptography they run are [`acme_proxy_core::jws`].
15
16pub mod acme;
17
18pub use acme::*;