pub struct TokenCache { /* private fields */ }Expand description
In-memory cache for AS-issued machine tokens.
Tokens are evicted ttl_buffer_seconds before their actual expiry so the
SDK never returns a token that is about to die mid-request.
Implementations§
Source§impl TokenCache
impl TokenCache
Sourcepub const DEFAULT_TTL_BUFFER_SECONDS: f64 = 30.0
pub const DEFAULT_TTL_BUFFER_SECONDS: f64 = 30.0
Default TTL buffer applied before token expiry on every get.
Sourcepub const DEFAULT_TTL_SECONDS: f64 = 3600.0
pub const DEFAULT_TTL_SECONDS: f64 = 3600.0
Default fallback TTL when the AS does not supply expires_in.
Sourcepub const MAX_CACHE_TTL_SECONDS: i64
pub const MAX_CACHE_TTL_SECONDS: i64
Upper bound clamp for AS-supplied expires_in values, in seconds.
Instant + Duration panics on overflow, so an absurd AS reply
(e.g. i64::MAX) cannot flow through unchecked. 30 days is well
above any realistic access-token lifetime.
pub fn new() -> Self
pub fn with_config(ttl_buffer_seconds: f64, default_ttl_seconds: f64) -> Self
Sourcepub fn get(&self, key: &str) -> Option<CachedToken>
pub fn get(&self, key: &str) -> Option<CachedToken>
Get a cached token if it exists and has not expired (after applying the buffer).
Sourcepub fn set(
&self,
key: &str,
access_token: &str,
token_type: &str,
expires_in: Option<i64>,
scope: &str,
cnf: Option<&Value>,
cnf_jkt: &str,
)
pub fn set( &self, key: &str, access_token: &str, token_type: &str, expires_in: Option<i64>, scope: &str, cnf: Option<&Value>, cnf_jkt: &str, )
Insert a token into the cache. Skips caching if the effective TTL (after buffer) would be non-positive.
expires_in follows the TokenResponse::expires_in semantics:
None— the AS omitted the hint; the cache applies its configureddefault_ttl(then the buffer).Some(0)— the AS asked for immediate expiry (RFC 6749 §5.1 permits this for one-shot flows). The entry is not stored, since it would be born expired.Some(n)withn > 0— usenseconds, then apply the buffer. Clamped toMAX_CACHE_TTL_SECONDSboth for the live TTL and for the hint preserved onCachedToken::expires_in, so the stored value never advertises a lifetime the cache will not actually honour. The clamp also keepsInstant + Durationfrom overflowing on an absurd AS reply.
cnf / cnf_jkt preserve the DPoP confirmation binding through
cache round-trips (RFC 9449 §6.1). Pass None / "" for plain
bearer tokens.