#[non_exhaustive]pub enum AuthLayerError {
NoCredential,
NoSources,
DecisionNeedsOAuth,
DecisionWithoutOAuth,
InvalidChallenge,
DecisionWithoutStaticToken,
InvalidScope,
ScopesNeedOAuth,
ScopesWithoutAuthentication,
}tower only.Expand description
Why a layer’s builder refused to build (HttpAuthLayerBuilder, or the
axum layer’s AuthLayerBuilder, which reaches this type as
oauth_resource_server::axum::AuthLayerError).
Variants (Non-exhaustive)§
This enum is marked as non-exhaustive
NoCredential
Neither a (non-blank) static token nor an OAuth validator was given (a whitespace-only static token counts as none: it could never match). A layer that could accept nothing would lock every route; one that accepted everything must be asked for by name.
NoSources
The builder’s sources was given an empty list, so no request could
ever present a credential.
DecisionNeedsOAuth
build_with_decision: the decision was made with OAuth on, but no
OAuth validator was given.
DecisionWithoutOAuth
build_with_decision: the decision was made with OAuth off, but an
OAuth validator was given.
InvalidChallenge
The OAuth validator’s challenge is not a valid HTTP header value, so
refusals could not carry WWW-Authenticate. crate::OAuthConfig::resolve
refuses every config that would cause this (a control or non-ASCII
character in resource, a scope that is not a scope-token); only a
hand-edited crate::ResolvedOAuthConfig reaches it.
DecisionWithoutStaticToken
build_with_decision: the builder was given a non-empty
static_tokens set, but the decision carries no static token and does
not ignore one (OAuthOnly or Unauthenticated), so
crate::static_token_policy was never told a static token exists.
Pass the current token to the policy too; a decision that carries it
then accepts the whole set.
InvalidScope
A require_scopes entry is not an RFC 6749 §3.3 scope-token (it is
empty, or holds a space, ", \, a control or non-ASCII
character). No token can carry such a scope, so every request would
be refused.
ScopesNeedOAuth
require_scopes was given without an OAuth validator and without
static_token_bypasses_scopes: a static token carries no scopes, so
no request could ever pass.
ScopesWithoutAuthentication
build_with_decision with StaticTokenDecision::Unauthenticated on a
builder given require_scopes: that decision builds the
allow_unauthenticated pass-through, which checks nothing, so the
scopes would be silently dropped.
Trait Implementations§
Source§impl Clone for AuthLayerError
impl Clone for AuthLayerError
Source§impl Debug for AuthLayerError
impl Debug for AuthLayerError
Source§impl Display for AuthLayerError
impl Display for AuthLayerError
impl Eq for AuthLayerError
Source§impl Error for AuthLayerError
impl Error for AuthLayerError
1.30.0 · Source§fn source(&self) -> Option<&(dyn Error + 'static)>
fn source(&self) -> Option<&(dyn Error + 'static)>
1.0.0 · Source§fn description(&self) -> &str
fn description(&self) -> &str
use the Display impl or to_string()