pub struct Claims {
pub sub: String,
pub iat: u64,
pub exp: u64,
pub nbf: Option<u64>,
pub iss: String,
pub aud: Vec<String>,
pub extra: HashMap<String, Value>,
}Expand description
Standard JWT claims with support for custom claims
Fields§
§sub: StringSubject (typically user ID)
iat: u64Issued at (Unix timestamp)
exp: u64Expiration time (Unix timestamp)
nbf: Option<u64>Not-before time (Unix timestamp) — optional per RFC 7519 §4.1.5.
When present, the token MUST NOT be accepted before this time (plus
MAX_CLOCK_SKEW_SECS). When absent, the not-before check is skipped.
iss: StringIssuer
aud: Vec<String>Audience
extra: HashMap<String, Value>Additional custom claims
Implementations§
Source§impl Claims
impl Claims
Sourcepub fn get_custom(&self, key: &str) -> Option<&Value>
pub fn get_custom(&self, key: &str) -> Option<&Value>
Get a custom claim by name
Sourcepub fn email(&self) -> Option<String>
pub fn email(&self) -> Option<String>
Extract the email claim as a flat string.
Handles plain strings, nested objects ({"value": "..."},
{"email": "..."}), and arrays (first string element).
Returns None when the claim is absent, null, or cannot be
normalised to a non-empty string.
Sourcepub fn name(&self) -> Option<String>
pub fn name(&self) -> Option<String>
Extract the name claim as a flat display-name string.
In addition to the shapes handled by extract_claim_string,
this also concatenates given + family keys when the claim is
an object without a formatted or value key.
Returns None when the claim is absent or cannot be normalised.
Sourcepub fn is_expired(&self) -> bool
pub fn is_expired(&self) -> bool
Check if token is expired
SECURITY: If system time cannot be determined, returns true (treats token as expired) This is a fail-safe approach to prevent accepting tokens when we can’t verify expiry
Sourcepub fn validate_temporal_claims(&self) -> Result<()>
pub fn validate_temporal_claims(&self) -> Result<()>
Validate temporal claims: iat staleness/skew and nbf not-before.
Enforces three RFC 7519 temporal guards beyond exp:
iatmust not be more thanMAX_CLOCK_SKEW_SECSseconds in the future (forgery guard — a futureiatis implausible for a legitimately issued token).iatmust not be more thanMAX_TOKEN_AGE_SECSseconds in the past (replay guard — a staleiatindicates a replayed or abnormally long-lived token).nbf(if present) must not be more thanMAX_CLOCK_SKEW_SECSseconds in the future (RFC 7519 §4.1.5 not-before enforcement).
§Errors
AuthError::TokenIssuedInFutureifiat > now + MAX_CLOCK_SKEW_SECS.AuthError::TokenTooOldifnow - iat > MAX_TOKEN_AGE_SECS.AuthError::TokenNotYetValidifnbf > now + MAX_CLOCK_SKEW_SECS.AuthError::SystemTimeErrorif the system clock cannot be read.
Trait Implementations§
Source§impl<'de> Deserialize<'de> for Claims
impl<'de> Deserialize<'de> for Claims
Source§fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>where
__D: Deserializer<'de>,
impl Eq for Claims
impl StructuralPartialEq for Claims
Auto Trait Implementations§
impl Freeze for Claims
impl RefUnwindSafe for Claims
impl Send for Claims
impl Sync for Claims
impl Unpin for Claims
impl UnsafeUnpin for Claims
impl UnwindSafe for Claims
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more