Skip to main content

ResourceOptions

Struct ResourceOptions 

Source
pub struct ResourceOptions {
    pub clock_skew_seconds: u64,
    pub dpop_proof_max_age_seconds: u64,
    pub revocation: Option<RevocationConfig>,
    pub inbound_dpop: Option<InboundDPoPOptions>,
    /* private fields */
}

Fields§

§clock_skew_seconds: u64§dpop_proof_max_age_seconds: u64

Maximum age for inbound DPoP proofs (seconds). Separate from clock_skew_seconds because DPoP proof TTL and access-token clock skew are independent time domains.

§revocation: Option<RevocationConfig>§inbound_dpop: Option<InboundDPoPOptions>

Per-resource inbound DPoP configuration (RFC 9449 §7.1 + RFC 9728 §2).

  • None (default) — Mode 3: resource has NOT opted into DPoP. The verifier rejects any inbound DPoP signal (cnf.jkt on the access token or a DPoP proof header) with VerifierError::DpopNotSupported; PRM omits the dpop_* discovery fields entirely.
  • Some(InboundDPoPOptions::default()) — Mode 2: bearer-only tokens accepted, DPoP-bound tokens validated end-to-end. PRM advertises DPoP capability with dpop_bound_access_tokens_required: false.
  • Some(InboundDPoPOptions::required()) — Mode 1: bearer-only tokens rejected with VerifierError::DpopBindingMismatch. PRM advertises dpop_bound_access_tokens_required: true.

Implementations§

Source§

impl ResourceOptions

Source

pub fn with_inbound_dpop(self, opts: InboundDPoPOptions) -> Self

Builder shortcut for opting the resource into inbound DPoP. Equivalent to assigning Some(opts) to Self::inbound_dpop via struct-update syntax — exists to avoid the four-line boilerplate at call sites:

ⓘ
ResourceOptions {
    inbound_dpop: Some(InboundDPoPOptions::default()),
    ..ResourceOptions::default()
}

becomes:

ⓘ
ResourceOptions::default().with_inbound_dpop(InboundDPoPOptions::default())
Source

pub fn with_allowed_algorithms( self, algorithms: Vec<Algorithm>, ) -> Result<Self, ResourceOptionsError>

Restrict the accepted access-token algorithms to a non-empty subset of [DEFAULT_ALLOWED_ALGORITHMS] (currently RS256 and ES256). Returns an error on an empty list or on any algorithm outside that allowlist, at construction rather than at the first verification.

An allowlist (rather than an HMAC blocklist) is required: the jsonwebtoken crate also exposes RS384, RS512, PS*, ES384, and EdDSA. None of these are part of the supported access-token algorithm contract; silently accepting them here would let a caller advertise an alg in their PRM / JWKS that peers can’t validate, and broaden the algorithm-confusion surface beyond that contract.

Acts as the public construction path; the field is pub(crate) so the only way to install a custom set from outside the crate is through this validator.

Source

pub fn allowed_algorithms(&self) -> &[Algorithm]

Borrow the configured access-token algorithm allow-list.

Source

pub fn with_resource_metadata_url( self, url: impl Into<String>, ) -> Result<Self, ResourceOptionsError>

Publish a custom Protected Resource Metadata URL in the resource_metadata challenge parameter (RFC 9728 §5.1) instead of the one derived from the resource identifier.

Rejects anything that is not an absolute URL with a host, at construction rather than on the first 401: a client cannot fetch a relative reference out of a header, and RFC 9728 §3.3 gives it no recovery path when the document does not resolve.

Whitespace, control characters, " and \ are rejected on the raw string, for the reason crate::prm spells out on the resource identifier: the WHATWG parser trims leading and trailing C0/space and removes tab and newline anywhere before parsing, so a value carrying them parses cleanly while being stored and advertised intact. A trailing newline — the shape a file-sourced env var or $(cat …) produces — would then make HeaderValue::from_str fail and drop WWW-Authenticate from every 401, which is the header this setter exists to populate.

Source

pub fn resource_metadata_url(&self) -> Option<&str>

The configured resource_metadata override, if any.

Trait Implementations§

Source§

impl Clone for ResourceOptions

Source§

fn clone(&self) -> Self

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for ResourceOptions

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for ResourceOptions

Source§

fn default() -> Self

Returns the “default value” for a type. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more