pub struct CachedToken {
pub access_token: String,
pub token_type: String,
pub expires_in: Option<i64>,
pub scope: String,
pub cnf: Option<Value>,
pub cnf_jkt: String,
}Expand description
A cached access-token entry.
Fields§
§access_token: String§token_type: String§expires_in: Option<i64>AS-supplied lifetime hint, preserved across the cache boundary so a
caller that schedules its own refresh off TokenResponse.expires_in
sees the same None / Some(N) distinction it would have gotten
from a fresh AS round-trip. Positive values are clamped to
TokenCache::MAX_CACHE_TTL_SECONDS before storage, matching the
clamp applied to the live TTL — so a caller scheduling its own
refresh sees the same upper bound the cache will honour.
scope: String§cnf: Option<Value>Raw cnf confirmation object from the AS token response (RFC 9449
§6.1). Preserved verbatim so a token that was issued as
DPoP-bound still looks DPoP-bound on cache hits — without this,
downstream code gating on cnf / cnf_jkt sees the wrong shape
the moment a token round-trips through the cache and silently
loses its sender-constrained guarantee.
cnf_jkt: StringDPoP key thumbprint at cnf.jkt, mirrored from the source
TokenResponse. Empty string when the cached token is not
DPoP-bound.
Trait Implementations§
Source§impl Clone for CachedToken
impl Clone for CachedToken
Source§impl Debug for CachedToken
impl Debug for CachedToken
Source§impl From<CachedToken> for TokenResponse
impl From<CachedToken> for TokenResponse
Source§fn from(cached: CachedToken) -> Self
fn from(cached: CachedToken) -> Self
Rehydrate a TokenResponse from a cached entry. refresh_token and
issued_token_type default to empty — client_credentials responses
never carry them. cnf and cnf_jkt are preserved verbatim from the
cache so a DPoP-bound token still looks DPoP-bound on cache hits.