use std::sync::Arc;
use thiserror::Error;
#[derive(Debug, Error)]
pub enum CredentialError {
#[error("service-account key is malformed: {0}")]
Malformed(#[source] serde_json::Error),
#[error(
"endpoint '{endpoint}' needs a {field} to fill `{placeholder}`, but the secret is not a \
service-account key (no project_id or region to fill it from)"
)]
MissingScope {
endpoint: String,
field: &'static str,
placeholder: &'static str,
},
#[error("service-account private_key is not a valid RSA PEM: {0}")]
SigningKey(#[source] jsonwebtoken::errors::Error),
#[error("could not sign the assertion: {0}")]
Sign(#[source] jsonwebtoken::errors::Error),
#[error("system clock is before the unix epoch: {0}")]
Clock(#[source] std::time::SystemTimeError),
#[error("could not build the token-exchange client: {0}")]
Client(#[source] Arc<reqwest::Error>),
#[error("token endpoint {uri} unreachable: {source}")]
Unreachable {
uri: String,
#[source]
source: reqwest::Error,
},
#[error("token endpoint returned {status}: {body}")]
Rejected { status: String, body: String },
#[error("token endpoint returned an unreadable body: {0}")]
UnreadableBody(#[source] serde_json::Error),
}