#[cfg(test)]
mod tests;
use std::sync::Arc;
use axum::{Json, extract::State, http::StatusCode};
use fraiseql_core::security::OidcValidator;
use serde_json::json;
use tracing::{info, warn};
pub async fn refresh_jwks_handler(
State(validator): State<Arc<OidcValidator>>,
) -> (StatusCode, Json<serde_json::Value>) {
match validator.refresh_jwks().await {
Ok(key_count) => {
info!(key_count, "JWKS cache force-refreshed via /admin/v1/auth/refresh-jwks");
(
StatusCode::OK,
Json(json!({
"refreshed": true,
"key_count": key_count,
})),
)
},
Err(e) => {
validator.invalidate_jwks_cache();
warn!(
error = %e,
"JWKS force-refresh could not reach the provider; cache invalidated (fail-closed)"
);
(
StatusCode::BAD_GATEWAY,
Json(json!({
"refreshed": false,
"cache_invalidated": true,
"error": "failed to fetch JWKS from the provider; cache invalidated, keys \
will be refetched on the next token validation",
})),
)
},
}
}