Skip to main content

JwtService

Struct JwtService 

Source
pub struct JwtService { /* private fields */ }
Expand description

JWT service with key rotation and multi-algorithm support

Maintains an active signing key and a list of retired keys. Tokens are always signed with the active key. Validation tries the active key first, then retired keys within the grace period.

Supports both HS256 (shared secret) and RS256 (RSA key pair).

Implementations§

Source§

impl JwtService

Source

pub fn new(secret: &str) -> Self

Create a new JWT service with HS256 (backward compatible)

Source

pub fn with_rotation(secret: &str, config: KeyRotationConfig) -> Self

Create a new JWT service with HS256 and explicit rotation configuration

Source

pub fn new_rs256(private_key_pem: &str, public_key_pem: &str) -> Result<Self>

Create a new JWT service with RS256 (asymmetric)

Validates the RSA key pair on construction — returns an error if the keys are malformed or cannot be used for signing/verification.

Source

pub fn with_rs256_rotation( private_key_pem: &str, public_key_pem: &str, config: KeyRotationConfig, ) -> Result<Self>

Create a new JWT service with RS256 and explicit rotation configuration

Validates the RSA key pair on construction — returns an error if the keys are malformed or cannot be used for signing/verification.

Source

pub fn active_kid(&self) -> String

Get the current active key ID

Source

pub fn algorithm(&self) -> JwtAlgorithm

Get the algorithm used by this service

Source

pub fn public_key_pem(&self) -> Option<String>

Export the public key PEM (RS256 only, returns None for HS256)

Source

pub fn rotate_key(&self, new_secret: &str) -> Result<String>

Rotate the HS256 signing key. Returns the kid of the new active key.

Source

pub fn rotate_rsa_key( &self, private_key_pem: &str, public_key_pem: &str, ) -> Result<String>

Rotate the RS256 key pair. Validates the new key pair before rotating. Returns the kid of the new active key.

Source

pub fn create_token(&self, claims: &Claims) -> Result<String>

Create JWT token (signs with the active key, includes kid in header)

Source

pub fn create_refresh_token( &self, claims: &RefreshTokenClaims, ) -> Result<String>

Create refresh token (signs with the active key)

Source

pub fn validate_token(&self, token: &str) -> Result<Claims>

Validate JWT token (tries active key first, then retired keys)

Source

pub fn decode_token(&self, token: &str) -> Result<Claims>

Decode JWT token without expiration validation

Source

pub fn validate_refresh_token(&self, token: &str) -> Result<RefreshTokenClaims>

Validate refresh token (tries all valid keys)

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
where ST: ?Sized, DT: ?Sized,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self> ⓘ

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self> ⓘ

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Read<Exclusive, BecauseExclusive> for T
where T: ?Sized,

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<V, T> VZip<V> for T
where V: MultiLane<T>,

Source§

fn vzip(self) -> V

Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self> ⓘ
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self> ⓘ

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more