systemprompt-api 0.64.0

Axum-based HTTP server and API gateway for systemprompt.io AI governance infrastructure. Exposes governed agents, MCP, A2A, and admin endpoints with rate limiting and RBAC.
Documentation
//! Building OAuth error responses from failures that carry a cause.
//!
//! An OAuth `error_description` is client-visible and may be copied into a
//! third-party `redirect_uri`, so a cause never becomes description text: the
//! response carries an authored description and the cause rides on the
//! [`OAuthHttpError`], logged once when the response is written.
//!
//! Copyright (c) systemprompt.io — Business Source License 1.1.
//! See <https://systemprompt.io> for licensing details.

use systemprompt_oauth::OauthError;
use systemprompt_traits::BoxedSource;

use super::{OAuthErrorCode, OAuthHttpError};

pub fn server_error(context: &'static str, source: impl Into<BoxedSource>) -> OAuthHttpError {
    OAuthHttpError::server_error(context).with_source(source)
}

pub fn rejected(error: OAuthHttpError, source: impl Into<BoxedSource>) -> OAuthHttpError {
    error.with_source(source)
}

pub fn classify_validation(
    error: OauthError,
    as_client_error: fn(String) -> OAuthHttpError,
) -> OAuthHttpError {
    match error {
        OauthError::Validation(message) | OauthError::InvalidClientMetadata(message) => {
            as_client_error(message)
        },
        other => OAuthHttpError::from(other),
    }
}

pub fn reclassify(
    error: OauthError,
    as_client_error: fn(String) -> OAuthHttpError,
) -> OAuthHttpError {
    let http = OAuthHttpError::from(error);
    if http.code() == OAuthErrorCode::ServerError {
        return http;
    }
    as_client_error(http.description().to_owned())
}

pub fn client_metadata_error(error: OauthError) -> OAuthHttpError {
    classify_validation(error, OAuthHttpError::invalid_client_metadata)
}