pub struct TokenRevocationManager { /* private fields */ }Expand description
High-level token revocation manager wrapping a backend store.
Implementations§
Source§impl TokenRevocationManager
impl TokenRevocationManager
Sourcepub fn new(
store: Arc<dyn RevocationStore>,
require_jti: bool,
fail_open: bool,
revoke_all_ttl_secs: u64,
) -> Self
pub fn new( store: Arc<dyn RevocationStore>, require_jti: bool, fail_open: bool, revoke_all_ttl_secs: u64, ) -> Self
Create a new revocation manager.
revoke_all_ttl_secs is how long a revoke-all epoch is retained (see
TokenRevocationConfig::revoke_all_ttl_secs).
Sourcepub async fn check_token(
&self,
jti: Option<&str>,
sub: &str,
iat: Option<i64>,
) -> Result<(), TokenRejection>
pub async fn check_token( &self, jti: Option<&str>, sub: &str, iat: Option<i64>, ) -> Result<(), TokenRejection>
Check if a token should be rejected, by single-JTI revocation and by the
caller’s revoke-all epoch.
jti/iat are the token’s claims; sub is the subject. The single-JTI check
uses jti; the epoch check rejects when the user has an active revoke-all epoch
and the token’s iat is at or before it. A token with no iat cannot be
epoch-checked, so the epoch is skipped for it (it can still be revoked by jti).
Returns Ok(()) if the token is allowed, or an error reason if rejected.
§Errors
Returns TokenRejection::MissingJti if JTI is required but absent.
Returns TokenRejection::Revoked if the token’s jti is revoked or its iat
predates the user’s revoke-all epoch.
Returns TokenRejection::StoreUnavailable if the revocation store is unreachable and
fail_open is false.
Sourcepub async fn revoke(
&self,
jti: &str,
ttl_secs: u64,
) -> Result<(), RevocationError>
pub async fn revoke( &self, jti: &str, ttl_secs: u64, ) -> Result<(), RevocationError>
Revoke a single token by JTI.
§Errors
Returns RevocationError if the underlying revocation store operation fails.
Sourcepub async fn revoke_all_for_user(
&self,
sub: &str,
) -> Result<(), RevocationError>
pub async fn revoke_all_for_user( &self, sub: &str, ) -> Result<(), RevocationError>
Revoke all of a user’s tokens by recording a revoke-all epoch retained for
the manager’s configured revoke_all_ttl_secs (see
RevocationStore::revoke_all_for_user).
§Errors
Returns RevocationError if the underlying revocation store operation fails.
Sourcepub async fn user_revoked_after(
&self,
sub: &str,
) -> Result<Option<i64>, RevocationError>
pub async fn user_revoked_after( &self, sub: &str, ) -> Result<Option<i64>, RevocationError>
Return the revoke-all epoch currently in effect for sub, if any.
§Errors
Returns RevocationError if the underlying revocation store operation fails.
Sourcepub const fn require_jti(&self) -> bool
pub const fn require_jti(&self) -> bool
Whether JTI is required.
Trait Implementations§
Auto Trait Implementations§
impl !RefUnwindSafe for TokenRevocationManager
impl !UnwindSafe for TokenRevocationManager
impl Freeze for TokenRevocationManager
impl Send for TokenRevocationManager
impl Sync for TokenRevocationManager
impl Unpin for TokenRevocationManager
impl UnsafeUnpin for TokenRevocationManager
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
impl<A, B, T> HttpServerConnExec<A, B> for Twhere
B: Body,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more