1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
// Copyright The OpenTelemetry Authors
// SPDX-License-Identifier: Apache-2.0
//! The `BearerTokenProvider` capability.
//!
//! A small, purpose-built capability that hands out OAuth bearer tokens
//! to data-path nodes. It is intentionally provider- and execution-model
//! agnostic: the same trait serves active and passive providers across
//! both the shared and local execution models. Consumers depend only on
//! the two methods below, never on how a token is produced or refreshed.
//!
//! Reading this capability separately from `vendor_bundle` cannot produce an
//! atomic token-and-attributes pair. Agent-fed consumers requiring that
//! guarantee must use
//! [`AgentFedCredentialProvider`](super::agent_fed_credential_provider::AgentFedCredentialProvider).
//!
//! The `#[capability]` proc macro expands the trait into:
//!
//! - A `pub(crate) mod local` containing the `!Send` `BearerTokenProvider` trait variant
//! - A `pub(crate) mod shared` containing the `Send + Sync` `BearerTokenProvider` trait variant
//! - A `SharedAsLocalBearerTokenProvider` adapter
//! - A zero-sized `pub struct BearerTokenProvider` registration handle
//! - `local_entry::<E>` / `shared_entry::<E>` factory bridges
//! - A `KNOWN_CAPABILITIES` distributed-slice entry
use BearerToken;
use crateCapabilityError;
use Stream;
use capability;
use Pin;
use Duration;
/// How close to [`BearerToken::expires_on`] a token stops being usable.
///
/// Part of the capability contract rather than either side's private tuning,
/// because both sides have to agree on it:
///
/// - A **provider** must not serve a token inside this window, and must
/// schedule its refresh far enough ahead of expiry to publish a replacement
/// before the current one enters it. A provider whose refresh lead time is
/// smaller than this margin strands its consumers: the token it is still
/// serving has already stopped being usable.
/// - A **consumer** must stop sending requests once its cached token is inside
/// this window, so a request cannot outlive the credential it carries while
/// in flight, in the presence of clock skew between the consumer, the token
/// issuer and the service.
///
/// Fixed rather than configurable so a provider can validate its own refresh
/// settings against the same value every consumer enforces. It has to cover a
/// request's own duration plus that clock skew; 30s matches the default token
/// endpoint timeout.
pub const TOKEN_USABLE_MARGIN: Duration = from_secs;
/// A per-consumer subscription to token refreshes.
///
/// The item is a plain [`BearerToken`], not a `Result`: a refresh
/// failure does not terminate the subscription. The stream simply does
/// not emit until the next successful refresh, and failures surface via
/// [`BearerTokenProvider::get_token`] and telemetry instead. Because the
/// item is [`Clone`], a provider can fan one refreshed token out to all
/// subscribers via a `watch`/`broadcast` channel.
///
/// Boxed to hide the concrete stream type so providers can back it
/// differently (e.g. a `watch` channel or an `unfold`) without changing
/// the signature. The `Send` bound is intentionally omitted: the
/// subscription is always consumed on the core that created it
/// (thread-per-core), so it need not be `Send`. The `#[capability]`
/// macro emits this signature into both the `local` (`?Send`) and
/// `shared` (`Send + Sync`) trait variants unchanged.
pub type TokenStream = ;
/// Hands out OAuth bearer tokens to data-path nodes.