pub struct Claims {
pub sub: String,
pub email: String,
pub name: String,
pub iss: String,
pub aud: String,
pub exp: i64,
pub iat: i64,
pub nbf: Option<i64>,
pub sid: String,
pub scope: Vec<String>,
pub roles: Vec<String>,
pub attrs: BTreeMap<String, Vec<String>>,
}Expand description
Verified token claims. Mirrors the auth-service Claims exactly so a
token signed there round-trips here. sub carries the user pid.
The field set is a contract with the auth-service: the service defines
an identical struct, and changing one without the other breaks token
round-tripping. exp / iat / nbf are unix seconds.
Fields§
§sub: StringSubject — the user pid (UUID string); the stable identifier a
peer service keys its authorization on.
email: StringUser email, surfaced for convenience at the edge; not used for authorization decisions.
name: StringHuman-readable display name carried alongside the subject.
iss: StringIssuer (iss) — the auth-service that minted the token. Checked
against the verifier’s configured issuer.
aud: StringAudience (aud) — the intended recipient service. Checked against
the verifier’s configured audience so a token issued for one peer
cannot be replayed against another.
exp: i64Expiry (exp), unix seconds. Tokens at or past this instant are
rejected. Issued ~5 minutes out (the session is the durable thing).
iat: i64Issued-at (iat), unix seconds — when the token was minted.
nbf: Option<i64>Not-before (nbf), unix seconds. When present, tokens before this
instant are rejected. Omitted from the wire form when None.
sid: StringSession id (sid) — the originating server-side session, so a
token can be correlated back to (and revoked with) its session.
scope: Vec<String>Granted scopes, if any. Empty when the token carries none.
Deprecated for authorization (kept on the wire for
compatibility; removal is a future major): the ABAC guard ignores
scope and decides from attrs instead. See
agents/share/authorization-attributes.md §3.
roles: Vec<String>Granted roles, if any. Empty when the token carries none.
Deprecated for authorization (kept on the wire for
compatibility; removal is a future major): the ABAC guard ignores
roles and decides from attrs instead — a role,
where one is wanted, is just another attribute (role=editor).
See agents/share/authorization-attributes.md §3.
attrs: BTreeMap<String, Vec<String>>Subject attributes for ABAC authorization — a string→strings map
minted by the auth-service from the user’s assigned attributes
(e.g. access: ["write"], dept: ["cardiology"],
svc: ["true"] for machine peers). Multi-valued keys mean “has
each of these values”; policies match set-membership; unknown
attributes are inert (forward-compatible). Absent on the wire
(old tokens) ⇒ empty map — no re-issue needed. Evaluated by the
abac engine per agents/share/authorization-attributes.md
§2–§3, alongside the pseudo-attributes sub and email.