acme_proxy/extractors/jws.rs
1use serde::{Deserialize, Serialize};
2
3/// Represents a JSON Web Signature (JWS) request structure used in ACME protocol.
4#[derive(Debug, Serialize, Deserialize, Clone)]
5pub struct AcmeJwsRequest {
6 pub protected: String,
7 pub signature: String,
8 pub payload: String,
9}
10
11/// Represents the JWK (JSON Web Key) structure used in ACME JWS headers.
12#[derive(Deserialize, Debug, PartialEq)]
13#[serde(tag = "kty")]
14pub enum Jwk {
15 /// RSA key type with modulus (n) and public exponent (e)
16 RSA { n: String, e: String },
17 /// Elliptic Curve key type with curve (crv) and coordinates (x, y)
18 EC { crv: String, x: String, y: String },
19}
20
21/// Represents the protected header of an ACME JWS request.
22///
23/// Deliberately *not* `deny_unknown_fields`: RFC 8555 §6.2 enumerates the
24/// fields it expects, but silently ignoring an extra member costs nothing and
25/// refusing one would reject clients over a harmless addition. `crit` is the
26/// exception — see the field below.
27#[derive(Debug, Deserialize)]
28pub struct ProtectedHeader {
29 pub alg: String,
30 pub jwk: Option<Jwk>,
31 pub kid: Option<String>,
32 pub nonce: String,
33 pub url: String,
34 /// Header extensions the sender marks as critical (RFC 7515 §4.1.11).
35 ///
36 /// This server implements no critical extension, so *every* value here is
37 /// unrecognized and the JWS must be rejected — which is why the field is
38 /// parsed at all: ignoring it would silently accept a request whose sender
39 /// demanded we understand something we do not.
40 pub crit: Option<Vec<String>>,
41}