#[non_exhaustive]pub enum ValidatorError {
#[non_exhaustive] NoAudience {
section: String,
},
#[non_exhaustive] NoAlgorithms {
key: String,
},
#[non_exhaustive] LeewayTooLarge {
key: String,
leeway_secs: u64,
max: u64,
},
HttpClient(Box<dyn Error + Send + Sync + 'static>),
#[non_exhaustive] FetchTimeoutOutOfRange {
timeout: Duration,
min: Duration,
max: Duration,
},
#[non_exhaustive] InvalidRootCertificate {
index: usize,
reason: String,
},
#[non_exhaustive] InvalidProxy {
proxy: String,
reason: String,
},
#[non_exhaustive] InvalidInitialJwks {
reason: String,
},
}Expand description
Why an OAuthValidator could not be built.
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
#[non_exhaustive]NoAudience
Neither audience nor audiences holds a value. crate::OAuthConfig::resolve
refuses this; only a hand-edited ResolvedOAuthConfig reaches it.
Fields
This variant is marked as non-exhaustive
section: StringThe config block, named per its crate::KeyNaming.
#[non_exhaustive]NoAlgorithms
The algorithm allowlist is empty. Refused by resolve as well.
Fields
This variant is marked as non-exhaustive
key: StringThe algorithms setting, named per its crate::KeyNaming.
#[non_exhaustive]LeewayTooLarge
leeway_secs is over crate::MAX_LEEWAY_SECS. Refused by resolve
as well; re-checked because a larger leeway silently extends every
token’s life (and past the current Unix time, overflows the expiry
arithmetic).
Fields
This variant is marked as non-exhaustive
key: StringThe leeway_secs setting, named per its crate::KeyNaming.
HttpClient(Box<dyn Error + Send + Sync + 'static>)
The HTTP client for metadata/JWKS fetches could not be built (in practice: the TLS backend failed to initialize).
The underlying error is boxed rather than named, so the HTTP client
library’s version is not part of this crate’s public API; it is still
reachable through std::error::Error::source.
#[non_exhaustive]FetchTimeoutOutOfRange
OAuthValidatorBuilder::fetch_timeout is zero or outside
crate::MIN_FETCH_TIMEOUT..=crate::MAX_FETCH_TIMEOUT.
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]InvalidRootCertificate
A PEM passed to OAuthValidatorBuilder::add_root_certificate_pem
holds no certificate, or one the TLS backend cannot parse or use as a
trust anchor.
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]InvalidProxy
The URL passed to OAuthValidatorBuilder::proxy is refused:
malformed, or plain http on a non-loopback host with a credential in
it and no allow_insecure_http.
§Security
A refused value is never echoed, not even redacted — a malformed URL
can hide a credential where no parser sees userinfo. proxy is only
the scheme (http://<redacted>) when it is a proxy scheme, and
<redacted> otherwise; reason never quotes the URL. This error is
safe to log whatever the proxy URL carries.
Fields
This variant is marked as non-exhaustive
#[non_exhaustive]InvalidInitialJwks
The JWK Set passed to OAuthValidatorBuilder::initial_jwks is too
large, not JSON, not a JWK Set, or holds no key usable for a signature
under the configured algorithms.
Trait Implementations§
Source§impl Debug for ValidatorError
impl Debug for ValidatorError
Source§impl Display for ValidatorError
impl Display for ValidatorError
Source§impl Error for ValidatorError
impl Error for ValidatorError
Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()