Skip to main content

acme_proxy/extractors/
jws.rs

1use serde::{Deserialize, Serialize};
2
3/// Represents a JSON Web Signature (JWS) request structure used in ACME protocol.
4#[derive(Debug, Serialize, Deserialize, Clone)]
5pub struct AcmeJwsRequest {
6    pub protected: String,
7    pub signature: String,
8    pub payload: String,
9}
10
11/// Represents the JWK (JSON Web Key) structure used in ACME JWS headers.
12#[derive(Deserialize, Debug, PartialEq)]
13#[serde(tag = "kty")]
14pub enum Jwk {
15    /// RSA key type with modulus (n) and public exponent (e)
16    RSA { n: String, e: String },
17    /// Elliptic Curve key type with curve (crv) and coordinates (x, y)
18    EC { crv: String, x: String, y: String },
19}
20
21/// Represents the protected header of an ACME JWS request.
22///
23/// Deliberately *not* `deny_unknown_fields`: RFC 8555 §6.2 enumerates the
24/// fields it expects, but silently ignoring an extra member costs nothing and
25/// refusing one would reject clients over a harmless addition. `crit` is the
26/// exception — see the field below.
27#[derive(Debug, Deserialize)]
28pub struct ProtectedHeader {
29    pub alg: String,
30    pub jwk: Option<Jwk>,
31    pub kid: Option<String>,
32    pub nonce: String,
33    pub url: String,
34    /// Header extensions the sender marks as critical (RFC 7515 §4.1.11).
35    ///
36    /// This server implements no critical extension, so *every* value here is
37    /// unrecognized and the JWS must be rejected — which is why the field is
38    /// parsed at all: ignoring it would silently accept a request whose sender
39    /// demanded we understand something we do not.
40    pub crit: Option<Vec<String>>,
41}