pub struct ResourceOptions {
pub clock_skew_seconds: u64,
pub dpop_proof_max_age_seconds: u64,
pub revocation: Option<RevocationConfig>,
pub inbound_dpop: Option<InboundDPoPOptions>,
/* private fields */
}Fields§
§clock_skew_seconds: u64§dpop_proof_max_age_seconds: u64Maximum age for inbound DPoP proofs (seconds). Separate from
clock_skew_seconds because DPoP proof TTL and access-token
clock skew are independent time domains.
revocation: Option<RevocationConfig>§inbound_dpop: Option<InboundDPoPOptions>Per-resource inbound DPoP configuration (RFC 9449 §7.1 + RFC 9728 §2).
None(default) — Mode 3: resource has NOT opted into DPoP. The verifier rejects any inbound DPoP signal (cnf.jkton the access token or a DPoP proof header) withVerifierError::DpopNotSupported; PRM omits thedpop_*discovery fields entirely.Some(InboundDPoPOptions::default())— Mode 2: bearer-only tokens accepted, DPoP-bound tokens validated end-to-end. PRM advertises DPoP capability withdpop_bound_access_tokens_required: false.Some(InboundDPoPOptions::required())— Mode 1: bearer-only tokens rejected withVerifierError::DpopBindingMismatch. PRM advertisesdpop_bound_access_tokens_required: true.
Implementations§
Source§impl ResourceOptions
impl ResourceOptions
Sourcepub fn with_inbound_dpop(self, opts: InboundDPoPOptions) -> Self
pub fn with_inbound_dpop(self, opts: InboundDPoPOptions) -> Self
Builder shortcut for opting the resource into inbound DPoP. Equivalent
to assigning Some(opts) to Self::inbound_dpop via struct-update
syntax — exists to avoid the four-line boilerplate at call sites:
ResourceOptions {
inbound_dpop: Some(InboundDPoPOptions::default()),
..ResourceOptions::default()
}becomes:
ResourceOptions::default().with_inbound_dpop(InboundDPoPOptions::default())Sourcepub fn with_allowed_algorithms(
self,
algorithms: Vec<Algorithm>,
) -> Result<Self, ResourceOptionsError>
pub fn with_allowed_algorithms( self, algorithms: Vec<Algorithm>, ) -> Result<Self, ResourceOptionsError>
Restrict the accepted access-token algorithms to a non-empty
subset of [DEFAULT_ALLOWED_ALGORITHMS] (currently RS256 and
ES256). Returns an error on an empty list or on any algorithm
outside that allowlist, at construction rather than at the first
verification.
An allowlist (rather than an HMAC blocklist) is required: the
jsonwebtoken crate also exposes RS384, RS512, PS*, ES384,
and EdDSA. None of these are part of the supported
access-token algorithm contract; silently accepting them here
would let a caller advertise an alg in their PRM / JWKS that
peers can’t validate, and broaden the algorithm-confusion
surface beyond that contract.
Acts as the public construction path; the field is pub(crate)
so the only way to install a custom set from outside the crate
is through this validator.
Sourcepub fn allowed_algorithms(&self) -> &[Algorithm]
pub fn allowed_algorithms(&self) -> &[Algorithm]
Borrow the configured access-token algorithm allow-list.
Sourcepub fn with_resource_metadata_url(
self,
url: impl Into<String>,
) -> Result<Self, ResourceOptionsError>
pub fn with_resource_metadata_url( self, url: impl Into<String>, ) -> Result<Self, ResourceOptionsError>
Publish a custom Protected Resource Metadata URL in the
resource_metadata challenge parameter (RFC 9728 §5.1) instead of
the one derived from the resource identifier.
Rejects anything that is not an absolute URL with a host, at
construction rather than on the first 401: a client cannot fetch
a relative reference out of a header, and RFC 9728 §3.3 gives it no
recovery path when the document does not resolve.
Whitespace, control characters, " and \ are rejected on the raw
string, for the reason crate::prm spells out on the resource
identifier: the WHATWG parser trims leading and trailing C0/space and
removes tab and newline anywhere before parsing, so a value carrying
them parses cleanly while being stored and advertised intact. A
trailing newline — the shape a file-sourced env var or $(cat …)
produces — would then make HeaderValue::from_str fail and drop
WWW-Authenticate from every 401, which is the header this setter
exists to populate.
Sourcepub fn resource_metadata_url(&self) -> Option<&str>
pub fn resource_metadata_url(&self) -> Option<&str>
The configured resource_metadata override, if any.