Skip to main content

TokenCache

Struct TokenCache 

Source
pub struct TokenCache { /* private fields */ }
Expand description

In-memory cache for AS-issued machine tokens.

Tokens are evicted ttl_buffer_seconds before their actual expiry so the SDK never returns a token that is about to die mid-request.

Implementations§

Source§

impl TokenCache

Source

pub const DEFAULT_TTL_BUFFER_SECONDS: f64 = 30.0

Default TTL buffer applied before token expiry on every get.

Source

pub const DEFAULT_TTL_SECONDS: f64 = 3600.0

Default fallback TTL when the AS does not supply expires_in.

Source

pub const MAX_CACHE_TTL_SECONDS: i64

Upper bound clamp for AS-supplied expires_in values, in seconds. Instant + Duration panics on overflow, so an absurd AS reply (e.g. i64::MAX) cannot flow through unchecked. 30 days is well above any realistic access-token lifetime.

Source

pub fn new() -> Self

Source

pub fn with_config(ttl_buffer_seconds: f64, default_ttl_seconds: f64) -> Self

Source

pub fn get(&self, key: &str) -> Option<CachedToken>

Get a cached token if it exists and has not expired (after applying the buffer).

Source

pub fn set( &self, key: &str, access_token: &str, token_type: &str, expires_in: Option<i64>, scope: &str, cnf: Option<&Value>, cnf_jkt: &str, )

Insert a token into the cache. Skips caching if the effective TTL (after buffer) would be non-positive.

expires_in follows the TokenResponse::expires_in semantics:

  • None — the AS omitted the hint; the cache applies its configured default_ttl (then the buffer).
  • Some(0) — the AS asked for immediate expiry (RFC 6749 §5.1 permits this for one-shot flows). The entry is not stored, since it would be born expired.
  • Some(n) with n > 0 — use n seconds, then apply the buffer. Clamped to MAX_CACHE_TTL_SECONDS both for the live TTL and for the hint preserved on CachedToken::expires_in, so the stored value never advertises a lifetime the cache will not actually honour. The clamp also keeps Instant + Duration from overflowing on an absurd AS reply.

cnf / cnf_jkt preserve the DPoP confirmation binding through cache round-trips (RFC 9449 §6.1). Pass None / "" for plain bearer tokens.

Source

pub fn delete(&self, key: &str)

Remove a cached entry.

Source

pub fn len(&self) -> usize

Number of currently-stored entries (test/admin helper).

Source

pub fn is_empty(&self) -> bool

Whether the cache is empty.

Source

pub fn cache_key(scope: &str, resource: &str) -> String

Build a deterministic cache key from scope + resource.

Scope tokens are sorted so the key is order-independent.

Trait Implementations§

Source§

impl Debug for TokenCache

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for TokenCache

Source§

fn default() -> Self

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more