pub struct TokenSession {
pub session: Session,
pub required_headers: &'static [&'static str],
pub token_fields: &'static [&'static str],
}Expand description
The token session: the OAuth exchange.
Fields§
§session: Session§required_headers: &'static [&'static str]The header lines a Platform Verifier requires, each exactly once with
its value: host and content-type, lowercased as the wire spells
them. Every other header is the runtime’s own, save the names
FORBIDDEN_REQUEST_HEADERS lists. content-length is absent
because its value is the body’s own count: the HTTP client appends
it and the verifier reads it rather than compares it.
token_fields: &'static [&'static str]The form fields the body carries, in the order the prover serializes them. Every verifier holds the whole body to this list: exactly these names in this order, each once with a nonempty value, nothing after the last. GitHub’s list is REQ-PLAT-61’s; X’s specification keeps its decoded form on ASM-PROV-07, so the contract is stricter than the specification there.