pub struct Credential(/* private fields */);Expand description
Where an Auth comes from, and how long it lasts.
See the module documentation for which constructor to reach for.
Implementations§
Source§impl Credential
impl Credential
Sourcepub fn token(token: impl Into<String>) -> Self
pub fn token(token: impl Into<String>) -> Self
A token that does not expire, over HTTPS.
A classic personal access token, a GitLab deploy token, an Azure DevOps
PAT. For one that does expire, see expiring — a
token pasted in here is presented unchanged forever, because there is
nothing here to obtain another one with.
Sourcepub fn basic(username: impl Into<String>, password: impl Into<String>) -> Self
pub fn basic(username: impl Into<String>, password: impl Into<String>) -> Self
A user name and password (or token) of the caller’s choosing.
For the host that does look at the user half — a GitLab deploy token is
a real user name and a real token, and a CI job token is
gitlab-ci-token plus CI_JOB_TOKEN.
Sourcepub fn ssh_agent() -> Self
pub fn ssh_agent() -> Self
SSH through the agent in SSH_AUTH_SOCK, and whatever ~/.ssh/config
says.
Sourcepub fn ssh_command(command: impl Into<String>) -> Self
pub fn ssh_command(command: impl Into<String>) -> Self
SSH through a command of the caller’s own.
Sourcepub fn from_fn(
obtain: impl Fn() -> Result<Auth, Error> + Send + Sync + 'static,
) -> Self
pub fn from_fn( obtain: impl Fn() -> Result<Auth, Error> + Send + Sync + 'static, ) -> Self
A credential read afresh on every fetch.
For a value that lives somewhere that can change without telling anyone — an environment variable a supervisor rewrites, a file a sidecar drops a new token into. Cheap, because a fetch is already a network round trip.
let credential = Credential::from_fn(|| {
let token = std::fs::read_to_string("/var/run/secrets/git-token")
.map_err(|error| Error::auth(format!("no git token: {error}")))?;
Ok(dynamic_config_git::Auth::Https {
username: "x-access-token".to_owned(),
password: token.trim().to_owned(),
})
});Sourcepub fn expiring(
obtain: impl Fn(Option<&Auth>) -> Result<Issued<Auth>, Error> + Send + Sync + 'static,
) -> Self
pub fn expiring( obtain: impl Fn(Option<&Auth>) -> Result<Issued<Auth>, Error> + Send + Sync + 'static, ) -> Self
A credential the issuer stamped a lifetime on.
The closure is handed the credential it is replacing — None on the
first call and after a refusal — and returns the new one with the
lifetime the issuer reported. It is called when there is nothing held,
when what is held is within a minute of expiring, and immediately after
the host refuses what was presented. It is not called per fetch: a
GitHub App token exchange is a rate-limited API call, and one per poll
tick would be a bill.
let credential = Credential::expiring(|_previous| {
// Sign the app JWT and exchange it for an installation token —
// whatever your GitHub client already does.
let (token, lives_for) = installation_token()?;
Ok(Issued {
value: Auth::Https {
username: "x-access-token".to_owned(),
password: token,
},
ttl: Some(lives_for),
})
});Trait Implementations§
Source§impl Clone for Credential
impl Clone for Credential
Source§fn clone(&self) -> Credential
fn clone(&self) -> Credential
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source. Read more