#![cfg_attr(
all(feature = "serde", feature = "env", feature = "axum"),
doc = include_str!("../README.md")
)]
#![cfg_attr(
all(feature = "serde", feature = "env", feature = "axum"),
doc = "
## API map
| Item | Role |
|---|---|
| [`OAuthConfig`], [`OAuthConfig::resolve`] | The unvalidated settings, and their all-or-nothing validation into a [`ResolvedOAuthConfig`] or a [`ConfigError`]. [`KeyNaming`] decides how problems name settings. |
| [`OAuthValidator`] | Validates one token ([`OAuthValidator::validate`]), renders the challenges and the metadata document, and keeps the signing keys fresh ([`OAuthValidator::spawn_background_refresh`]). |
| [`AuthorizedToken`], [`TokenRejection`] | The two outcomes of a validation. |
| [`authenticate`], [`Credential`] | Framework-free checking of several candidate credentials against a static token and OAuth. |
| [`Algorithm`], [`parse_algorithm`], [`AlgorithmError`] | The JWS algorithms a config may allow (never HMAC or `none`). |
| [`static_token_policy`], [`StaticTokenDecision`] | The startup decision about a static API key alongside OAuth. |
| [`axum::AuthLayer`], [`axum::require_auth`], [`axum::metadata_router`] | The axum integration (feature `axum`). |
| [`env::oauth_config_from_env`], [`env::secret_from_env`] | Configuration from environment variables (feature `env`). |"
)]
#![cfg_attr(
all(
feature = "serde",
feature = "env",
feature = "axum",
feature = "testing"
),
doc = "| [`testing`] | Fixtures for your tests (feature `testing`). |"
)]
#![cfg_attr(
all(
feature = "serde",
feature = "env",
feature = "axum",
not(feature = "testing")
),
doc = "| `testing` | Fixtures for your tests (feature `testing`, not enabled in this build). |"
)]
#![cfg_attr(
not(all(feature = "serde", feature = "env", feature = "axum")),
doc = "OAuth 2.0 bearer-token resource server for Rust HTTP services: JWT \
access-token validation against a JWKS (RFC 9068), RFC 9728 \
protected-resource metadata, RFC 6750 `WWW-Authenticate` challenges, an \
optional static API key alongside OAuth, and axum integration.\n\n\
The full guide is this crate's README, which becomes the crate \
documentation when it is built with the `serde`, `env` and `axum` \
features (as on docs.rs): <https://docs.rs/oauth-resource-server>."
)]
#![cfg_attr(docsrs, feature(doc_cfg))]
#![warn(missing_docs)]
#![forbid(unsafe_code)]
#[cfg(not(any(
feature = "rustls-tls",
feature = "rustls-tls-native-roots",
feature = "native-tls"
)))]
compile_error!(
"oauth-resource-server needs a TLS backend for JWKS fetches: enable the `rustls-tls` \
(default), `rustls-tls-native-roots` or `native-tls` feature"
);
mod algorithms;
mod challenge;
pub mod config;
mod jwks;
mod token;
mod validator;
mod authenticate;
mod policy;
#[cfg(feature = "env")]
#[cfg_attr(docsrs, doc(cfg(feature = "env")))]
pub mod env;
#[cfg(feature = "axum")]
#[cfg_attr(docsrs, doc(cfg(feature = "axum")))]
pub mod axum;
#[cfg(any(test, feature = "testing"))]
#[cfg_attr(docsrs, doc(cfg(feature = "testing")))]
pub mod testing;
pub use algorithms::{Algorithm, AlgorithmError, DEFAULT_ALGORITHMS, parse_algorithm};
pub use authenticate::{Credential, authenticate};
pub use challenge::PROTECTED_RESOURCE_METADATA_PREFIX;
pub use config::{
ConfigError, DEFAULT_LEEWAY_SECS, DEFAULT_PRINCIPAL_CLAIMS, DEFAULT_SCOPE_CLAIMS, KeyNaming,
KeyNamingBuf, MAX_LEEWAY_SECS, OAuthConfig, ResolvedOAuthConfig,
};
pub use jwks::RefreshError;
pub use policy::{NoAuthConfigured, StaticTokenDecision, static_token_policy};
pub use token::{AuthorizedToken, TokenRejection};
pub use validator::{OAuthValidator, ValidatorError};