pub fn parse_token_response(body: &Value) -> Result<TokenResponse>Expand description
Validate a token response before anything is stored or sent.
Does not compare sub against the DID the login started from. That is
deliberate: login_hint is only a should, so a user who typed handle A may
legitimately be signed in to the authorization server as account B, and
hard-failing would break a normal case. The caller must instead verify
independently that this issuer is authoritative for the returned sub.