pub struct OAuth2RefreshProvider { /* private fields */ }Expand description
OAuth2 refresh_token grant provider with refresh-token rotation capture.
When a durable StateStore is attached (via persist: config, #499), the
rotated refresh_token is written back after every refresh and re-read on
startup — so a second scheduled run authenticates with the current token
instead of the now-invalidated config seed.
Implementations§
Source§impl OAuth2RefreshProvider
impl OAuth2RefreshProvider
Sourcepub fn from_config(config: &Value) -> Result<Self, FaucetError>
pub fn from_config(config: &Value) -> Result<Self, FaucetError>
Build from a config object with token_url, client_id,
client_secret, refresh_token, and optional scope / expiry_ratio /
persist.
Sourcepub fn with_store(
self,
store: Arc<dyn StateStore>,
key: impl Into<String>,
) -> Self
pub fn with_store( self, store: Arc<dyn StateStore>, key: impl Into<String>, ) -> Self
Attach a durable store for the rotated refresh token (used by tests and
library callers that supply their own StateStore). key must be
stable across runs for the same logical provider.
Trait Implementations§
Source§impl AuthProvider for OAuth2RefreshProvider
impl AuthProvider for OAuth2RefreshProvider
Source§fn credential<'life0, 'async_trait>(
&'life0 self,
) -> Pin<Box<dyn Future<Output = Result<Credential, FaucetError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
fn credential<'life0, 'async_trait>(
&'life0 self,
) -> Pin<Box<dyn Future<Output = Result<Credential, FaucetError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
Return a currently-valid credential, refreshing if needed.
Source§fn invalidate<'life0, 'life1, 'async_trait>(
&'life0 self,
stale: &'life1 Credential,
) -> Pin<Box<dyn Future<Output = Result<Credential, FaucetError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
fn invalidate<'life0, 'life1, 'async_trait>(
&'life0 self,
stale: &'life1 Credential,
) -> Pin<Box<dyn Future<Output = Result<Credential, FaucetError>> + Send + 'async_trait>>where
Self: 'async_trait,
'life0: 'async_trait,
'life1: 'async_trait,
Force a refresh iff the cached credential still equals
stale
(compare-and-swap). Multiple connectors that hit a 401 with the same
token collapse into a single refresh; callers holding an already-rotated
token get the new one without triggering another fetch. Read moreSource§fn provider_name(&self) -> &'static str
fn provider_name(&self) -> &'static str
Stable, non-empty name for diagnostics and metrics.
Source§fn sign_request<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
_method: &'life1 str,
_url: &'life2 str,
_query: &'life3 BTreeMap<String, String>,
) -> Pin<Box<dyn Future<Output = Result<Option<Credential>, FaucetError>> + Send + 'async_trait>>where
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
Self: 'async_trait,
fn sign_request<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
_method: &'life1 str,
_url: &'life2 str,
_query: &'life3 BTreeMap<String, String>,
) -> Pin<Box<dyn Future<Output = Result<Option<Credential>, FaucetError>> + Send + 'async_trait>>where
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
Self: 'async_trait,
Per-request signing hook (OAuth1 and similar, #496). Read more
Source§fn request_auth<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
_method: &'life1 str,
_url: &'life2 str,
_query: &'life3 BTreeMap<String, String>,
) -> Pin<Box<dyn Future<Output = Result<RequestAuth, FaucetError>> + Send + 'async_trait>>where
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
Self: 'async_trait,
fn request_auth<'life0, 'life1, 'life2, 'life3, 'async_trait>(
&'life0 self,
_method: &'life1 str,
_url: &'life2 str,
_query: &'life3 BTreeMap<String, String>,
) -> Pin<Box<dyn Future<Output = Result<RequestAuth, FaucetError>> + Send + 'async_trait>>where
'life0: 'async_trait,
'life1: 'async_trait,
'life2: 'async_trait,
'life3: 'async_trait,
Self: 'async_trait,
Richer per-request auth for multi-step flows (#511): credential
placements across header / query / cookie / body plus an optional
dynamic base-URL override. Read more
Source§fn reauth_statuses(&self) -> &[u16]
fn reauth_statuses(&self) -> &[u16]
HTTP status codes on which the connector should force a re-auth
(via
invalidate) and retry the request once. Read moreAuto Trait Implementations§
impl !Freeze for OAuth2RefreshProvider
impl !RefUnwindSafe for OAuth2RefreshProvider
impl !UnwindSafe for OAuth2RefreshProvider
impl Send for OAuth2RefreshProvider
impl Sync for OAuth2RefreshProvider
impl Unpin for OAuth2RefreshProvider
impl UnsafeUnpin for OAuth2RefreshProvider
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more