pub enum VerifyError {
Keys(String),
Malformed(String),
MissingKid,
UnknownKid(String),
Paseto(String),
Claim(String),
UnsupportedAlgorithm {
kid: String,
algorithm: String,
},
}Expand description
Failure modes for key-set loading and token verification.
Every fallible entry point returns this type, and every variant is a
handled outcome — the crate never panics on bad input, so a malformed
key set and a forged token are both ordinary Err values.
Variants§
Keys(String)
The key-set document was missing or structurally invalid (no keys
array, a key missing kid / x, or an x that is not a 32-byte
base64url Ed25519 public key). Raised at load time, not per token.
Malformed(String)
The token was not a structurally valid v4.public token, or its
footer could not be decoded as { "kid": ... }. Distinct from a
signature failure (Paseto).
MissingKid
The token footer carried no kid, so no key could be selected.
All auth-service tokens stamp a footer kid, so this indicates a
hand-built or non-conforming token.
UnknownKid(String)
No verification key matched the token’s footer kid (stale cache,
wrong issuer, or forgery). The wrapped String is the unmatched
kid; on a legitimate stale cache a caller may refetch and retry.
Paseto(String)
PASETO parsing or Ed25519 signature verification failed. Carries the
stringified underlying rusty_paseto error.
Claim(String)
The signature was valid but a registered claim did not satisfy the
policy: wrong iss, wrong aud, expired exp, or unmet nbf.
UnsupportedAlgorithm
The token’s kid selected a key whose algorithm this build does
not implement.
Distinct from UnknownKid on purpose.
Both reject the token, but they mean different things to whoever
is on call: UnknownKid says “I hold no key for this signer” and
invites a key-set refetch; this says “I hold the key and cannot
use it”, which a refetch will never fix. It is the expected error
during a partial algorithm rollout — the issuer has moved ahead of
this verifier, and this binary needs upgrading.
Trait Implementations§
Source§impl Debug for VerifyError
impl Debug for VerifyError
Source§impl Display for VerifyError
impl Display for VerifyError
Source§impl Error for VerifyError
impl Error for VerifyError
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()