Skip to main content

Claims

Struct Claims 

Source
pub struct Claims { /* private fields */ }
Expand description

Standard OIDC claims decoded from an ID token.

JWT signature validation is optional but strongly encouraged. Configure a crate::jwks::JwksValidator via the builder to enable cryptographic validation of the ID token.

§Examples

Accessing claims:

use loopauth::oidc::Claims;
use std::time::UNIX_EPOCH;
use url::Url;

let json = serde_json::json!({
    "sub": "user123",
    "email": "user@example.com",
    "email_verified": true,
    "name": "Test User",
    "picture": "https://example.com/avatar.jpg",
    "iss": "https://accounts.example.com",
    "aud": ["client-id"],
    "iat": 1_000_000_000_u64,
    "exp": 9_999_999_999_u64
});
let claims: Claims = serde_json::from_value(json).unwrap();

assert_eq!(claims.sub().as_str(), "user123");
assert_eq!(claims.email().unwrap().as_str(), "user@example.com");
assert!(claims.email().unwrap().is_verified());
assert_eq!(claims.name(), Some("Test User"));
assert_eq!(claims.picture().unwrap().as_url().as_str(), "https://example.com/avatar.jpg");
assert_eq!(claims.iss().as_url(), &Url::parse("https://accounts.example.com").unwrap());
assert_eq!(claims.aud().len(), 1);
assert!(claims.iat() > UNIX_EPOCH);
assert!(claims.exp() > UNIX_EPOCH);

Serde roundtrip preserves all fields including email_verified and picture:

use loopauth::oidc::Claims;

let original = serde_json::json!({
    "sub": "user123",
    "email": "user@example.com",
    "email_verified": true,
    "name": "Test User",
    "picture": "https://example.com/avatar.jpg",
    "iss": "https://accounts.example.com",
    "aud": ["client-id"],
    "iat": 1_000_000_000_u64,
    "exp": 9_999_999_999_u64
});
let claims: Claims = serde_json::from_value(original).unwrap();
let serialized = serde_json::to_string(&claims).unwrap();
let roundtripped: Claims = serde_json::from_str(&serialized).unwrap();

assert_eq!(roundtripped.email().unwrap().as_str(), "user@example.com");
assert!(roundtripped.email().unwrap().is_verified());
assert_eq!(roundtripped.picture().unwrap().as_url().as_str(), "https://example.com/avatar.jpg");

Implementations§

Source§

impl Claims

Source

pub const fn sub(&self) -> &SubjectIdentifier

Returns the subject identifier.

Source

pub const fn email(&self) -> Option<&Email>

Returns the email address, if present.

Source

pub fn name(&self) -> Option<&str>

Returns the display name, if present.

Source

pub const fn picture(&self) -> Option<&PictureUrl>

Returns the picture URL, if present.

Source

pub const fn iss(&self) -> &Issuer

Returns the issuer identifier.

Source

pub fn aud(&self) -> &[Audience]

Returns the audience values.

Source

pub fn aud_contains(&self, client_id: &str) -> bool

Returns true if client_id appears in the aud claim.

§Example
use loopauth::oidc;

let json = serde_json::json!({
    "sub": "user123",
    "iss": "https://accounts.example.com",
    "aud": ["my-client-id"],
    "iat": 1_000_000_000_u64,
    "exp": 9_999_999_999_u64
});
let claims: oidc::Claims = serde_json::from_value(json).unwrap();
assert!(claims.aud_contains("my-client-id"));
assert!(!claims.aud_contains("other-client"));
Source

pub const fn iat(&self) -> SystemTime

Returns the time at which the ID token was issued.

Source

pub const fn exp(&self) -> SystemTime

Returns the expiration time of the ID token.

Source

pub fn is_expired(&self) -> bool

Returns true if the ID token’s exp claim is more than 60 seconds in the past.

A 60-second clock-skew window is applied to match the tolerance used during ID token validation. Tokens that expired less than 60 seconds ago are still considered valid.

Trait Implementations§

Source§

impl Clone for Claims

Source§

fn clone(&self) -> Claims

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for Claims

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl<'de> Deserialize<'de> for Claims

Source§

fn deserialize<D>(deserializer: D) -> Result<Self, D::Error>
where D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl Serialize for Claims

Source§

fn serialize<S>(&self, serializer: S) -> Result<S::Ok, S::Error>
where S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = !

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more