Expand description
Provider-neutral authentication scope and execution contracts.
Structs§
- Authenticated
Request - Request plus mandatory provider or operation-owned authentication policy.
- Authentication
Scope - Immutable borrowed scope bound to one admitted credential.
- Authentication
Scope Error - Payload-free authentication-scope policy failure.
- Authentication
Scope Policy - Complete provider or operation-owned authentication-scope policy.
- Canonical
Signing Input - Cleanup-owning canonical input that retains the exact hashed request.
- Credential
Generation - Monotonic generation of one credential state.
- Refresh
Handoff - Opaque generation captured before an external refresh operation begins.
- Scope
Value - Borrowed, bounded provider-owned authentication-scope value.
- Signed
Request - Exact request and validated signature produced from one canonical snapshot.
- Signing
Algorithm - Borrowed provider-owned signature algorithm identifier.
- Signing
Context - Complete security domain bound into one canonical signature.
- Signing
Digest Algorithm - Borrowed provider-owned request-body digest algorithm identifier.
- Signing
Freshness - Caller-owned nonce and observed time bound into one anti-replay context.
- Signing
Headers - Canonically ordered request headers selected by provider signing policy.
- Signing
KeyId - Borrowed provider-owned signing key identifier.
- Signing
Nonce - Borrowed caller-provided nonce.
- Unix
Time - Caller-observed Unix time in whole seconds.
Enums§
- Credential
Generation Error - Credential-generation transition error.
- Scope
Field - Authentication-scope field that failed policy validation.
- Scope
Requirement - Provider or operation requirement for one authentication-scope field.
- Scope
Value Error - Authentication-scope value validation error.
- Scope
Violation - Payload-free reason a scope field failed validation.
- Signing
Build Error - Body hashing and canonical signing-input construction failure.
- Signing
Context Value Error - Signing-context text validation failure.
- Signing
Input Error - Canonical signing-input construction failure.
- Signing
Output Error - Validated signing-output failure.
- Signing
Value Error - Bounded signing value validation failure.
Constants§
- MAX_
CANONICAL_ SIGNING_ INPUT_ BYTES - Maximum complete canonical signing-input bytes.
- MAX_
SCOPE_ VALUE_ BYTES - Maximum bytes in one provider-owned audience, account, or tenant binding.
- MAX_
SIGNING_ ALGORITHM_ BYTES - Maximum bytes in a signing algorithm identifier.
- MAX_
SIGNING_ BODY_ DIGEST_ BYTES - Maximum request-body digest bytes accepted by the canonical format.
- MAX_
SIGNING_ DIGEST_ ALGORITHM_ BYTES - Maximum bytes in a body-digest algorithm identifier.
- MAX_
SIGNING_ HEADERS - Maximum selected request headers.
- MAX_
SIGNING_ KEY_ ID_ BYTES - Maximum bytes in a signing key identifier.
- MAX_
SIGNING_ NONCE_ BYTES - Maximum caller-provided nonce bytes accepted by the canonical format.
Traits§
- Async
Authenticated Transport - Executor-neutral async transport requiring an authentication policy.
- Blocking
Authenticated Transport - Blocking transport that cannot execute without an authentication policy.
- Request
Body Hasher - Caller-provided request-body hashing implementation.
- Request
Signer - Caller-provided request-signing implementation.