Skip to main content

parse_token_response

Function parse_token_response 

Source
pub fn parse_token_response(body: &Value) -> Result<TokenResponse>
Expand description

Validate a token response before anything is stored or sent.

Does not compare sub against the DID the login started from. That is deliberate: login_hint is only a should, so a user who typed handle A may legitimately be signed in to the authorization server as account B, and hard-failing would break a normal case. The caller must instead verify independently that this issuer is authoritative for the returned sub.