#[non_exhaustive]pub enum Credential {
StaticToken,
OAuth(AuthorizedToken),
}Expand description
Which mechanism accepted a request.
Deliberately not something to put in a response: a client should not be able to tell from the outcome which mechanism accepted (or refused) which of its credentials. The axum middleware inserts it into request extensions so a handler can, for example, attribute a write to an OAuth principal.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
StaticToken
A candidate matched a configured static token. Which one, when several
are configured, is reported separately as a StaticTokenMatch: by
authenticate_with_static_tokens, and in request extensions by the
layers.
OAuth(AuthorizedToken)
A candidate validated as an OAuth access token carrying every required scope.
Trait Implementations§
Source§impl Clone for Credential
impl Clone for Credential
Source§impl Debug for Credential
impl Debug for Credential
impl Eq for Credential
Source§impl<S: Send + Sync> FromRequestParts<S> for Credential
Available on crate feature axum only.Extracts the credential an AuthLayer accepted.
impl<S: Send + Sync> FromRequestParts<S> for Credential
axum only.Extracts the credential an AuthLayer accepted.
Refuses with the layer’s own 401 and WWW-Authenticate challenge when the
layer inserted none (an optional or
allow_unauthenticated layer passed the
request through), and with 500 (logged at error) on a route no
AuthLayer covers. See the module docs.
§Examples
use axum::{Router, routing::get};
use oauth_resource_server::Credential;
async fn whoami(credential: Credential) -> String {
match credential {
Credential::OAuth(token) => format!("subject {:?}", token.subject),
Credential::StaticToken => "the static API key".to_string(),
_ => "some other credential".to_string(),
}
}Source§impl<S: Send + Sync> OptionalFromRequestParts<S> for Credential
Available on crate feature axum only.Option<Credential>: None when an AuthLayer ran and inserted no
credential (no credential under an optional
or allow_unauthenticated layer). On a
route no AuthLayer covers it still refuses with 500, logged at error,
rather than reading as anonymous.
impl<S: Send + Sync> OptionalFromRequestParts<S> for Credential
axum only.Option<Credential>: None when an AuthLayer ran and inserted no
credential (no credential under an optional
or allow_unauthenticated layer). On a
route no AuthLayer covers it still refuses with 500, logged at error,
rather than reading as anonymous.