Skip to main content

AccessTokenFormat

Enum AccessTokenFormat 

Source
pub enum AccessTokenFormat {
    Opaque,
    Jwt(Box<JwtConfig>),
}
Available on crate feature jwt only.
Expand description

What the client receives as its access_token.

AccessTokenFormat::Opaque is the DEFAULT and is what this crate did before the jwt feature existed: a 256-bit random string that means nothing without asking the AS. It is the right default because it leaks nothing, is revocable in the only sense that matters (the AS stops honouring it immediately), and costs one introspection call per protected request. Since 0.9.2 a registered resource server can make that call itself (crate::ServerConfig::resource_servers), so opaque is a real choice for a deployment with resource servers rather than a client-only one. A deployment whose resource servers must validate WITHOUT talking to the AS at all still wants AccessTokenFormat::Jwt.

Variants§

§

Opaque

Opaque random access tokens (RFC 7662 introspection reads them, for the token’s own client and for a resource server the token is addressed to).

§

Jwt(Box<JwtConfig>)

RFC 9068 at+jwt access tokens, signed with ES256. The record is still persisted, so introspection and revocation continue to work on the exact string the client presents.

BOXED deliberately. JwtConfig carries a signing key, an audience and a jwks_uri, and inlining that here put all of it in every crate::server::ServerConfig, which grew AuthorizationServer from 656 to 856 bytes and tripped the size gate in tests/allocation.rs. The box costs ONE allocation per server at construction, never per request, and keeps the struct the same size for the opaque-token majority who pay for a feature they did not enable otherwise. The gate caught this; raising the budget instead would have made the gate meaningless.

Trait Implementations§

Source§

impl Clone for AccessTokenFormat

Source§

fn clone(&self) -> AccessTokenFormat

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for AccessTokenFormat

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for AccessTokenFormat

Source§

fn default() -> AccessTokenFormat

Returns the “default value” for a type. Read more
Source§

impl Eq for AccessTokenFormat

Source§

impl PartialEq for AccessTokenFormat

Source§

fn eq(&self, other: &AccessTokenFormat) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for AccessTokenFormat

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> FromRef<T> for T
where T: Clone,

Source§

fn from_ref(input: &T) -> T

Converts to this type from a reference to the input type.
Source§

impl<A, B, T> HttpServerConnExec<A, B> for T
where B: Body,

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.