#[non_exhaustive]pub enum VerifierError {
Show 13 variants
TokenMissing,
TokenExpired,
InvalidSignature {
message: String,
},
InvalidClaims {
message: String,
},
MetadataUnavailable {
message: String,
},
JwksUnavailable {
message: String,
},
TokenRevoked,
InsufficientScope {
required: String,
available: Vec<String>,
},
DpopProofMissing,
DpopReplayDetected,
DpopMultipleProofs,
DpopBindingMismatch {
message: String,
},
DpopNotSupported,
}Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
TokenMissing
TokenExpired
InvalidSignature
InvalidClaims
TokenRevoked
RFC 7662 §2.2 — introspection answered active: false for a token
that had already passed local JWT verification.
RFC 7662 defines active: false broadly and authserver does not
say why, so the token may be revoked — or the AS may not recognise
this resource server as the token’s owner. Since authserver 0.1.2
only the issuing client or a runtime-client of the Resource named
in aud gets a real answer; any other caller, including a public
(secret-less) client, gets active: false for every token. If every
token is rejected with this error, register the resource server’s
client on the Resource:
authserver admin resource runtime-client add --client-id <rs-client-id> --slug <resource-slug>.
The Display is deliberately bare: www_authenticate* copies
error.to_string() into error_description and the mcp adapter copies
it into the 401 body, so anything said here reaches an unauthenticated
caller. The operator guidance above stays in the docs.
InsufficientScope
DpopProofMissing
RFC 9449 §7 — the verify_with_context entrypoint received a
DPoP-bound access token (one with cnf.jkt) but the request
context carried no DPoP proof. Maps to the catalog’s
error_category = "dpop_proof_missing" bucket.
A context that was never supplied is a different failure and is
reported as Self::DpopBindingMismatch: verify takes no
request context by construction, so “the caller passed one and it
held no proof” is a claim only this entrypoint can make.
DpopReplayDetected
RFC 9449 §11.1 — the proof’s jti had already been observed by
the configured replay store.
DpopMultipleProofs
RFC 9449 §4.3 #1 — the request carried more than one DPoP header,
so there is no way to know which proof binds the request. Unlike the
other DPoP failures this maps to error="invalid_dpop_proof"
(RFC 9449 §7.1) rather than the generic invalid_token.
DpopBindingMismatch
DpopNotSupported
RFC 9449 §6 — the resource has NOT opted into inbound DPoP
(ResourceOptions::inbound_dpop is None), but the request carried
a DPoP signal (a cnf.jkt-bound access token or a DPoP proof
header). The verifier rejects rather than silently downgrading to
bearer or applying ad-hoc defaults never advertised in PRM.
Implementations§
Source§impl VerifierError
impl VerifierError
Sourcepub fn is_dpop(&self) -> bool
pub fn is_dpop(&self) -> bool
true for any DPoP-specific variant. Currently DpopProofMissing,
DpopReplayDetected, DpopMultipleProofs, DpopBindingMismatch,
and DpopNotSupported.
Membership only — does NOT decide the WWW-Authenticate scheme.
DpopNotSupported is a DPoP-flavoured error but the spec-correct
retry scheme is Bearer (see Self::www_authenticate_scheme_is_dpop).
Sourcepub fn www_authenticate_scheme_is_dpop(&self) -> bool
pub fn www_authenticate_scheme_is_dpop(&self) -> bool
true when the spec-correct WWW-Authenticate challenge for this
error uses the DPoP scheme (RFC 9449 §7.1) rather than the default
Bearer (RFC 6750 §3).
All DPoP-bound failures map to DPoP except Self::DpopNotSupported,
which is the carve-out: the client presented a DPoP signal against a
resource that has not opted into DPoP, so there is no DPoP retry
path on this resource — the correct challenge tells the client to
retry as Bearer. Conformance fixtures assert this scheme
byte-for-byte.
Trait Implementations§
Source§impl Clone for VerifierError
impl Clone for VerifierError
Source§impl Debug for VerifierError
impl Debug for VerifierError
Source§impl Display for VerifierError
impl Display for VerifierError
impl Eq for VerifierError
Source§impl Error for VerifierError
impl Error for VerifierError
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()
Source§impl PartialEq for VerifierError
impl PartialEq for VerifierError
impl StructuralPartialEq for VerifierError
Auto Trait Implementations§
impl Freeze for VerifierError
impl RefUnwindSafe for VerifierError
impl Send for VerifierError
impl Sync for VerifierError
impl Unpin for VerifierError
impl UnsafeUnpin for VerifierError
impl UnwindSafe for VerifierError
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
Source§impl<T> ToStringFallible for Twhere
T: Display,
impl<T> ToStringFallible for Twhere
T: Display,
Source§fn try_to_string(&self) -> Result<String, TryReserveError>
fn try_to_string(&self) -> Result<String, TryReserveError>
ToString::to_string, but without panic on OOM.