Expand description
Who is calling the API: an API key in Authorization: Bearer <key>, and nothing else. The
session cookie never authenticates the API (so no request can ride on a browser login), and a
key that is malformed or revoked is refused, never treated as “no key”.
Structs§
- ApiCaller
- A caller holding a live API key: the key’s account (as loaded for this request) and the key.
Functions§
- authenticate
- The caller of a request that must carry a key.
- bearer_
key - The key in the
Authorizationheader:Ok(None)when the header is absent, an error when it is there but isn’t a well-formedBearerkey. - resolve_
key - The caller behind a well-formed key: unknown and revoked keys are refused.