pub struct TokenGenerator { /* private fields */ }Expand description
Consolidated token generation and validation service.
Wraps JwtService for JWT operations and provides static methods
for crypto operations that don’t require JWT context.
Implementations§
Source§impl TokenGenerator
impl TokenGenerator
Sourcepub fn new(jwt_service: Arc<JwtService>) -> Self
pub fn new(jwt_service: Arc<JwtService>) -> Self
Create a new TokenGenerator wrapping a shared JwtService.
Sourcepub fn generate_otp() -> String
pub fn generate_otp() -> String
Generate a 6-digit OTP code.
Sourcepub fn hash_token(token: &str) -> String
pub fn hash_token(token: &str) -> String
SHA-256 hash a token/OTP before storing in the database.
Sourcepub fn generate_refresh_token() -> String
pub fn generate_refresh_token() -> String
Generate a new refresh token string (UUID v4).
Sourcepub fn constant_time_eq(a: &str, b: &str) -> bool
pub fn constant_time_eq(a: &str, b: &str) -> bool
Constant-time string comparison to prevent timing side-channel attacks.
The XOR-fold comparison runs in constant time for inputs of equal length. The length check on line 1 does leak whether lengths differ via timing, but this is acceptable because all call sites compare fixed-length values (6-digit OTP codes or 64-char SHA-256 hex hashes).
Do NOT use this for variable-length secret comparison.
Sourcepub fn create_access_token(&self, claims: &Claims) -> Result<String>
pub fn create_access_token(&self, claims: &Claims) -> Result<String>
Create an access token from claims.
Sourcepub fn create_refresh_token_jwt(
&self,
claims: &RefreshTokenClaims,
) -> Result<String>
pub fn create_refresh_token_jwt( &self, claims: &RefreshTokenClaims, ) -> Result<String>
Create a refresh token JWT from refresh claims.
Sourcepub fn validate_access_token(&self, token: &str) -> Result<Claims>
pub fn validate_access_token(&self, token: &str) -> Result<Claims>
Validate an access token and return its claims.
Sourcepub fn validate_refresh_token(&self, token: &str) -> Result<RefreshTokenClaims>
pub fn validate_refresh_token(&self, token: &str) -> Result<RefreshTokenClaims>
Validate a refresh token JWT and return its claims.
Sourcepub fn decode_access_token(&self, token: &str) -> Result<Claims>
pub fn decode_access_token(&self, token: &str) -> Result<Claims>
Decode an access token without expiry validation.