pub struct JwksCacheConfig {
pub discovery_url: String,
pub refresh_interval: Duration,
pub http_timeout: Duration,
pub issuer: Option<String>,
pub audience: Option<String>,
pub leeway_seconds: u64,
pub allow_hs256: bool,
}Fields§
§discovery_url: String§refresh_interval: Duration§http_timeout: Duration§issuer: Option<String>§audience: Option<String>§leeway_seconds: u64§allow_hs256: boolOpt-in escape hatch for HS256 (symmetric) tokens. Defaults to false:
this security primitive rejects HS256 by default to avoid algorithm
confusion if the IdP’s JWKS publishes an oct/alg-less key. Only set to
true for a trusted local/dev IdP you control.
Implementations§
Source§impl JwksCacheConfig
impl JwksCacheConfig
pub fn new(discovery_url: String) -> Self
Sourcepub fn with_audience(self, audience: impl Into<String>) -> Self
pub fn with_audience(self, audience: impl Into<String>) -> Self
Set the expected audience. Required: the cache fails closed when no audience is configured, preventing cross-RP token reuse.
Sourcepub fn with_issuer(self, issuer: impl Into<String>) -> Self
pub fn with_issuer(self, issuer: impl Into<String>) -> Self
Set the expected issuer.
Sourcepub fn allow_hs256(self, allow: bool) -> Self
pub fn allow_hs256(self, allow: bool) -> Self
Opt in to accepting HS256 (symmetric) tokens. Only for a trusted local
IdP you control — see Self::allow_hs256.
Trait Implementations§
Source§impl Clone for JwksCacheConfig
impl Clone for JwksCacheConfig
Source§fn clone(&self) -> JwksCacheConfig
fn clone(&self) -> JwksCacheConfig
Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
Performs copy-assignment from
source. Read moreAuto Trait Implementations§
impl Freeze for JwksCacheConfig
impl RefUnwindSafe for JwksCacheConfig
impl Send for JwksCacheConfig
impl Sync for JwksCacheConfig
impl Unpin for JwksCacheConfig
impl UnsafeUnpin for JwksCacheConfig
impl UnwindSafe for JwksCacheConfig
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Mutably borrows from an owned value. Read more
impl<ST, DT> CastableFrom<ST, Initialized, Initialized> for DT
impl<ST, DT> CastableFrom<ST, Uninit, Uninit> for DT
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CoreExecutorTurnFinalizationGuard for Twhere
T: Send,
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
fn instrument(self, span: Span) -> Instrumented<Self> ⓘ
Source§fn in_current_span(self) -> Instrumented<Self> ⓘ
fn in_current_span(self) -> Instrumented<Self> ⓘ
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
fn into_either(self, into_left: bool) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self> ⓘ
Converts
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more