Expand description
DPoP-authenticated form POSTs, with nonce persistence and a bounded retry.
Every OAuth POST this client makes goes through here: PAR, token exchange, refresh. Three behaviours matter and all three are easy to get subtly wrong:
- The nonce is persisted per origin and harvested from EVERY response, including successes. Using one only for an immediate retry means every request pays a wasted round trip.
- The retry is bounded at one. A server that answers every request with
use_dpop_noncewould otherwise spin forever. - The endpoint kind is passed, not inferred. The authorization server
signals a nonce requirement with
400+ a JSON body; a resource server uses401+WWW-Authenticate. Reading only one of those misses every challenge from the other.
Structs§
- Dpop
Request - One DPoP-authenticated request.
- Post
Outcome - A completed request: what the server said, and what it said it with.
Enums§
- Dpop
Body - What this request carries, and therefore which method it uses.
- Retry
- Whether this request may be repeated if the server demands a nonce.
Functions§
- send_
with_ dpop - Send a request with a DPoP proof, retrying once if the server demands a
nonce and
Retrypermits it.