#[non_exhaustive]pub struct TokenResponse {
pub access_token: String,
pub token_type: String,
pub expires_in: Option<i64>,
pub scope: String,
pub refresh_token: String,
pub issued_token_type: String,
pub cnf: Option<Value>,
pub cnf_jkt: String,
}Fields (Non-exhaustive)§
This struct is marked as non-exhaustive
Struct { .. } syntax; cannot be matched against without a wildcard ..; and struct update syntax will not work.access_token: String§token_type: String§expires_in: Option<i64>AS-supplied lifetime hint in seconds (RFC 6749 §5.1).
None— the AS omitted the field. The cache layer applies its configureddefault_ttl.Some(0)— the AS asked for immediate expiry (RFC 6749 §5.1 permits this for one-shot flows). The cache refuses to store.Some(n)withn > 0— usenseconds, then apply the buffer.
On the wire, None is omitted entirely (the field is absent from
the JSON), matching what the AS would have sent — so serializing a
cached TokenResponse round-trips through the same parse path
that produced it.
match resp.expires_in {
None => { /* AS gave no hint — apply default TTL */ }
Some(0) => { /* explicit immediate expiry — do not cache */ }
Some(_n) => { /* use n seconds */ }
}scope: String§refresh_token: String§issued_token_type: String§cnf: Option<Value>Raw cnf (confirmation) object from the token response when
present. RFC 9449 §6.1 places cnf.jkt here for DPoP-bound
tokens; this field preserves any extension members
(x5t#S256, future additions) verbatim. Only Some when the
AS sent a JSON object; non-object cnf values are dropped.
cnf_jkt: StringConvenience accessor for the DPoP key thumbprint at
cnf.jkt (RFC 9449 §6.1). Empty string when the token is
not DPoP-bound. Always derived from cnf.jkt on deserialize
via #[serde(from = "TokenResponseWire")], matching the
imperative parse_token_response_inner path through
extract_cnf_and_jkt — a top-level cnf_jkt on the wire is
not honoured, so a poisoned blob that disagrees with its own
cnf object cannot mint a mismatched thumbprint.
Trait Implementations§
Source§impl Clone for TokenResponse
impl Clone for TokenResponse
Source§impl Debug for TokenResponse
impl Debug for TokenResponse
Source§impl<'de> Deserialize<'de> for TokenResponse
impl<'de> Deserialize<'de> for TokenResponse
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for TokenResponse
Source§impl From<CachedToken> for TokenResponse
impl From<CachedToken> for TokenResponse
Source§fn from(cached: CachedToken) -> Self
fn from(cached: CachedToken) -> Self
Rehydrate a TokenResponse from a cached entry. refresh_token and
issued_token_type default to empty — client_credentials responses
never carry them. cnf and cnf_jkt are preserved verbatim from the
cache so a DPoP-bound token still looks DPoP-bound on cache hits.