Skip to main content

UserAccessToken

Struct UserAccessToken 

Source
pub struct UserAccessToken { /* private fields */ }
Expand description

A user access token obtained from the device flow.

Non-expiring, and non-renewable. The published App opts out of user-token expiration, so GitHub issues no renewal token alongside this one and there is nothing to renew — see the crate documentation. The token is invalidated only by the user uninstalling the App or revoking the authorization at GitHub.

Debug is written by hand. Deriving it here would put the token into every tracing field, every unwrap() panic message, and every anyhow chain that ever carries one, which is the exact leak 07-security.md gates on.

Implementations§

Source§

impl UserAccessToken

Source

pub fn new(token: SecretString) -> Self

Source

pub fn renewal(&self) -> Option<&Renewal>

The renewal half, when there is one.

Source

pub fn from_stored(token: SecretString) -> Self

Rebuild the credential d2 handed back, for f1.

Source

pub fn from_stored_document(stored: &SecretString) -> Self

Reads whichever of the two stored shapes is there.

§Why the store holds a document now, and why the old shape still loads

A renewable credential is three values – access token, refresh token, and when each stops working – where there used to be one string. The secret store takes one opaque value per host, so the document goes inside it rather than the store growing a schema: no platform change, no migration step, and the same DPAPI blob or keychain item as before.

A value that is not this document is a bare access token, which is what every host stored until now. That is not a fallback for tidiness: upgrading must not log anybody out, and the App’s expiration setting can be turned on – or back off – without stranding hosts that are mid-way through either. A token has no internal structure to confuse with JSON, so the discrimination is unambiguous.

Source

pub fn to_stored_document(&self) -> SecretString

The value to hand the secret store.

Always the document, even for a credential with no renewal half: one shape written means one shape to reason about, and reading still accepts the bare token that older versions wrote.

Source

pub fn secret(&self) -> &SecretString

The token itself. Every call site of this is a place a secret can escape, so there are deliberately few: the Authorization header, and d2’s store call.

Source

pub fn token_type(&self) -> &str

Source

pub fn scope(&self) -> Option<&str>

Source

pub fn family(&self) -> &str

The token’s four-character family prefix — ghu_ for an App user-to-server token — and nothing else.

This exists so diagnostics can answer “did the device flow return the kind of token we expected?” without exposing the token. The D17 spike asserted exactly this and no more.

Source

pub fn is_user_to_server(&self) -> bool

true for the ghu_ family the published App issues.

Trait Implementations§

Source§

impl Clone for UserAccessToken

Source§

fn clone(&self) -> UserAccessToken

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for UserAccessToken

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for UserAccessToken

Source§

impl PartialEq for UserAccessToken

Source§

fn eq(&self, other: &Self) -> bool

Equality exists so device_flow::PollOutcome can carry a token and still be compared in a test. Production code never compares two credentials, and this is not a constant-time comparison.

1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Checks if this value is equivalent to the given key. Read more
Source§

impl<Q, K> Equivalent<K> for Q
where Q: Eq + ?Sized, K: Borrow<Q> + ?Sized,

Source§

fn equivalent(&self, key: &K) -> bool

Compare self to key and return true if they are equal.
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, !>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more