Expand description
OpenID Connect pieces: the discovery document, JWKS parsing, and ID token
verification (RS256 and ES256 with ring).
An ID token is accepted only when its signature verifies with a key from
the issuer’s JWKS, iss is the discovered issuer exactly, aud holds the
client id (with azp equal to it when there are several audiences), exp
has not passed and iat is not in the future (60s leeway each), and
nonce is the one this sign-in sent.
Structs§
- Discovery
- The parts of
/.well-known/openid-configurationisb uses. - IdClaims
- What a verified ID token says about the user.
Enums§
- Jwk
- A signing key from a JWKS.
- Token
Error - Why a token was not checked: its key is not in the JWKS we hold (fetch the JWKS again and retry), or it is simply bad.
Functions§
- parse_
jwks - The signing keys in a JWKS, with their key ids. Keys of other types or curves, and keys marked for encryption, are skipped.
- truthy
email_verifiedis a boolean, but some providers send the string.- verify_
id_ token - Verify an ID token. See the module docs for what is checked.
Type Aliases§
- Keys
- The signing keys of a JWKS, with their key ids.