Expand description
TTL’d LRU caches for DID documents and jti replay detection (§5.2, §5.4).
Both caches wrap lru::LruCache with expiration checks on access.
Entries that are expired when looked up are treated as a miss and
evicted, so stale data never influences a decision.
Time is read through a Clock handle so tests can advance it
deterministically — TTL semantics that depend on Instant::now()
flake under CI scheduling jitter when tests rely on thread::sleep
to cross small thresholds (§F4 #21). Production passes a
SystemClock; tests pass MockClock.
Structs§
- Replay
- Returned by the jti cache’s
check_and_recordwhen the(iss, jti)pair was already observed inside its TTL (§5.2 replay protection). Callers at the auth boundary map this toAuthError::Replay.