Skip to main content

Module fetch

Module fetch 

Source
Expand description

Fetching the JSON documents OAuth discovery depends on.

Three rules apply to every document here, and each exists because the reference client enforces it:

  • No redirects. The mix-up defence compares a document’s issuer against the URL it was fetched from; a 302 would make that comparison meaningless while still appearing to pass. See crate::net::guarded_get_no_redirect.
  • Status exactly 200. Not “2xx”, not “whatever parsed”. A 204 or a 206 is not a metadata document.
  • Content type must be JSON. A server answering text/html is not serving the document we asked for, whatever the bytes happen to parse as.

On top of the SSRF guard and the body cap those bring with them.

Constants§

DID_JSON
Content types accepted for DID documents. did+ld+json is what plc.directory actually serves.
JSON
Content types accepted for OAuth metadata documents.

Functions§

get_json
Fetch a JSON document, requiring 200 and an acceptable content type.
get_json_optional
As get_json, but a 404 means absent rather than failed.