Skip to main content

authplane_sdk/
constants.rs

1//! Well-known string constants used across the SDK.
2//!
3//! Previously these literals (OAuth parameter names, RFC 6750 / 9449
4//! error codes, HTTP header names, MIME types, JWT / DPoP / JWK claim
5//! names, `.well-known/*` paths, JOSE algorithm identifiers) lived
6//! inline in 30+ sites across `core/src/oauth`, `core/src/dpop`,
7//! `core/src/errors`, `core/src/www_authenticate`, `core/src/resource`,
8//! `core/src/cache`, `core/src/metadata`, `core/src/prm`, and the two
9//! adapters. Drift between any two copies — a typo in one site, a
10//! missing entry in another — silently breaks OAuth / DPoP interop.
11//!
12//! New entries land here the first time the same literal is needed in
13//! a second site. Existing constants (`GRANT_TYPE_TOKEN_EXCHANGE`,
14//! `TOKEN_TYPE_ACCESS_TOKEN` in `oauth`, `SUPPORTED_DPOP_ALGORITHMS`
15//! in `dpop`) stay where they are for now to avoid churn; they may
16//! migrate here over time.
17
18/// OAuth 2.0 / RFC 8693 form-body parameter names.
19pub mod oauth_params {
20    pub const GRANT_TYPE: &str = "grant_type";
21    pub const SCOPE: &str = "scope";
22    pub const RESOURCE: &str = "resource";
23    pub const AUDIENCE: &str = "audience";
24    pub const TOKEN: &str = "token";
25    pub const TOKEN_TYPE_HINT: &str = "token_type_hint";
26    pub const SUBJECT_TOKEN: &str = "subject_token";
27    pub const SUBJECT_TOKEN_TYPE: &str = "subject_token_type";
28    pub const ACTOR_TOKEN: &str = "actor_token";
29    pub const ACTOR_TOKEN_TYPE: &str = "actor_token_type";
30    pub const REQUESTED_TOKEN_TYPE: &str = "requested_token_type";
31
32    pub const GRANT_TYPE_CLIENT_CREDENTIALS: &str = "client_credentials";
33}
34
35/// OAuth 2.0 / RFC 6750 / RFC 7009 / RFC 9449 error codes.
36pub mod oauth_errors {
37    pub const INVALID_TOKEN: &str = "invalid_token";
38    pub const INSUFFICIENT_SCOPE: &str = "insufficient_scope";
39    pub const INVALID_DPOP_PROOF: &str = "invalid_dpop_proof";
40    pub const USE_DPOP_NONCE: &str = "use_dpop_nonce";
41    pub const CONSENT_REQUIRED: &str = "consent_required";
42    pub const INTERACTION_REQUIRED: &str = "interaction_required";
43    pub const INVALID_GRANT: &str = "invalid_grant";
44    pub const INVALID_SCOPE: &str = "invalid_scope";
45    pub const INVALID_REQUEST: &str = "invalid_request";
46    pub const INVALID_CLIENT: &str = "invalid_client";
47    pub const UNAUTHORIZED_CLIENT: &str = "unauthorized_client";
48    /// RFC 6749 §4.1.2.1 — the AS refused the request on policy grounds.
49    /// authserver 0.2.0 answers it (HTTP 403) to a cross-client token
50    /// exchange whose client is not allowlisted on the target Resource.
51    /// Unlike `consent_required`, no user interaction can clear it.
52    pub const ACCESS_DENIED: &str = "access_denied";
53    /// RFC 8707 §2.2 — returned by the AS when a `resource` parameter is
54    /// rejected. authserver compares the value byte for byte against the
55    /// granted resources, so a trailing slash is enough to trigger it.
56    pub const INVALID_TARGET: &str = "invalid_target";
57    pub const SERVER_ERROR: &str = "server_error";
58    pub const UNSUPPORTED_GRANT_TYPE: &str = "unsupported_grant_type";
59    pub const UNSUPPORTED_TOKEN_TYPE: &str = "unsupported_token_type";
60    pub const INVALID_RESPONSE: &str = "invalid_response";
61    pub const TOKEN_TYPE_HINT_ACCESS_TOKEN: &str = "access_token";
62    pub const TOKEN_TYPE_HINT_REFRESH_TOKEN: &str = "refresh_token";
63}
64
65/// HTTP header names this SDK reads or writes.
66pub mod http_headers {
67    pub const AUTHORIZATION: &str = "authorization";
68    pub const ACCEPT: &str = "accept";
69    pub const CONTENT_TYPE: &str = "content-type";
70    pub const HOST: &str = "Host";
71    pub const DPOP: &str = "dpop";
72    pub const DPOP_NONCE: &str = "dpop-nonce";
73    pub const WWW_AUTHENTICATE: &str = "WWW-Authenticate";
74    pub const CACHE_CONTROL: &str = "cache-control";
75}
76
77/// MIME types this SDK reads or writes.
78pub mod media_types {
79    pub const APPLICATION_JSON: &str = "application/json";
80    pub const APPLICATION_FORM_URLENCODED: &str = "application/x-www-form-urlencoded";
81}
82
83/// Authorization scheme prefixes (RFC 6750 / RFC 9449 / RFC 7617).
84pub mod auth_schemes {
85    pub const BEARER: &str = "Bearer";
86    pub const DPOP: &str = "DPoP";
87    pub const BASIC: &str = "Basic";
88}
89
90/// `.well-known/*` document paths.
91pub mod well_known {
92    pub const OAUTH_AUTHORIZATION_SERVER: &str = "/.well-known/oauth-authorization-server";
93    pub const OPENID_CONFIGURATION: &str = "/.well-known/openid-configuration";
94    pub const OAUTH_PROTECTED_RESOURCE: &str = "/.well-known/oauth-protected-resource";
95}
96
97/// Standard JWT claim names (RFC 7519, RFC 7800, RFC 9068).
98///
99/// Confined to claims that are spec-defined for JWT payloads. OAuth /
100/// introspection fields that happen to also appear inside JWTs (`scope`,
101/// `client_id` per RFC 9068, `active` / `token_type` from RFC 7662
102/// introspection responses) live in [`oauth_params`] and
103/// [`introspection_fields`] respectively so the module taxonomy reflects the
104/// spec each constant comes from. The constants module is brand-new this
105/// release cycle so moving these is not a downstream break.
106pub mod jwt_claims {
107    pub const ISS: &str = "iss";
108    pub const SUB: &str = "sub";
109    pub const AUD: &str = "aud";
110    pub const EXP: &str = "exp";
111    pub const IAT: &str = "iat";
112    pub const NBF: &str = "nbf";
113    pub const JTI: &str = "jti";
114    /// RFC 7800 §3.1 confirmation claim, carrying the sender-constrained
115    /// binding (e.g. `cnf.jkt` per RFC 9449 §6).
116    pub const CNF: &str = "cnf";
117    /// RFC 9449 §6.1 — JWK SHA-256 thumbprint inside `cnf`.
118    pub const JKT: &str = "jkt";
119    /// RFC 9068 §2.2.3.1 — client identifier, mirrored into the access-token
120    /// JWT (also an OAuth response field; kept here because the JWT-payload
121    /// usage is the one this SDK reads).
122    pub const CLIENT_ID: &str = "client_id";
123
124    // Authplane-specific (custom claims used by the AS).
125    pub const AGENT_ID: &str = "agent_id";
126    pub const AGENT_CHAIN: &str = "agent_chain";
127}
128
129/// RFC 7662 token-introspection response fields.
130pub mod introspection_fields {
131    pub const ACTIVE: &str = "active";
132    pub const TOKEN_TYPE: &str = "token_type";
133    pub const SCOPE: &str = "scope";
134}
135
136/// RFC 9449 DPoP-proof claim names + JWS `typ` header value.
137pub mod dpop_claims {
138    pub const HTM: &str = "htm";
139    pub const HTU: &str = "htu";
140    pub const ATH: &str = "ath";
141    pub const NONCE: &str = "nonce";
142
143    /// `typ` header value for a DPoP proof JWS (RFC 9449 §4.2).
144    pub const TYP_DPOP_JWT: &str = "dpop+jwt";
145
146    /// `typ` header value for an access-token JWT (RFC 9068).
147    pub const TYP_AT_JWT: &str = "at+jwt";
148}
149
150/// RFC 7517 JWK parameter names + RFC 7518 / RFC 8037 algorithm values.
151pub mod jwk_params {
152    pub const KTY: &str = "kty";
153    pub const CRV: &str = "crv";
154    pub const X: &str = "x";
155    pub const Y: &str = "y";
156    pub const E: &str = "e";
157    pub const N: &str = "n";
158
159    pub const KTY_EC: &str = "EC";
160    pub const KTY_RSA: &str = "RSA";
161    pub const KTY_OKP: &str = "OKP";
162
163    pub const CRV_P256: &str = "P-256";
164
165    pub const USE: &str = "use";
166    pub const USE_SIG: &str = "sig";
167
168    pub const KEY_OPS: &str = "key_ops";
169    pub const KEY_OPS_VERIFY: &str = "verify";
170
171    /// RFC 7517 §4.4 — JOSE algorithm identifier on the JWK.
172    pub const ALG: &str = "alg";
173    /// RFC 7517 §4.5 — key identifier on the JWK.
174    pub const KID: &str = "kid";
175}
176
177/// HTTP request methods written by this SDK.
178///
179/// Currently only `POST` is constructed in DPoP-proof HTU/HTM binding; other
180/// methods reach this SDK only via inbound parsing where `http::Method` already
181/// owns the canonical spelling.
182pub mod http_methods {
183    pub const POST: &str = "POST";
184}
185
186/// JOSE algorithm identifiers (RFC 7518).
187pub mod algorithms {
188    pub const ES256: &str = "ES256";
189    pub const RS256: &str = "RS256";
190}