Skip to main content

Module request

Module request 

Source
Expand description

DPoP-authenticated form POSTs, with nonce persistence and a bounded retry.

Every OAuth POST this client makes goes through here: PAR, token exchange, refresh. Three behaviours matter and all three are easy to get subtly wrong:

  • The nonce is persisted per origin and harvested from EVERY response, including successes. Using one only for an immediate retry means every request pays a wasted round trip.
  • The retry is bounded at one. A server that answers every request with use_dpop_nonce would otherwise spin forever.
  • The endpoint kind is passed, not inferred. The authorization server signals a nonce requirement with 400 + a JSON body; a resource server uses 401 + WWW-Authenticate. Reading only one of those misses every challenge from the other.

Structs§

DpopRequest
One DPoP-authenticated request.
PostOutcome
A completed request: what the server said, and what it said it with.

Enums§

DpopBody
What this request carries, and therefore which method it uses.
Retry
Whether this request may be repeated if the server demands a nonce.

Functions§

send_with_dpop
Send a request with a DPoP proof, retrying once if the server demands a nonce and Retry permits it.